Recent reports indicate that cyberattacks targeting water systems across the United States, believed to be connected to hackers supported by Iran, have been identified in at least twelve states, as disclosed by sources to CBS News on Wednesday.
The affected states include Michigan, Minnesota, Georgia, New Jersey, and South Dakota. Notably, over 30 community water systems in Minnesota have been reported to be affected, according to previous updates from CBS News.
In Georgia, the Clayton County Water Authority, which provides service to approximately 300,000 residents in the Atlanta region, experienced a decline in water pressure due to cyber activities last month, resulting in the issuance of a boil water advisory. Fortunately, service was restored within a few hours.
Several utilities have reported the loss of essential remote-control capabilities, necessitating a shift to manual operation for their systems. In some instances, hackers were able to gain remote access to pumps, valves, and water pressure controls.
As of now, officials have confirmed that these cyberattacks have not compromised the safety of drinking water, which continues to be deemed safe for consumption.
On July 30, a joint alert was issued by the FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency, warning that cyber threat actors had remotely accessed online infrastructure associated with water and wastewater systems in at least seven states. This intrusion resulted in a loss of both monitoring and control functionalities.
Water agencies were advised to disconnect their operational systems from the internet and to enhance their password security and firewall protections.
While federal authorities suspect the involvement of Iran-backed hackers in these incidents, no formal attribution has been established yet.
The methods employed in these attacks bear similarities to a campaign from 2023 conducted by the CyberAv3ngers, a group associated with the Iranian Revolutionary Guard, which exploited water system controllers using default passwords.















