Key Takeaways
- A Clayton County pump‑station failure on July 27 triggered a boil‑water advisory that was later linked to possible unauthorized cyber activity.
- The incident fits a broader pattern: the FBI reports water‑and‑wastewater utilities in at least seven states have faced similar cyber intrusions.
- Attackers are exploiting internet‑connected programmable logic controllers (PLCs) – often left exposed with default credentials – to tamper with water pressure and other critical functions.
- Cybersecurity experts warn that many PLCs remain unnecessarily accessible online; removing them from the public internet is the simplest immediate fix.
- While no definitive attribution has been made, CISA has warned of ongoing Iranian‑affiliated targeting of OT devices, and past Iranian‑linked attacks on U.S. water infrastructure exist.
- Experts call for mandatory cybersecurity regulations for water utilities, financial penalties for non‑compliance, and routine password changes and system updates.
Incident Overview
On July 27, the Clayton County Water Authority issued a precautionary boil‑water advisory after a pump station failed around 1 a.m., causing low or no water pressure for many customers. Crews restored pressure by approximately 4 a.m., and after water quality testing showed the supply was safe, the advisory was lifted on July 28. The authority later disclosed that the disruption might have resulted from “unauthorized cyber activity that may have caused or contributed to the incident,” noting coordination with state and federal partners, including the FBI and CISA, to investigate and secure the affected systems.
Representative Scott’s Concerns
State Representative Sandra Scott (D‑Rex) said she has heard from constituents upset about the water disruption, emphasizing that access to clean water is essential for everyone. She urged authorities to “truly get to the bottom of it,” highlighting public frustration and the need for transparency regarding what caused the outage and how similar events can be prevented in the future.
FBI Awareness and Multi‑State Context
The FBI confirmed it is aware of recent public reporting concerning cyber threats to the Water and Wastewater (WWS) sector. A bureau spokesperson stated that the agency and its interagency partners are fully engaged in protecting critical infrastructure and remain prepared to counter cyber threats of all kinds. The Clayton County episode aligns with a wider trend: the FBI’s public service announcement notes that water and wastewater utilities in at least seven states—including Minnesota, Michigan, and Wisconsin—have reported incidents to federal authorities.
Details of the Apparent Cyber Activity
Clayton County Water Authority spokesperson Erin Thomas said there is no evidence that customers’ billing or payment information was compromised. The authority immediately began working with state and federal partners to investigate the disruption and secure the affected systems. The authority’s statement suggested that unauthorized cyber activity may have caused or contributed to the pump‑station failure, marking the first public indication that a cyber intrusion could have played a role in the water pressure loss.
Easy Targets: PLC Vulnerabilities
According to an FBI public service announcement, malicious cyber actors are targeting specific models of programmable logic controllers (PLCs)—rugged industrial computers that gather data from and issue commands to other equipment. Attackers remotely access these internet‑connected devices, altering IP addresses and passwords, which can lead to a loss of view or function of connected equipment, pressure drops, and even flooding. The intrusions exploit the fact that many PLCs are left exposed online for operator convenience, making them easy entry points for hackers.
Expert Analogy: PLCs as Thermostats
Saman Zonouz, a cybersecurity professor at Georgia Tech, likens PLCs to a household thermostat: just as a thermostat senses temperature and decides whether to activate air conditioning, a PLC monitors variables such as water pressure, chlorine levels, and flow rates, then makes automatic adjustments to keep the system operating correctly. However, unlike a thermostat, PLCs often control essential processes in water treatment, power grids, oil and gas refineries, and other critical infrastructure, amplifying the potential impact of a compromise.
Exposure and Remediation Statistics
Zonouz and his research team scanned the internet and found more than 7,000 PLCs openly accessible in water treatment plants, airports, hospitals, energy facilities, and even military sites—largely because operators left them online for remote maintenance convenience. After notifying the owners, approximately 30 % of the vulnerable devices were taken off the public internet. The researchers noted that many breaches succeeded because the devices retained factory‑default usernames and passwords, or because facilities used identical passwords across multiple units, simplifying attackers’ tasks.
Basic Cybersecurity Shortcomings
Zonouz emphasized that the underlying issue is a failure to apply basic cybersecurity hygiene: changing default credentials, using unique passwords, and applying regular software updates. He remarked, “You don’t have to be a rocket scientist to do this,” underscoring that the attacks exploit simple oversights rather than sophisticated zero‑day exploits. Water systems, in particular, lag behind sectors like the power grid in mandatory cybersecurity standards, often running legacy equipment for decades without security patches.
Iran Connection and Recommendations
While no definitive attribution has been made for the Clayton County incident, the Cybersecurity and Infrastructure Security Agency (CISA) issued an April advisory warning of ongoing Iranian‑affiliated cyber targeting of internet‑connected operational technology (OT) devices, including PLCs. Iranian‑linked groups have previously struck U.S. water infrastructure, such as a 2023 attack on a Pennsylvania station. Zonouz advocates for long‑term solutions: establishing mandatory cybersecurity regulations for water utilities, imposing financial penalties for non‑compliance, and encouraging operators to adopt basic safeguards—starting with removing PLCs from the public internet to sacrifice convenience for security.

