At Least 12 U.S. States Report Cyberattacks on Water Systems Possibly Linked to Iran‑Backed Hackers

0
23

Key Takeaways

  • Cyber intrusions have hit community water and wastewater systems in at least a dozen U.S. states, with officials suspecting Iranian‑backed hackers.
  • In Minnesota, more than 30 community water systems showed signs of compromise; Georgia’s Clayton County Water Authority suffered a pressure drop that triggered a boil‑water advisory.
  • Attackers gained remote access to pumps, valves and pressure controls, forcing some utilities to switch to manual operation, but drinking‑water quality has remained safe.
  • The FBI, EPA and CISA issued a joint warning on July 30 urging utilities to disconnect operational technology from the internet and strengthen passwords and firewalls.
  • The tactics resemble a 2023 campaign by the hacker group CyberAv3ngers, which exploited default credentials on water‑system controllers.
  • No formal attribution has been made, yet the pattern of activity aligns with known Iran‑linked cyber operations targeting critical infrastructure.

Overview of the Reported Incidents
According to sources who spoke to CBS News on Wednesday, cyberattacks targeting U.S. water and wastewater systems have been identified in at least a dozen states. The intrusions involve unauthorized remote access to supervisory control and data acquisition (SCADA) platforms that manage pumps, valves, and pressure regulators. While monitoring and control functions have been disrupted, officials confirm that drinking‑water safety has not been compromised. The pattern prompted federal agencies to issue a joint alert highlighting the growing threat to essential public‑health infrastructure.

State‑by‑State Breakdown
The states named by sources include Michigan, Minnesota, Georgia, New Jersey, and South Dakota, with additional reports emerging from other jurisdictions. Minnesota saw more than thirty community water systems exhibit anomalous logins and unexpected command executions. Georgia’s Clayton County Water Authority, serving roughly 300,000 residents in the Atlanta area, experienced a noticeable pressure drop that led to a boil‑water advisory. Utilities in Michigan and New Jersey reported intermittent loss of remote‑control capability, forcing operators to revert to manual oversight. South Dakota’s smaller systems also noted irregular traffic on their control networks.

Impact on Clayton County Water Authority (Georgia)
On the day of the incident, operators at the Clayton County Water Authority observed a sudden decline in water pressure across parts of the distribution network. The drop triggered a boil‑water advisory as a precaution. Technicians restored normal pressure within hours by switching affected pumps to manual control and isolating the compromised remote‑access points. No contamination was found in water samples, and the advisory was lifted after pressure stabilized and quality tests confirmed safety. The episode illustrates how cyber interference can cause operational disruption even when water quality remains safe.

Technical Nature of the Intrusions
Investigators reported that the threat actors gained remote access to programmable logic controllers (PLCs) and related SCADA components that regulate pumps, valves, and pressure sensors. By manipulating these devices, attackers could alter flow rates, cause pressure fluctuations, or shut down critical equipment, which explains the loss of monitoring and control functionality noted in the federal warning. In several cases, utilities were compelled to disconnect their control systems from the internet and operate solely in manual mode to prevent further manipulation. The intrusions did not alter chemical dosing or introduce contaminants, which is why drinking‑water safety has been preserved thus far.

Federal Response and Guidance
On July 30, the Federal Bureau of Investigation, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency released a joint advisory warning that cyber threat actors had remotely accessed online infrastructure for water and wastewater systems in at least seven states, resulting in a loss of monitoring and control capability. The agencies urged water utilities to immediately disconnect operational technology from the internet, enforce strong, unique passwords, enable multi‑factor authentication, and review firewall configurations. They also recommended conducting comprehensive network scans for unauthorized devices and enhancing logging to detect anomalous activity promptly.

Attribution Suspicions and Link to Iran‑Backed Actors
Federal investigators have not issued a formal attribution, but sources say the observed tactics resemble those of Iran‑backed hacking groups. The suspicion is based on known exploit patterns, timing, and infrastructure that match prior Iranian cyber operations targeting critical infrastructure. Officials stress that attribution remains provisional without definitive evidence, yet the pattern warrants heightened scrutiny of any Iranian‑linked threats to U.S. water sectors.

Historical Context: The CyberAv3ngers Campaign
The current activity resembles a 2023 campaign by the hacker group CyberAv3ngers, linked to the Iranian Revolutionary Guard Corps. Attackers then scanned for water‑system controllers using default or weak passwords, logged in, and altered pump speeds and valve positions. Their approach—exploiting default credentials, using open‑source scanners, and maintaining low‑profile persistence—matches the tactics observed today, indicating a possible continuation or imitation of that earlier effort.

Implications for Critical Infrastructure Security
These incidents highlight the vulnerability of essential services that rely on networked control systems for efficiency. A cyber intrusion disrupting pressure or storage can erode public trust, provoke costly emergency responses, and, if prolonged, endanger public health. The water sector often lags behind power and finance in regulation and cybersecurity resources, relying on legacy gear that attackers find appealing. The events thus urge utilities, regulators, and federal partners to prioritize resilience, segment critical networks, and invest in modern threat detection.

Recommended Mitigations and Ongoing Vigilance
Experts recommend that water utilities adopt multi‑factor authentication for all remote‑access points, replace default passwords with strong, unique passphrases, and segment operational technology from corporate and guest networks. Regular patching, continuous monitoring for anomalous logins, and SCADA‑focused intrusion detection are essential. Tabletop exercises simulating pressure loss or valve manipulation improve readiness, and sharing information via the WaterISAC keeps utilities informed of emerging threats.

Conclusion and Outlook
Although the cyberattacks have so far failed to contaminate drinking water, the loss of control and monitoring functions demonstrates that adversaries can interfere with the reliable delivery of a vital public service. Federal agencies continue to investigate the incidents, collaborate with state authorities, and work with the private sector to harden water‑system defenses. As threat actors refine their techniques, sustained investment in cybersecurity training, technology upgrades, and cross‑sector coordination will be crucial to safeguarding U.S. water infrastructure against future attacks.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here