Home Part of States Newsroom
News
Expert says Georgia water system attack highlights critical security deficiencies

Share

Expert says Georgia water system attack highlights critical security deficiencies

Aug 04, 2026 | 4:39 pm ET
By Ross Williams
Expert says Georgia water system attack highlights critical security deficiencies
Description
Some Clayton County residents experienced low water pressure or a lack of water last week after what may have been a cyber attack. (Kentucky Lantern photo by Sarah Ladd)

Clayton County authorities say a boil water advisory and low water pressure may have been part of a multistate cyber campaign targeting water infrastructure that could be linked to Iran.

Rex Democratic state Rep. Sandra Scott said she’s heard from constituents upset about the incident.

“It is critical that they truly get to the bottom of it because we know that we all need water,” she said

The incident comes amid cyber attacks on municipal water systems in at least seven other states, according to the FBI, including Minnesota, Michigan and Wisconsin.

But Jenna Sellitto, a public affairs specialist with the Atlanta FBI office, would not confirm any specific incident or details.

“The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors,” Sellitto said in a statement. “The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties.”

The apparent attack

On July 27, the Clayton County Water Authority issued a precautionary boil water advisory after it said a pump station failed at around 1 a.m., causing some customers to experience low water pressure or no water whatsoever.

Crews restored pressure by around 4 a.m., and the boil advisory was lifted on July 28 after testing showed the water was safe to consume, the authority said.

On Monday, the water authority announced the issue may have been the result of “unauthorized cyber activity that may have caused or contributed to the disruption as utilities nationwide are facing a growing number of cyber threats targeting critical infrastructure.” The cyberattack was first reported by WSB-TV.

In a statement, authority spokesperson Erin Thomas said there is no evidence that customers’ billing or payment information was compromised and that the authority immediately began coordinating with state and federal partners, including the FBI and the federal Cybersecurity and Infrastructure Security Agency to investigate the incident and secure the affected systems.

Easy targets

According to an FBI public service announcement, water and wastewater utility companies in at least seven states have reported incidents to federal authorities.

The FBI says “malicious cyber attackers” are targeting specific models of programmable logic controllers, rugged industrial computers that can collect data from and issue commands to other equipment.

According to the agency, the malicious actors are remotely accessing the internet-connected controllers and remotely tampering with them, including by changing IP addresses and passwords. The attacks have resulted in “a loss of view, and in some cases function, of connected equipment” as well as “loss of pressure and flooding,” according to the FBI.

Georgia Tech cybersecurity professor Saman Zonouz compares programmable logic controllers to your thermostat, which detects the temperature in your home and determines whether to turn on the air conditioning. But the programmable logic controllers can detect multiple factors like water pressure, chlorine levels and more and make the appropriate adjustments.

The same devices are used across industries and in other essential infrastructure like power grids and oil and gas refineries, but Zonouz said they are often critically vulnerable to infiltration.

Zonouz and his fellow researchers found more than 7,000 programmable logic controllers  open and accessible on the internet in water treatment plants, airports, hospitals, the energy sector and even military facilities – mostly for convenience’s sake.

“The reason that attacks of last week happened is because these (devices) in the US and all over the place internationally usually are exposed to the internet either misconfigured or for the operator’s convenience purposes so that they can remotely maintain and operate the processes when they’re not in person in the plant,” he said.

The researchers alerted the devices’ owners that they were vulnerable and found that 30% took them off the public internet.

Part of that vulnerability comes down to the type of basic cybersecurity principles applicable to homes and small businesses. Zonouz said the team was able to get into many of the devices because they had the original manufacturer usernames and passwords they shipped with, or people in large facilities with multiple devices gave them all the same passwords, making malicious hackers’ jobs easier.

“You don’t have to be a rocket scientist to do this,” he said.

Water systems tend to be more vulnerable than the power grid or oil and gas because that sector doesn’t have the same mandatory cybersecurity requirements, Zonouz added, and systems typically run for decades without security updates.

Iran connection probed

It’s not yet clear who is behind the incidents or whether they all come from the same group, but the Cybersecurity and Infrastructure Security Agency warned in an April advisory of “ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs).”

The U.S. and Iran are locked in an ongoing conflict that has embroiled much of the region, and Iranian leaders have vowed to retaliate to U.S. strikes.

Groups affiliated with Iran have previously targeted U.S. water infrastructure, including a 2023 attack on a station in Pennsylvania.

In the long term, Zonouz said the government should establish mandatory cybersecurity regulations for water systems with financial penalties for non-compliance, but he said he hopes these incidents cause operators to take simple security steps.

“The first thing to be done really is just take them off the internet,” he said. “That’s the simplest fix to this problem to start with, to sacrifice convenience of operators for security.”