It was therefore noteworthy, but should have come as no surprise, when America’s own water facilities came under attack this summer. On July 27th Maple Plain, near Minneapolis, declared an emergency. That same day the Clayton County Water Authority in Georgia, which serves 300,000 people south of Atlanta, asked customers to boil their water after a drop in pressure caused disruption. In all, hackers wormed their way into water and waste- water facilities in at least seven American states; some reports suggest more than 12. Minnesota was hardest hit, with 30 community water systems affected. American officials’ early assessments suggest that groups affiliated with Iran are responsible. Hacks can disrupt water supply and make water unsafe to drink, though none of the recent attacks is thought to have done so. The question is whether politicians will, at last, move to deter hackers before their next big onslaught. On August 13th Amy Klobuchar and Adam Schiff, a pair of Democratic senators, introduced the Water Cyber Shield Act, which includes more power for the Environmental Protection Agency (EPA). But on August 19th federal officials had already issued a new warning: hackers were trying to breach Siemens devices used in water facilities and other critical infrastructure. As the latest attack proves, water plants are not the only form of infrastructure under threat, but they are particularly easy to infiltrate. The electricity grid must meet cyber-security standards overseen by the Federal Energy Regulatory Commission. But no requirements exist for water. The electricity utilities that operate power plants are also larger, better funded and more tightly regulated than water operators: the biggest investor-owned utilities, such as PG&E in California and Duke Energy in the south-east and Midwest, supply power to millions of households. Water—heavy and expensive to move—is more localised. About 90% of utilities, mostly owned by local governments, serve fewer than 10,000 people each. That means each has less money to harden their often obsolete computer systems. Indeed, water infrastructure had already shown itself ill- equipped to fend off attacks. Iranian hackers broke into the control systems of a small dam in New York in 2013, in an incident which went unreported for almost three years, and in 2023 seized a pump at a water plant in Pennsylvania.

Iran’s hackers are prolific; on August 18th federal prosecutors charged 17 Iranians with attacking the systems of universities and companies to steal research and intellectual property. A sprawling Chinese campaign, known as Volt Typhoon, has sought to burrow into American critical infrastructure to prepare for sabotage. But those with less skill can break in, too. In 2019 a former water-district employee in Kansas used his old credentials to log on to an application that shut down cleaning procedures. (He claimed he was drunk which, if true, would offer further evidence that water is an easy target.) Two years later hackers took control of a water facility in Oldsmar, Florida, and attempted to poison residents by increasing the levels of sodium hydroxide, an ingredient in drain cleaner. That failed, but they were able to infiltrate the system easily, because an operator’s machine was running TeamViewer, a popular corporate tool that allows remote access to machines for IT support. The latest intrusions were relatively simple. Hackers breached the “operational-technology” systems that serve as the interface between a computer network and a physical system. That required little wizardry: such systems are often connected to the public-facing internet, via mobile networks, and use weak credentials, if any. On July 30th, then again on August 19th, federal officials pleaded with operators to disconnect critical systems from the internet. Earlier efforts to impose cyber-security standards on this patchwork have largely failed. During the Biden administration the EPA sought to compel states to review and report cyber-threats to water systems. The Republican state attorneys-general in Missouri, Arkansas and Iowa, joined by the American Water Works Association (AWWA) and the National Rural Water Association (NRWA), a pair of industry groups, sued, citing federal overreach. After a federal court issued a stay on the EPA’s effort, the agency pulled back. When Congress has acted, measures have been minimal and slow to take effect. The Cyber Incident Reporting for Critical Infrastructure Act was passed in 2022, obliging organisations in important sectors to report major cyber-attacks within 72 hours. Its rules are due to be finalised in September, more than four years on.

There may now be momentum to do more. This month DEF CON Franklin, a group of civic-minded hackers, teamed up with the NRWA to launch the Water Watch Centre, an initiative to provide private-sector cyber-security support to small utilities. Ms Klobuchar’s and Mr Schiff’s bill is not the only proposal under consideration. On August 5th the AWWA, which resisted the Biden administration’s proposals, endorsed the Water Risk and Resilience Organisation Establishment Act, sponsored by Rick Crawford, a Republican congressman from Arkansas. That bill would create an independent body to draft minimum cyber-security standards, under the EPA’s oversight, in a mirror of the requirement for electric utilities. The same day Tom Cotton, a Republican senator, wrote to Scott Bessent, the treasury secretary, urging changes to the tax code and other regulatory tweaks to encourage water plants to invest in better security. Whether Washington moves swiftly depends in no small part on Mr Trump. The president’s proposed budget, which the Senate will take up in September, would increase the budget for the Department of War by 44%, to $1.5trn. That includes money for the Iran war and a high-tech “Golden Dome”, to shield America from missiles. He has shown less interest in defending American water. His budget would cut the EPA’s biggest source of funds for water cyber- security by almost 90%. In July he suggested that fault for Minnesota’s attack lay with Tim Walz, the “corrupt” governor of the state—and that there had not been an Iranian attack at all. “Iran’s got bigger problems than worrying about Minnesota,” he offered. The Cybersecurity and Infrastructure Security Agency, the main federal body tasked with cyber- defence, is in disarray, with leadership turmoil, low morale and a one-third cut in staff since Mr Trump returned to the White House. The Senate may push him to do more after it returns from recess. Hackers are not waiting.■ Stay on top of American politics with The US in brief, our daily newsletter with fast analysis of the most important political news, and Checks and Balance, a weekly note that examines the state of American democracy and the issues that matter to voters.

This article was downloaded by zlibrary from https://www.economist.com/united-states/2026/08/19/why-the-worlds-richest-country- cant-defend-vital-infrastructure

United States · United States | Campaign cash

The problem with Republican fundraising Democratic candidates are outraising their rivals Aug 20th 2026 Before the midterm elections Republicans claim to have at least one thing going for them: money, and lots of it. At first glance, the latest filings with the Federal Election Commission show Republicans with a staggeringly large cash advantage. Across their party apparatus and political action committees, or PACs, Republicans have amassed around $1bn, more than twice as much as Democrats have (see chart). However, this should give Republicans scant encouragement. The party’s biggest war-chest belongs to MAGA Inc, Donald Trump’s super PAC, and the president has declined to say how much he will contribute to individual campaigns. While Republicans remain captive to the president’s whim, Democratic fundraising is decentralised. Individual candidates are outraising

their opponents in competitive races. That means they have more cash on hand and more enthusiastic supporters, too. Money cannot buy victory, but it is not immaterial, either. Candidates raise money to pay for campaign operations and to buy advertisements. Get-out- the-vote efforts can boost a candidate’s prospects, though the effect seems to decline when a campaigner is already well known. In competitive general elections for federal office, it is usually hard to measure the effect of extra advertisements because airwaves are already saturated. The recent governors’ primary in Wisconsin provided a rare natural experiment, albeit not in a general election. Francesca Hong, a Democratic Socialist, did not buy a single television ad. The Economist’s analysis, controlling for factors such as voters’ median age and education level by county, suggests that her lack of television advertising helped ensure her defeat in the Democratic primary on August 11th. If the amount of cash matters, how campaigns raise it does, too: money is both a factor in a campaign’s success and an indicator of its health. Strong candidates tend to attract donations from ordinary voters in their states, a sign of their enthusiasm. That is why The Economist includes individual donations as one predictor in our forecast of the midterm elections. It is also

another reason why Republicans cannot be confident that their cash advantage will help them. Mr Trump has proved particularly skilled at mobilising donors (think of those $1m-a-plate dinners at Mar-a-Lago). But those donations have flowed into his super PAC, not to candidates themselves. MAGA Inc accounts for at least $400m of the total Republican haul, a reminder that the president remains the party’s source of power. He looks reluctant to share it. MAGA Inc has spent just $2.3m, 0.6% of its resources, to help Republicans win elections so far. “I could spend it on pretty much anything I want,” Mr Trump boasted recently. Though the president claims he will use his PAC to help Republicans, the group has yet to announce its spending plans, or even to share them with Republican allies. While Republicans’ fundraising is centralised—powerful in theory but limited in effect—Democrats are seeing the opposite phenomenon. The party’s centralised fundraising is sputtering. Small donors are fed up with what they perceive to be the Democratic establishment. Top donors remain frustrated by how their money was spent during the 2024 presidential campaign; that the Democratic National Committee (DNC) is $2m in debt is not instilling confidence. The DNC, according to a quip in Washington, now stands for “Do Not Contribute”. But many individual Democratic candidates are not suffering—donors are still giving money, but skirting the central committee and going straight to the campaigns. Take the Senate race in Texas. James Talarico, the Democratic nominee, raised $28m in the second quarter of this year, while his Republican opponent, Ken Paxton, raised a puny $1.6m. More than half of Mr Talarico’s total came from small donations, compared with just 12% for Mr Paxton. The Democratic candidate is netting big donations, as well. Reid Hoffman, a major donor who has shunned the DNC, recently handed $10m to a pro- Talarico PAC. Democratic candidates hold an advantage in other states, too. In the nine most competitive Senate races, they had around $116m in cash on hand, compared with just $51m for Republicans. In a reflection of voters’ enthusiasm, on average small donors—individuals who pledge less than