Dozens of U.S. water utilities hit by cyber intrusions possibly tied to Iran-linked hackers
At least twelve states have reported cyber incidents affecting water utilities, with investigators suspecting actors linked to Iran’s Revolutionary Guard.
Sources familiar with the matter say cyberattacks have been reported in at least a dozen states, among them Michigan, Minnesota, Georgia, New Jersey and South Dakota. Minnesota saw over thirty community water systems breached, and in Georgia the Clayton County Water Authority, serving 300,000 Atlanta customers, suffered a pressure loss that led to a temporary boil-water notice before service was restored. Several utilities reported loss of remote-control capabilities, forcing staff to operate equipment manually after hackers accessed pumps, valves and pressure controls.
The FBI, EPA and CISA warned that the intrusions, detected in at least seven states, caused loss of monitoring and control functions but left drinking water safe. Officials advised utilities to disconnect operational software from the internet and tighten passwords and firewalls. While investigators have not formally attributed the attacks, the tactics resemble a 2023 campaign by the CyberAv3ngers, a group associated with the Iranian Revolutionary Guard.
Why it matters
Cyber attacks on water infrastructure threaten essential services and expose gaps in U.S. critical-infrastructure security.
In this story