Cyberattacks targeting U.S. municipal water systems have been reported in at least 12 states, with federal agencies investigating possible links to Iran-backed hackers. The incidents, which occurred over the past month, prompted immediate manual overrides and heightened security measures across affected utilities.
At least 30 community water systems in Minnesota were impacted, while Georgia’s Clayton County Water Authority reported a water pressure drop that triggered a boil water advisory. Officials confirmed no drinking water contamination occurred, and services were restored within hours in most cases. The FBI, EPA, and CISA issued a joint warning on July 30, noting that cyber threat actors had remotely accessed water and wastewater systems in seven states, disrupting monitoring and control functions.
Utilities responded by disconnecting systems from the internet and reinforcing cybersecurity protocols, including password protections and firewall updates. In several instances, hackers gained access to pumps, valves, and pressure controls, forcing operators to switch to manual operations. The tactics mirrored a 2023 campaign attributed to CyberAv3ngers, a group linked to Iran’s Revolutionary Guard, which exploited default passwords to infiltrate water-system controllers.
How the attacks unfolded
Hackers targeted programmable logic controllers (PLCs), small computers that manage industrial equipment like pumps and valves. These devices read sensor data—such as water pressure and chemical levels—and automatically adjust operations. By breaching PLCs, attackers could manipulate equipment remotely, though utilities mitigated risks by shutting down affected systems and deploying personnel to operate machinery manually.
The 152,000 public drinking water systems in the U.S. rely on interconnected infrastructure, from treatment plants to distribution networks. A breach in any component could disrupt supply chains or trigger safety protocols, though no incidents resulted in unsafe drinking water.
Federal response and ongoing investigations
The FBI, EPA, and CISA have not formally attributed the attacks to any group, though suspicion remains focused on Iran-linked actors due to similarities with past campaigns. The July 30 warning urged water utilities to isolate operational systems from the internet and audit their cybersecurity defenses.
Utilities in Michigan, New Jersey, South Dakota, and other states reported varying degrees of intrusion, with most resolving issues without lasting impact. The Clayton County incident in Georgia highlighted the vulnerability of even large systems, as a brief pressure drop affected 300,000 customers before service was restored.
Long-term implications
The attacks underscore the growing threat to critical infrastructure, particularly as water systems increasingly rely on digital controls. Experts note that while no drinking water was compromised, the incidents reveal potential avenues for sabotage in an era of escalating cyber warfare. Utilities are now reviewing emergency protocols and cybersecurity investments to prevent future breaches.