Cyberattacks on US Water Systems Trigger Boil Water Advisory in Georgia
Threat actors exploited internet-exposed controllers across multiple states, locking out operators and disrupting critical infrastructure.
Cyberattackers have targeted programmable logic controllers (PLCs) in water and wastewater systems across at least a dozen US states, causing operational disruptions to critical infrastructure. The campaign highlights a systemic vulnerability in how the United States manages its decentralized water utilities.
According to the Cybersecurity and Infrastructure Security Agency (CISA), the attackers targeted operational technology (OT) systems that were exposed to the public internet. The threat actors gained access to the PLCs and modified passwords to lock out legitimate operators, while simultaneously changing IP addresses to disconnect the devices from the network. While many of these incidents required manual workarounds to restore service, the impact reached a critical level in Clayton County, Georgia, where cyber activity caused a drop in water pressure that forced officials to issue a boil water advisory.
A Legacy of Vulnerability
The scale of the risk is driven by the fragmented nature of the US water sector, which consists of approximately 170,000 drinking water and wastewater systems. Most of these systems are small and decentralized, often running OT installed by third parties.
Much of this infrastructure relies on legacy technology designed for physical isolation rather than digital security. These systems frequently lack modern protections, such as multi-factor authentication (MFA). Vulnerabilities are often introduced when non-IT staff or third-party integrators install cellular modems or configure port forwards for remote access without notifying central security teams, effectively leaving the controllers open to the public internet.
Implications for National Security
These attacks demonstrate that critical US infrastructure can be compromised using low-complexity exploits. While the current activity appears to be driven by hacktivism intended to stoke fear rather than a desire to cause permanent physical destruction, the ability to manipulate water pressure proves that adversaries can disrupt essential services. Such disruptions can quickly escalate into public health crises if water quality or availability is compromised on a larger scale.
The coordination and scale of the campaign point to a well-organized adversary that is likely technically capable of more significant operations.
Future Outlook
The FBI and EPA have issued warnings regarding these attacks, specifically highlighting vulnerabilities in Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs. Security officials are now urging utilities to audit their internet-facing devices and ensure that OT systems are not directly accessible from the web. The industry must now grapple with the urgent need to modernize security protocols across thousands of small-town utilities that remain the weakest links in the national infrastructure chain.