States affectedAt least 12
as of Aug 6
Named statesMinnesota, Michigan
Georgia, New Jersey
South Dakota
AttributionPreliminary Iranian
(not confirmed)
First reportedJuly 26, 2026
Minnesota
What happened
Sources familiar with the investigation told CBS News on August 6 that cyberattacks on US water systems suspected to be linked to Iranian-backed hackers have been confirmed in at least 12 states, including Michigan, Minnesota, Georgia, New Jersey, and South Dakota. The incidents began on July 26 and 27 with the coordinated disruption of more than 30 community water systems across Minnesota, covered in Issue 97. The scope expanded steadily through the following week. The FBI and EPA issued a joint public service announcement on July 30 warning water and wastewater utilities in at least seven states had reported incidents with some malicious activity degrading operations. By August 4, reporting expanded that count to 12 states. In Georgia, the Clayton County Water Authority, which serves approximately 300,000 customers in the Atlanta metropolitan area, said cyber activity caused a water pressure drop during late July and forced the agency to issue a boil water advisory. Service was restored within hours. In Minnesota, investigators from the FBI, CISA, and the EPA have conducted on-site assessments at affected utilities. Federal officials have declined to publicly attribute the campaign, though multiple sources across outlets have named Iranian-affiliated actors as the most likely responsible party. The Wikipedia article on the Minnesota incident, citing reporting from The New Republic, notes investigators described Iranian hackers as probably responsible while stressing that assessments could change. The CyberAv3ngers group, associated with Iran's Islamic Revolutionary Guard Corps and previously documented by CISA for targeting internet-facing programmable logic controllers at US water facilities, is the actor class consistent with the techniques observed. No drinking water safety issues have been confirmed beyond the temporary Georgia boil water advisory.
Why it matters
The expansion from one state to twelve in eleven days indicates either a single coordinated campaign that was larger than initially understood, or a sustained actor conducting sequential intrusions against a consistently vulnerable sector. Either framing is operationally significant. Water and wastewater infrastructure in the United States is predominantly operated by small community utilities with limited cybersecurity staffing and budgets. The EPA's own 2024 audit found that more than 70 percent of audited water systems were failing to meet baseline statutory security requirements. The Georgia boil water advisory is the first confirmed drinking water impact from this campaign and demonstrates that operational technology compromise at water facilities can reach public health outcomes, not just operational inconvenience.
Don't miss
CISA Advisory AA26-097A, updated on July 22, documented Iranian-affiliated actors targeting internet-facing programmable logic controllers across US critical infrastructure and expanded the scope of observed exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation. That advisory was published four days before the Minnesota attacks began. The timing and targeting profile are consistent across both the advisory and the observed campaign. Water utilities that have not reviewed AA26-097A and implemented its recommendations for PLC network isolation, project file integrity verification, and internet-facing device removal should treat the 12-state scope of this campaign as a direct operational warning. CISA has separately published CI Fortify guidance with sector-specific steps for water and wastewater systems.
Potential actions
- Water and wastewater utilities should review CISA Advisory AA26-097A and the CI Fortify guidance immediately. Priority steps include isolating internet-facing operational technology systems, verifying PLC project file integrity against known clean backups, and logging all remote access to field control equipment.
- Utilities in states not yet publicly identified should not assume they are outside the campaign scope. The FBI and EPA joint advisory recommends that all water utilities report any anomalous operational technology activity to the FBI and CISA regardless of whether they believe they have been targeted.
- For utilities using programmable logic controllers from Rockwell, Schneider Electric, or Siemens on internet-accessible network segments, disconnect or firewall those devices from internet exposure and implement deny-by-default access rules as an immediate measure independent of longer-term patching cycles.
The Sip
Thirty communities in Minnesota became twelve states in eleven days. A Georgia utility serving 300,000 people issued a boil water advisory. The campaign is ongoing. The advisory that described exactly this kind of attack was published four days before it started. Review AA26-097A today.