Federal agencies confirm that cyberattacks linked to Iranian operatives have compromised water infrastructure across at least 12 states, forcing utilities to issue boil water advisories and switch critical systems to manual control after hackers gained access to pumps, valves, and water pressure controls.
Widespread Infrastructure Breach
The attacks affected Michigan, Minnesota, Georgia, New Jersey, and South Dakota, among others. Minnesota alone reported more than 30 community water systems impacted by the coordinated campaign. In Georgia, the Clayton County Water Authority, serving 300,000 customers in the Atlanta area, experienced a water pressure drop that forced officials to issue a boil water advisory last month. Service returned within hours, but the incident exposed vulnerabilities in critical infrastructure systems across the nation.
Several utilities lost remote-control capabilities entirely, forcing operators to revert to manual operations. Hackers successfully gained remote access to essential equipment controlling water pressure, pumps, and valves. Federal officials confirmed that drinking water remained safe throughout the attacks, with no contamination reported. The breaches primarily affected monitoring and control systems rather than water treatment processes themselves.
Federal Warning Issued
On July 30, the FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency issued a joint warning about cyber threat actors remotely accessing online infrastructure for water and wastewater systems. The alert confirmed attacks in at least seven states resulted in a loss of monitoring and control functionality. Federal agencies advised water utilities nationwide to disconnect their operating programs from the internet immediately and strengthen password protections and firewall defenses against further intrusions.
Iranian Connection Identified
The attack tactics match a 2023 campaign by CyberAv3ngers, a hacking group linked to the Iranian Revolutionary Guard. That group exploited water-system controllers using default passwords left unchanged by utilities. Security experts warn that many municipal water systems rely on outdated industrial control systems with weak cybersecurity protections, making them vulnerable targets for foreign adversaries. The coordinated nature of these attacks across multiple states suggests a deliberate campaign to test American infrastructure defenses and demonstrate capability to disrupt essential services that millions of Americans depend on daily.
