St. Cloud water
A water treatment facility in St. Cloud, one of dozens of municipalities in Minnesota affected by coordinated cyberattacks. Credit: City of St. Cloud

Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents

Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow. 

State officials in Minnesota were the first to report incidents last week, and the FBI previously said that since July 27 water and wastewater utilities in at least seven states had reported attacks that impacted operations. 

ABC News reported on Tuesday that facilities in at least 12 states are now remediating cyberattacks, including several in Michigan.  

While federal agencies have declined to publicly attribute the attacks, multiple sources pointed the finger at Iran,  which since 2023 has repeatedly targeted a specific kind of operational technology used by water and wastewater facilities

On Monday, Georgia’s Clayton County Water Authority confirmed that it “experienced a temporary disruption affecting a portion of its operational systems and water service in parts of north Clayton County.” 

The authority said it is investigating the cyber activity and that it was forced to issue a precautionary boil water advisory in response to the attack. The advisory has since been lifted after water quality testing was done. Another nearby water authority in Georgia also reported a cyber incident on Tuesday. 

In addition to facilities in Minnesota, Michigan and Georgia, a water utility in South Dakota also reported an incident. 

The Cybersecurity and Infrastructure Security Agency (CISA) released an advisory two weeks ago warning that Iranian state hackers are targeting internet-connected operational technology devices, including programmable logic controllers (PLCs).

A follow-up advisory last week from CISA said attacks on PLCs have “resulted in boil water notices and sustained manual operations.” CISA added that the threat actors are targeting water entities of all sizes. 

“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities,” CISA Acting Director Nick Andersen told Recorded Future News.  

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”

An FBI spokesperson said it is working with other agencies to protect utilities against the intruders. 

The incidents bear similar hallmarks, the FBI said. After the devices are accessed remotely, the actors change the passwords and remove the ability of officials to monitor and control the devices. 

The agency urged organizations to remove PLCs from the internet, set up firewalls, create unique passwords and only allow communication between expected control devices. 

“Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes,” the FBI explained.  

Water utilities have been a source of concern for federal cyber defenders for years due to the lack of funding available to protect systems that could have an inordinate impact on a local population in the event of a cyberattack. 

Jake Braun, a former cyber official in the Biden administration who now runs a project connecting volunteer cyber experts with water utilities, told Recorded Future News the attacks are a significant shot across the bow by Iran because of three potential impacts. 

Civilian water utilities support military installations across the U.S. and many also underpin data centers, particularly those that were targeted in Minnesota, he said. The attacks also undermine trust in the government at a time when the country is already deeply divided. 

Braun also noted the irony of Iranians specifically targeting PLCs after previous incidents where U.S. and Israeli officials allegedly used the Stuxnet worm to cause damage to Iran’s nuclear program by targeting the same operation technology. 

“They can shut off the water for our military, they can shut off the water for our economy, in particular our AI dominance, and they can undermine trust in our government to provide the most basic life-giving services,” he said. “That's really what's at the core of this. I don't think it has anything to do with any particular physical objective they were hoping to achieve with hacking these water systems.”

State officials in Minnesota were the first to report incidents last week, and the FBI previously said that since July 27 water and wastewater utilities in at least seven states had reported attacks that impacted operations. 

ABC News reported on Tuesday that facilities in at least 12 states are now remediating cyberattacks, including several in Michigan.  

While federal agencies have declined to publicly attribute the attacks, multiple sources pointed the finger at Iran,  which since 2023 has repeatedly targeted a specific kind of operational technology used by water and wastewater facilities

On Monday, Georgia’s Clayton County Water Authority confirmed that it “experienced a temporary disruption affecting a portion of its operational systems and water service in parts of north Clayton County.” 

The authority said it is investigating the cyber activity and that it was forced to issue a precautionary boil water advisory in response to the attack. The advisory has since been lifted after water quality testing was done. Another nearby water authority in Georgia also reported a cyber incident on Tuesday. 

In addition to facilities in Minnesota, Michigan and Georgia, a water utility in South Dakota also reported an incident. 

The Cybersecurity and Infrastructure Security Agency (CISA) released an advisory two weeks ago warning that Iranian state hackers are targeting internet-connected operational technology devices, including programmable logic controllers (PLCs).

A follow-up advisory last week from CISA said attacks on PLCs have “resulted in boil water notices and sustained manual operations.” CISA added that the threat actors are targeting water entities of all sizes. 

“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities,” CISA Acting Director Nick Andersen told Recorded Future News.  

“We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”

An FBI spokesperson said it is working with other agencies to protect utilities against the intruders. 

The incidents bear similar hallmarks, the FBI said. After the devices are accessed remotely, the actors change the passwords and remove the ability of officials to monitor and control the devices. 

The agency urged organizations to remove PLCs from the internet, set up firewalls, create unique passwords and only allow communication between expected control devices. 

“Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes,” the FBI explained.  

Water utilities have been a source of concern for federal cyber defenders for years due to the lack of funding available to protect systems that could have an inordinate impact on a local population in the event of a cyberattack. 

Jake Braun, a former cyber official in the Biden administration who now runs a project connecting volunteer cyber experts with water utilities, told Recorded Future News the attacks are a significant shot across the bow by Iran because of three potential impacts. 

Civilian water utilities support military installations across the U.S. and many also underpin data centers, particularly those that were targeted in Minnesota, he said. The attacks also undermine trust in the government at a time when the country is already deeply divided. 

Braun also noted the irony of Iranians specifically targeting PLCs after previous incidents where U.S. and Israeli officials allegedly used the Stuxnet worm to cause damage to Iran’s nuclear program by targeting the same operation technology. 

“They can shut off the water for our military, they can shut off the water for our economy, in particular our AI dominance, and they can undermine trust in our government to provide the most basic life-giving services,” he said. “That's really what's at the core of this. I don't think it has anything to do with any particular physical objective they were hoping to achieve with hacking these water systems.”

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.