Clayton County Water Authority
Incident posture
Linked entities
- Victim
- Clayton County Water Authority
- Threat actors
- 1 actor
- Sources
- 4 sources
Timeline
Summary
The Clayton County Water Authority, serving 300,000 customers in the Atlanta area, experienced cyber activity that caused a water pressure drop and prompted a boil water advisory before service was restored. The incident is part of a broader pattern of cyberattacks on water systems in multiple states where attackers gained remote access to pumps, valves and pressure controls, leading some utilities to switch to manual operation while drinking water safety remained unaffected. Federal agencies have warned of such intrusions, advised disconnecting online controls and strengthening passwords, and suspect Iran‑linked actors though no formal attribution has been made.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In July 2026 the Clayton County Water Authority, which serves approximately 300,000 customers in the Atlanta metropolitan area, reported that cyber activity detected on its systems caused a sudden drop in water pressure. The pressure loss prompted the agency to issue a boil water advisory to protect public health while operators investigated the anomaly. Water service was restored to normal levels within a few hours, and the advisory was lifted once pressure stabilized. The authority confirmed that the incident did not affect the safety of the drinking water supply.
The Clayton County incident was part of a wider wave of cyber intrusions targeting water and wastewater utilities that officials said had been observed in at least a dozen states, including Georgia, Michigan, Minnesota, New Jersey and South Dakota. In Minnesota alone, more than thirty community water systems were reported as impacted by similar activity. Several affected utilities described losing remote‑control capabilities over pumps, valves and pressure regulators, forcing operators to revert to manual operation. Investigators noted that the threat actors had gained remote access to operational technology components such as pumps and valves, although they emphasized that no contamination of drinking water had been detected in any of the cases.
On July 30, 2026 the Federal Bureau of Investigation, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency issued a joint warning that cyber threat actors had remotely accessed the online infrastructure of water and wastewater systems in at least seven states, resulting in a loss of monitoring and control functionality. The agencies advised the affected utilities to disconnect their operational technology networks from the internet and to strengthen password protections and firewall configurations. Federal investigators stated that they suspect the intrusions may be linked to Iran‑backed hackers but have not issued a formal attribution, and they observed that the tactics resemble those used in a 2023 campaign by the CyberAv3ngers group, which is associated with the Iranian Revolutionary Guard and has previously exploited default passwords to compromise water‑system controllers.
Sources
Sources available to members: 4 sources.