Cyberattacks on US Water Systems Spread to 12 States; Iran Suspected
This digest was compiled by AI from multiple sources — links to the originals are below.

Cyberattacks targeting programmable logic controllers in water and wastewater systems have struck at least 12 US states, with evidence pointing to possible Iranian state involvement. The attacks, which began in Minnesota in late July, have since been reported in Georgia, Michigan, South Dakota, Alabama, New Jersey, and other states, prompting a federal advisory. While no water supply disruptions have occurred, operators were locked out of systems in some cases, and Georgia’s Clayton County issued a boil water advisory after a pressure drop.
Attack Scope
The campaign has compromised operational technology in at least a dozen states, starting with Minnesota, where over 30 water systems were targeted in late July. Threat actors modified passwords on programmable logic controllers (PLCs) to lock out operators and changed IP addresses to disconnect devices from networks. Additional affected states include Michigan, South Dakota, Alabama, New Jersey, and Georgia, where a pressure drop in Clayton County prompted a boil water advisory.
Federal Response
On July 30, the Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory warning of a significant increase in attacks on PLCs in the Water and Wastewater Systems (WWS) Sector. The FBI had earlier updated an April warning on July 22, stating that Iranian threat actors are targeting PLCs from vendors such as Rockwell Automation, Schneider Electric, and Siemens. CISA urged critical infrastructure operators to remove publicly exposed PLCs from the internet immediately.
Iran Connection
The intrusions bear the hallmarks of Iranian state-linked groups, though no group has claimed responsibility. The attacks appear aimed at stoking fear rather than causing permanent damage or extortion, with no major supply disruptions reported. However, in several states, operators were forced to resort to manual workarounds after being locked out of control systems.
What's Next
The FBI and CISA are investigating the full extent of the compromise while water utilities race to secure Internet-exposed OT. It remains unclear whether the attackers will escalate to more disruptive actions, such as contaminating supplies or causing prolonged outages.
1 source
Cyberattacks on US Water Systems Spread to 12 States; Iran Suspected



