The Trump administration launched Project Watershed 250, a six-month pilot to identify and remediate cybersecurity weaknesses at Texas water and wastewater utilities. Led by the Office of the National Cyber Director and Texas Cyber Command, with participation from the Texas governor’s office, EPA, CISA and private companies, the program will provide participating utilities no-cost assessments, red-team testing, system hardening and AI-enabled defensive tools.
The initiative follows persistent threats to U.S. water infrastructure, including an Iranian-backed campaign that affected roughly 30 systems across 12 states and a suspected Russian-linked 2024 intrusion at Muleshoe, Texas. Officials said the pilot is designed as a collaborative, industry-led alternative to withdrawn federal audit requirements and could become a model for a nationwide water-sector cybersecurity program.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Iranian hackers reportedly shut down an unnamed UK power plant for several days in July 2026, reportedly during a broader operation targeting U.S. water plants.
Texas established Texas Cyber Command, funding it with $135 million to protect state and local government systems and coordinate cyberattack responses.
A cyberattack against the Muleshoe, Texas, water system was suspected to have been conducted by Russian hackers.
The Trump administration formally launched Project Watershed 250 in San Antonio, Texas, as a six-month pilot to identify and remediate cybersecurity weaknesses in water and wastewater systems. ONCD, Texas Cyber Command, EPA, CISA, Texas state officials, and private-sector companies are participating, with assistance provided to utilities at no cost.
After some Republican-led states challenged Biden-era water-system cybersecurity audit requirements in court, the Environmental Protection Agency withdrew the rule.
An Iranian-backed cyberattack affected 30 water systems across 12 U.S. states. Officials said affected systems continued operating safely and no known public-health effects occurred.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourcegov.texas.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.