Georgia and Michigan have confirmed cyberattacks on their water facilities, adding to a multistate campaign that has struck at least seven states since late July, according to an FBI advisory posted last week. Iran-backed hackers are the prime suspects, though the bureau hasn't publicly named a culprit. Both states said the intrusions didn't disrupt operations or threaten public health.
Michigan's Department of Environment, Great Lakes, and Energy received reports from nine water systems describing hostile cyber activity that matched patterns seen in Minnesota's attacks the week before. Department communications director Dale George said the state got "a small number" of reports aligned with Minnesota's experience, but all facilities kept running safely and local operators resolved the issues without public health consequences. Georgia also told ABC News it was affected but kept damage contained. Neither state has issued any public notification about the breaches. Minnesota was the first to confirm it was targeted, with more than 30 community water systems hit over July 26-27, though it hasn't officially blamed Iran either.
The FBI advisory, released last week, stated that since July 27, 2026, water and wastewater utilities in at least seven states have reported incidents, and some of that activity degraded water operations. The bureau said it has so far observed the activity only against Rockwell Automation and Allen-Bradley programmable logic controllers, though it warned organizations using other manufacturers' devices to follow the same security hardening advice. A broader CISA advisory updated July 22 warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors. Security researchers at Tenable were among the first to publicly suspect Iran's involvement, pointing to similarities with earlier attacks by the IRGC-linked CyberAv3ngers group.
President Trump rejected the Iran theory during a cabinet meeting Friday, instead blaming Minnesota's governor without offering evidence. "They blame it on Iran. I don't think so. I blame it on Minnesota because they're grossly incompetent," he told reporters, adding that he thought the governor was behind it and didn't believe there was an Iranian cyberattack. Minnesota's Democratic Governor Tim Walz pushed back, suggesting Iran was indeed responsible and pointing to Trump's funding cuts as leaving water facilities more vulnerable. "This is what modern warfare looks like," Walz said, adding that DOGE took an axe to CISA and left the US exposed to cyberattacks, though Minnesota's experts identified the vulnerability quickly and worked with local communities to stop it.
The attacks highlight how critical infrastructure like water systems has become a front line in state-sponsored cyber warfare, with adversaries targeting industrial control systems that run essential services. The focus on programmable logic controllers — the hardware that operates pumps, valves, and treatment processes — shows attackers are moving beyond data theft to potentially disruptive sabotage. While none of the seven states reported serious operational damage this time, the FBI's acknowledgment that some activity degraded water operations suggests at least partial success in disrupting service. The breadth of the campaign, spanning at least seven states in just over a week, points to a coordinated effort rather than opportunistic probing.
The attacks come as federal cybersecurity resources face budget pressures, with Walz specifically citing cuts to CISA as weakening defenses. The FBI is continuing its investigation without public attribution, while state officials are left balancing transparency with security concerns — neither Georgia nor Michigan has warned residents despite confirmed breaches. For water utilities nationwide, the message is clear: harden your PLCs now, regardless of manufacturer, because this threat isn't going away.

