
Cyberattacks increasingly threaten capital-strapped communities across the Midwest, with threat actors using artificial intelligence to increase the speed and sophistication of their hacking campaigns.
In Middletown, Ohio, a cyberattack this summer left water customers unable to pay their bills.
In Michigan and Minnesota,
Also in July, Rapid City, South Dakota's municipal wastewater system faced a denial of service attack.
And the Trump administration's cutbacks to federal cybersecurity defense mean state and local governments are increasingly left to their own devices to manage a more dangerous threat environment.
Hackers are compromising organizations by tricking the organizations' own AI assistants and targeting their proprietary AI models, according to
This evolution is unfolding as the Trump administration pulls back from cybersecurity, sunsetting federal cybersecurity grants to state and local governments and cutting funding for the Cybersecurity and Infrastructure Security Agency.
It's also happening as cybersecurity remains underfunded at the state and local level.
The share of local governments with adequate cybersecurity funding is likely lower still. As of August 2025, 68% of state, local, tribal and territorial governments had no budget for major cybersecurity priorities,
"The systems that were breached (this summer) tended to be smaller systems, perhaps with less sophistication to protect themselves against cybersecurity threats, as well as fewer resources to do so," said David Bodek, senior director at S&P Global Ratings. "We've seen this in past years also with small water systems, and perhaps that's a way for the bad actors to test the waters, so to speak."
Smaller issuers often more vulnerable
"Smaller organizations are going to have much less capital to invest in security programs, security posture and security personnel than the larger organizations, but that doesn't always mean those large organizations deploy capital in ways that best suit their organization," said Omid Rahmani, associate director and public finance cyber risk lead at Fitch Ratings.
Rahmani said he looks to ensure that issuers have adequate resources, that they have cyber policies in place and that they have the organization to implement cybersecurity measures.
"We have local government entities that have really strategic personnel in place that have been able to do really great, outsized security posture planning and defense," he said. "But overall, when you get to the local level, it gets to be extremely underfunded in relation to the scope of the advancing technology."
And because threat actors know that small local governments are under-resourced, those smaller entities tend to be targeted more, said Krystal Tena, associate director at S&P.
The coordinated cyberattacks on water systems this summer bore the signs of a state actor, said Peter Scherer, senior director at KBRA. And while the impact of those attacks on smaller municipal water systems had "outcomes that give you some pause… you might take some comfort it was not worse than it was," he said.
"An attack that may appear to be small in one location may not be small if it was the exact same incident or breach someplace else," said Douglas Kilcommons, managing director at KBRA. "If you have an attack that results in service disruption, that would certainly have dramatic effects. But if you had an attack on a billing system and someone received access to proprietary information… that could be equally as bad."
KBRA asks issuers what safeguards are in place to mitigate cyber risks and what type of planning has been conducted, among other things, he said.
Federal retrenchment
Moody's Ratings warned in a 2025 sector report that the pullback of federal cybersecurity funding would raise risk exposure for local governments. It pointed to the Sept. 30, 2025, sunsetting of the State and Local Cybersecurity Grant Program as one factor leading "to additional exposure and expenses."
Launched in 2022, the $1 billion program's
"AI is helping to reduce the skill barrier for cyberattacks, so less sophisticated users are able to execute pretty harmful cyberattacks, and it's also allowing sophisticated users to operate at a faster speed," said Sanjay Motwani, assistant vice president at Moody's.
Moody's has seen cases of large, well-resourced local governments and state governments deploying AI for cyber risk prevention, but "the same opportunities that AI can provide for local governments and any public finance entity, cybercriminals have access to that, as well," said Gregory Max Sobel, vice president, municipal credit at Moody's.
As for smaller local governments, "they don't have the additional capacity to finance robust cyber risk prevention or cyber hygiene practices," Sobel said. "They've been relying extensively on the state, and prior to the expiration of the state and local government cybersecurity grant program, on the federal government, so there is a real reliance on higher levels of government by local governments."
The federal grant program is not the only form of federal help that's vanishing.
"There's been significant downsizing in the federal cyber support workforce — for example, at the FBI," Rahmani said. "There's been significant downsizing of not just the assistance programs, but the financial programs, as well. It's been really significant at CISA, which historically was the organization that did the most outreach work with our community."

Even states that had funded cybersecurity efforts are running into competing budgetary priorities. In South Dakota, the state cybersecurity support program for local governments, SecureSD, faces a loss of funding in the next two years,
Tena said since 2020, many states had ramped up cybersecurity help for local governments. "We see that in New Jersey, New York, California, Utah, Texas, as well as Florida," she said. "If there's a breach, the state has resources to assist the local government, and many states have services to help local governments prepare for an attack." But with the acceleration of AI, "there's always more that needs to be done," she said.
Scherer said that improvement in state funding of cybersecurity tapered off recently.
"Over the last five years we have been through a period where the priority of funding these protections has been very much in vogue," he said. "States relatively flush from the pandemic money had extra resources. States were going to build out infrastructure for this… (and then) the last year it has been a bit quieter."
AI as a destructive tool
S&P's Tena said AI is boosting threat actors on two fronts.
"If an entity has not patched a vulnerability... then that's a huge risk," she said. "And then, in addition to that, AI has accelerated the ability of hackers to identify new vulnerabilities."
Kilcommons said that while AI is in some ways just another tool, "there's absolutely a need to evolve as the threat evolves… AI enhances the need to do so."
That may be easier said than done for some local governments. "There are a lot of proprietary systems across issuers, and invariably there are holes," Scherer said.
Right now the defensive capabilities enabled by AI are lagging the offensive ones, Rahmani said. "Its offensive capabilities currently are ahead of its defensive capabilities simply by (virtue of) the fact that it can come up with novel vectors of attack," he said.
It's up to each organization to gauge how much AI integration it can allow "or, frankly, need(s) in (its) operations," Rahmani said, adding small-town municipal water systems probably don't need advanced AI models.
What many public sector entities could use is a chief information security officer who would act as a check, balancing deployment of new tools that might expose the organization to wider threats, Rahmani said.
Yet many local governments can't afford their own IT team, let alone a CISO. "Unfortunately, that is the norm," Rahmani said. "That's the case across most small governments, most school districts, most small critical infrastructure. Even some medium-sized."
Credit risks
Tena said when a public sector entity is attacked, S&P looks at how it impacts their operations: how quickly they recover; do they lose revenue; do critical services suffer; did the hackers access funds; did the entity pay a ransom; and do they have liquidity to cover the costs, including of remediation.
Following the cyberattacks on water systems this summer, Moody's said in a sector comment that "utilities — and the governments behind them — will likely need to commit significant resources over a sustained period to improve the cybersecurity posture of their water systems."
That ongoing investment is a credit negative, Moody's said, because it will compete with capital and rate pressures already burdening many systems.
Motwani said while it's up to each issuer to determine how to best allocate its resources, "this is a growing threat, and there's evidence of that, and it requires resources to meet that escalating threat environment."
He pointed to cyber insurance, which, being annually renewable, is arguably "retroactive in the sense that if there are attacks, an entity could be covered this cycle and covered for a particular attack, but that could change, both in premium and in coverage, in future cycles. That's another area that I think is of interest to investors, and certainly something that we're mindful of, too," he said.
Sobel noted that across all the credits Moody's rates, "68% of all of our issuers have policies and procedures governing the use of AI, but when we look at regional and local governments, we're talking about 47%.
"And it is higher for our enterprises — for housing, healthcare, higher education, infrastructure — but it's still meaningfully below median for all of our rated entities," he said. "We're seeing growth in adoption, but (there's) a lack of… policies that govern that adoption, which opens up these entities to incremental risk."
KBRA's Scherer said the rating agency is "looking for issuers that communicate an ongoing effort to maintain good cyber hygiene. It starts with the small things."
He added, "To the extent that they have had breaches, the question is what are you doing to fortify and change. Figuring out what is an appropriately sized effort to plug some of these holes and risks."
Fitch's Rahmani said while some states will be more willing to spend money on cybersecurity than others, there is no mandate for the protection of state and local governments under their umbrella.
"Each individual municipal organization is ultimately responsible for their own security posture," he said. "You can't transfer this risk to somebody else in the current environment."
But "more collaboration when it comes to shared defense" is always helpful, he said. "We just don't have a cavalry that's going to come in."









