The U.S. is facing a wave of cyberattacks that have targeted water and wastewater systems in at least 12 states, including Michigan, Minnesota, Georgia, New Jersey and South Dakota. More than 30 community water systems in Minnesota were affected, and Clayton County, GA, experienced a brief pressure drop and a short boil-water advisory before service was restored. Federal investigators suspect Iran-backed actors, though no formal attribution has been made; the FBI and CISA are investigating and have warned owners to remove publicly exposed PLCs.
Wave of Cyberattacks Disrupts U.S. Water Systems in 12 States; FBI and CISA Investigate

Sources with knowledge of the situation have confirmed to multiple news outlets that a coordinated wave of cyberattacks has targeted U.S. water and wastewater systems in at least 12 states.
Scope and Immediate Effects
The states identified so far include Michigan, Minnesota, Georgia, New Jersey and South Dakota. According to CBS News, more than 30 community water systems in Minnesota were affected. In Georgia, the Clayton County Water Authority — which serves roughly 300,000 customers in the Atlanta area — reported a temporary disruption that caused a drop in water pressure and prompted a short boil-water advisory. Service was restored within hours.
Operational Impact
Officials say some intrusions disrupted utilities' ability to remotely monitor and control systems, forcing operators to switch to manual operations. Authorities reported that attackers gained remote access to equipment such as pumps, valves and water-pressure controllers, interfering with routine automation and monitoring functions.
So far, authorities say there has been no reported impact to the safety of drinking water.
Investigation and Warnings
Federal investigators have indicated that Iran-backed actors are suspected of involvement, though the U.S. government has not issued a formal attribution. The FBI confirmed it is aware of the incidents and is investigating alongside other agencies.
In a joint advisory, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian actors have targeted water systems and other critical infrastructure previously. The agencies highlighted the danger posed to programmable logic controllers (PLCs) — devices widely used to automate pumps, valves and other industrial equipment — and urged infrastructure owners to remove any PLCs that are publicly exposed to the internet.
What Operators Should Do Now
- Isolate and patch publicly exposed PLCs and other industrial controllers.
- Verify backups and incident response plans; be prepared to operate systems manually if needed.
- Coordinate with federal partners (FBI, CISA) and local public health officials when an incident affects service or public advisories.
The investigation is ongoing. Public utilities and federal agencies continue to monitor for further intrusions and are urging operators to harden network defenses and follow CISA guidance.
Help us improve.




























