Cybersecurity

Cyberattacks Disrupt Water Systems Across 12 States, Possibly Linked to Iran

Cyberattacks have been reported across at least 12 U.S. states targeting water systems, with officials suspecting the involvement of Iran-backed hacking groups, sources familiar with the matter told CBS News on August 5, 2026. While operational disruptions occurred, authorities confirmed that drinking water safety has not been compromised.

What Happened

Starting before July 30, 2026, multiple cyber intrusions impacted water utilities across states including Michigan, Minnesota, Georgia, New Jersey, and South Dakota. Notably, over 30 community water systems in Minnesota were affected. In Georgia, the Clayton County Water Authority—serving approximately 300,000 customers in the Atlanta area—experienced a cyber event that caused a temporary pressure drop in its water system, prompting a boil water advisory. Service was quickly restored within hours. Some utilities lost critical remote-control capabilities, forcing operators to manage pumps, valves, and water pressure manually. Federal agencies reported that attackers gained remote access to these critical controls, affecting system monitoring and operational control.

Key Facts

On July 30, the FBI, Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA) jointly issued a warning about remote cybersecurity intrusions into online infrastructure for water and wastewater systems in at least seven states. The intrusions resulted in loss of monitoring and control functionality. Cyber threat actors are suspected to be Iran-backed hackers, though no formal government attribution has been made. The attack methods resemble those used by the CyberAv3ngers group, linked to the Iranian Revolutionary Guard, which previously exploited water-system controllers in 2023 by using default credentials.

Federal advisories recommended that water authorities disconnect operational systems from the internet and reinforce password security and firewall defenses. No CVE identifiers or specific vulnerability scores were cited by officials. The timeline of attacks and affected systems continues to be investigated by authorities.

What This Means

This series of cyberattacks highlights ongoing vulnerabilities in critical infrastructure, particularly in vital public utilities like water systems. Although drinking water safety remains intact, loss of remote control and monitoring poses significant risks to timely operational responses, potentially delaying emergency interventions during incidents. Such disruptions could strain local resources and increase public health risks if left unresolved. The advisory to disconnect from the internet and strengthen cybersecurity measures underscores the necessity for water utilities to upgrade their defenses against increasingly sophisticated cyber threats.

For community residents, these events illustrate the growing intersection of cybersecurity and public health, emphasizing that protecting digital infrastructure is essential for maintaining essential services. Utilities nationwide may face pressure to accelerate modernization efforts and adopt stricter cybersecurity protocols. Coordination among federal agencies, local water authorities, and cybersecurity experts remains critical to mitigating these risks and preventing potential future attacks that might lead to contamination or service outages.

Background

The tactics mirror a 2023 campaign by the hacking group CyberAv3ngers, which had targeted U.S. water systems by exploiting default passwords to gain unauthorized access to water-system controllers. Since then, threats against water infrastructure have escalated as cyber attackers focus on critical infrastructure vulnerabilities exposed by increased digital connectivity.

What Remains Unclear

While federal agencies suspect Iran-backed hackers are responsible, official attribution has not been formally announced. The full extent of the breach across all affected states and the number of impacted water systems remain under investigation. Additionally, it is unclear whether all affected utilities have completed recommended cybersecurity enhancements or whether any data or control system manipulations went undetected beyond the confirmed incidents.

What Comes Next

Authorities continue to work with water utilities to implement stronger cybersecurity measures, including removing operating control systems from internet connectivity and enforcing stronger password and firewall protections. Federal agencies will likely maintain heightened monitoring and incident response readiness to address any evolving threats against critical infrastructure sectors.

Sources

This article is based on reporting and publicly available information from the following sources:

Read more Cybersecurity stories on Goka World News.

Ethan Clarke
About the editor

Ethan Clarke

Ethan Clarke Role: Cybersecurity Editor Ethan Clarke covers cybersecurity incidents, data breaches, online threats, ransomware, software vulnerabilities, and digital safety. His reporting focuses on confirmed details, affected systems, official advisories, and practical context without making unsupported accusations.

View all posts by Ethan Clarke