Cyberattacks believed to be linked to hackers backed by Iran have reportedly targeted water systems in at least 12 U.S. states, according to sources familiar with the investigation.
The affected states include Michigan, Minnesota, Georgia, New Jersey and South Dakota. In Minnesota alone, more than 30 community water systems were reportedly impacted.
In Georgia, the Clayton County Water Authority, which supplies water to about 300,000 customers in the Atlanta metropolitan area, said cyber activity last month caused a temporary drop in water pressure, prompting officials to issue a boil water advisory. Water service was restored within a few hours.
Authorities said some utilities lost key remote-control functions, forcing staff to operate systems manually. In several incidents, hackers reportedly gained remote access to pumps, valves and water pressure controls.
Despite the breaches, officials said there has been no impact on the safety of drinking water.

On July 30, the Federal Bureau of Investigation (FBI), the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint warning after discovering that cyber threat actors had accessed online infrastructure used by water and wastewater systems in at least seven states.
The agencies said the attacks “resulted in a loss of monitoring and control functionality.”
Following the incidents, water utilities were urged to disconnect operational technology from the internet where possible and strengthen password security and firewall protections.
Although investigators suspect the attacks may have been carried out by hackers linked to Iran, no official attribution has been announced.
Officials noted that the methods used in the recent attacks resemble those employed during a 2023 cyber campaign by the CyberAv3ngers group, which has been associated with Iran’s Islamic Revolutionary Guard Corps and was accused of exploiting default passwords to gain access to water system controllers.





