ATLANTA, Ga. — A recent series of cyberattacks targeting water and wastewater utilities across the United States has reached Georgia, raising new concerns about the security of the computer systems that help control one of the nation’s most essential services.
At least three Georgia water systems — Clayton County, Columbus and Coweta County — have reported cyber incidents connected to the broader wave of attacks or occurring during the same period. Federal authorities are investigating attacks affecting utilities in multiple states. (CBS News)
Reports have raised the possibility of connections to Iranian-affiliated hackers, but there is an important distinction: federal authorities have warned separately about Iranian-affiliated cyber activity targeting critical infrastructure, while the FBI’s July 30 warning about the latest water-system attacks did not publicly attribute that entire campaign to Iran. (FBI)
One of the most significant incidents occurred at the Clayton County Water Authority on July 27. The authority reported unauthorized cyber activity that may have contributed to a temporary disruption of operational systems and water service in portions of north Clayton County. Reduced water pressure prompted a precautionary boil-water advisory. Service was restored within hours, and subsequent testing confirmed the water met applicable safety standards. (Clayton County Water Authority)
Columbus Water Works also reported a cyber breach during the same period. Officials said the incident did not disrupt water service and emphasized that the water supply remained safe. (ajc) In Coweta County, officials said hackers gained access to the water system on July 27.
Coweta Water and Sewage Authority CEO Jay Boren said attackers began changing passwords and shutting down controls. The utility’s technology staff detected the intrusion after losing communication with equipment controlling valves and pump stations. The system switched to manual operations while passwords were reset. Officials said water service and customer information were not affected. (https://www.atlantanewsfirst.com)
The incidents have drawn federal attention partly because the targets aren’t simply office computers. On July 30, the FBI and Environmental Protection Agency warned that malicious actors were attacking internet-connected programmable logic controllers, or PLCs, used by water and wastewater utilities. These devices can control physical equipment involved in water operations, including pumps and valves.
The FBI said utilities in at least seven states had reported incidents beginning July 27 and that some attacks degraded water operations. Later reporting indicated incidents had been reported in at least 12 states. (FBI) Federal officials recommended that utilities remove vulnerable controllers from direct exposure to the internet, change default passwords and strengthen protections surrounding operational equipment.
What about the Iran connection? This is where separating confirmed information from speculation becomes especially important. The FBI issued a warning on July 22 specifically addressing Iranian-affiliated cyber actors exploiting programmable logic controllers across U.S. critical infrastructure. (FBI)
Separately, the Georgia Association for Water Professionals reportedly circulated a security bulletin warning Georgia utilities about disruptive threats associated with operatives affiliated with Iran’s Islamic Revolutionary Guard Corps. (AJC Feeds) National reporting has also cited officials and cybersecurity experts investigating whether the latest attacks are connected to Iran-backed hackers. (CBS News)
However, the FBI has not publicly declared that Iran was responsible for every incident in the recent multistate campaign or specifically attributed each of the Georgia breaches to the Iranian government. For that reason, Hazlehurst Now believes it would be inaccurate at this point to characterize the situation simply as “Iran attacked Georgia’s water system.”
What can be confirmed is that Georgia water utilities were targeted, federal authorities are investigating a broader cyber campaign against water infrastructure, and Iranian-affiliated cyber threats to critical infrastructure have been the subject of separate federal warnings.
The incidents also raise questions beyond metro Atlanta. Could smaller Georgia communities be vulnerable?Many modern water and wastewater systems depend on computerized equipment to monitor and operate pumps, valves and other infrastructure. A cyberattack doesn’t necessarily mean someone can simply “poison the water,” but unauthorized access to operational technology can potentially interfere with the physical operation of a system.
The Georgia Environmental Finance Authority warns that cyberattacks against water systems could result in service outages or manipulation of water pressure and potentially threaten treatment and distribution operations. (Georgia Environmental Finance Authority)
Georgia officials recommend safeguards including multifactor authentication, strong and unique passwords, network intrusion detection, regular software updates, secure backups and improved protection of operational technology.
State financing programs are also available to help eligible water systems make cybersecurity improvements. (Georgia Environmental Finance Authority)
There has been no information found by Hazlehurst Now indicating that the Hazlehurst or Jeff Davis County water systems were involved in the recent attacks.
The Georgia incidents do, however, demonstrate that cybersecurity is no longer solely an information-technology issue. When computers control pumps, valves and other pieces of public infrastructure, a cyberattack can potentially have consequences in the physical world.
Federal authorities continue to investigate the recent attacks and are urging water and wastewater utilities to strengthen their defenses.




