Cyber Incident Victim: Clayton County
Timeline
Summary
A coordinated cyberattack targeted industrial technology at water and wastewater facilities across several states, disrupting operations and prompting officials to issue boil water advisories, including in Clayton County where a pump station failure was detected overnight. Investigators linked the activity to Iranian‑linked actors exploiting exposed devices with default credentials, while federal agencies worked with sector groups to share intelligence and restore services. The incident highlighted vulnerabilities in operational technology and spurred calls for increased funding and information sharing across the water sector.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Between July 26 and July 28, 2026, a series of cyberattacks targeted water and wastewater facilities across multiple states. In Clayton County, located outside Atlanta, operators detected a pump station failure in the middle of the night. The failure prompted local officials to issue a brief boil water advisory for residents. The advisory was issued after the pump station failure was identified as part of a broader pattern of disruptions. Similar incidents were reported in Minnesota, New Jersey and Michigan during the same period. The attacks were described by state and federal officials as a coordinated cyberattack against industrial technology nationwide.

The boil water advisory in Clayton County remained in effect until officials confirmed that the immediate threat to public health, safety and welfare had been addressed. While the advisory was active, residents were instructed to boil water before consumption or use bottled water. In Minnesota, communities such as Braham and Maple Plain experienced plant outages that led to temporary water conservation measures and the use of backup supplies. In Braham, operators took the affected plant offline, drew on a stored backup supply, and restored service after assuming manual control of the pump. WaterISAC convened a call for its members to share intelligence from federal agencies, and the EPA released a public webinar discussing urgent operational matters related to cyber threats to the water sector. The FBI confirmed that at least seven states had experienced comparable attacks on water and wastewater facilities and stated that its investigation was ongoing.
Cybersecurity experts noted that the attackers focused on devices exposed to the open internet with unchanged default credentials, which allowed them to manipulate operational technology. Officials from the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency had previously issued an advisory about Iranian-linked hackers seeking vulnerabilities in similar industrial equipment. Although no group claimed responsibility, some experts told NPR that intelligence linked the activity to the Iranian Revolutionary Guard Corps, describing the attacks as opportunistic but likely tied to the ongoing conflict. Former White House acting principal deputy national cyber director Jake Braun characterized the incidents as a signal of Iran's ability to disrupt water services to military and economic targets. The attacks contributed to broader concerns about the vulnerability of aging operational technology across critical infrastructure sectors. Federal, state and local partners continued to coordinate response efforts while assessing the full scope of the incidents.
