Michigan, Georgia confirm public water system attacks linked to Iranian hacking spree
Four US states now confirm attacks – but the FBI says at least seven were targeted.

Aerial landscape of water tower in DeKalb County, Georgia. Image by Andrew Baum | Shutterstock
Michigan and Georgia have confirmed that multiple public water systems across both states were targeted in last week’s critical infrastructure hacking campaign linked to Iranian nation-state actors.
Last week, at least 30 municipal water and wastewater treatment systems were targeted in Minnesota, while South Dakota also reported attacks in Rapid City, the state’s second-largest city, located about a half hour’s drive from Mt. Rushmore.
The attacks caused multiple disruptions across the public water supply and forced staff in some facilities to use manual workarounds to continue operations until systems were restored.
Now officials in Michigan and Georgia have come forward announcing they too were targeted in what the FBI has referred to as a coordinated seven-state hacking campaign.
The three other states have yet to be identified by authorities.
Joseph Perry, cybersecurity researcher and advanced services lead at Arcova, warns the attackers may be seeking long-term access rather than immediate disruption.
"Threat actors are increasingly focusing on essential infrastructure providers as part of larger campaigns against groups of similar organizations rather than as isolated targets,”Perry says.
“Gaining access to operational environments can provide attackers with visibility into systems, reveal weaknesses, and create opportunities for future action,” he says.
Georgia and Michigan come forward
According to The Register, officials say operators detected “hostile cyber activity” at multiple water facilities in both states over the past weekend, consistent with the July 26th-27th attacks in Minnesota.
Michigan officials said there were no reports of operational disruptions or risks to public health, such as water contamination or threats to drinking water safety.
Nine Michigan water systems were involved in the alleged Iranian hacking spree, including Michigan’s Department of Environment, Great Lakes, and Energy (EGLE), The Register said.
"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," EGLE communications director Dale George told the outlet.
In Georgia, a local ABC News affiliate reported water systems operators were able to “identify the vulnerabilities rather quickly,” averting any major disruptions, although it's unclear how many facilities may have been targeted.
In Minnesota, the attackers were able to infiltrate operational systems to change passwords and IP addresses – locking operators out of critical water equipment.
At least one municipal well and treatment plant were knocked offline.
IRGC actors tied to attacks
Minnesota IT Services (MNIT), responding to the July breach, said “the timing, methods of access, and targeted infrastructure share characteristics with previous coordinated attacks against US critical infrastructure,” which also involve specific components of industrial control systems (ICS), called PLCs.
PLCs, or Programmable Logic Controllers, are internet-connected computers used to automate facility operations.
When tampered with, attackers can physically force system shutdowns, cause damage to equipment by altering pump speeds and shutting off valves, and corrupt the water treatment process.
Attackers can also spoof data, tricking operators with fake status readings.
Paul Bischoff, consumer privacy advocate at Comparitech, agrees the campaign appears more consistent with state-backed activity than financially motivated cybercrime.
"I think the question a lot of people are asking now is whether these attacks are coming from a state-sponsored threat actor, e.g. Iran, or more typical profit-seeking cybercrimnals. Most experts seem to agree the attacks were linked to Iran at this stage.
"A cyberattack on a water treatment plant is nothing new. We see ransomware attacks on all levels of public infrastructure all of the time," Bischoff says. He also says these attacks often come from cybercriminal gangs looking for “low-hanging fruit – easily phished employees and known software vulnerabilities.”
“State-sponsored attacks tend to be more targeted and persistent. They can use more sophisticated techniques, stockpile vulnerabilities, and pay a lot of money for initial access,"Bischoff says.
CISA warns of critical infrastucture attacks
Barely a week before the attacks began, the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a joint advisory warning critical infrastructure operators to harden water and wastewater treatment systems against an imminent threat from Iranian-affiliated hackers.
Although the FBI has not named a specific threat actor, security insiders have linked the campaign to the CyberAvengers – a known hacktivist collective with ties to the Islamic Revolutionary Guard Corps (IRGC).
The group has successfully breached other US water and wastewater facilities in the past.
To reduce the risk of compromise, the FBI is urging operators to "disconnect PLCs from direct internet exposure, set up strong, unique passwords, and use an access control list (ACL) to allow only authorized communication between control system devices."
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Perry also says that for smaller and rural service providers, these attacks reinforce the need for greater cybersecurity collaboration.
He says organizations should explore focused partnerships and communities that allow them to share best practices, improve access to resources, and address common challenges together.
“Similar to the benefits provided by larger information-sharing groups, smaller and more specialized communities can help organizations strengthen their collective resilience against evolving threats,” Perry says.
Has your password leaked?