US Water Attacks Now Reported in at Least 12 States — Georgia's Clayton County Pump Station Disrupted
The water campaign keeps growing. Cyberattacks have reportedly hit at least 12 US states, per SecurityWeek — and Georgia's Clayton County confirmed a pump-station disruption, the latest named operational impact in a campaign that began with 30-plus Minnesota systems.
The cyber campaign against US water systems is no longer a Minnesota story. Water-sector cyberattacks have reportedly hit at least 12 states, according to SecurityWeek, and Georgia now sits on that list after Clayton County reported a disruption at one of its pump stations — the first time a specific piece of pumping equipment has been named as taking an operational hit in a campaign that began with more than 30 affected Minnesota systems.
That scope jump is the story. A few weeks ago the public tally was one state; now it spans at least a dozen, and the reporting has moved from "systems affected" to a concrete failure that residents felt at the tap. Below is what's actually confirmed, what still isn't, and what every water operator should check before attribution is settled.
What SecurityWeek Reported
SecurityWeek's August 5 report puts the count at "at least 12 states." That phrasing is deliberate, and it's worth holding onto: it reflects the outlet's reporting and the sourcing it has gathered, not an official tally published by the Cybersecurity and Infrastructure Security Agency. As of this writing, only four states have been named across the whole thread — Minnesota, Michigan, Georgia, and South Dakota. The other eight are, so far, states without public names.
The broader wire coverage lines up on the number. The Record and Axios both reported the same jump to a dozen states over the first days of August, with South Dakota and Georgia the newest additions. What none of them provide is the full state-by-state list — a gap that matters, because "12 states" is a headline number that no single public document currently itemizes.
Clayton County: The Pump Station That Went Down
Georgia's entry is the most concrete data point in the campaign so far. The Clayton County Water Authority, which serves the suburbs south of Atlanta, said it experienced a temporary disruption affecting a portion of its operational systems and water service. In practical terms, according to the Georgia Recorder and local reporting from WSB-TV, a pump station failed in the early hours of July 27, leaving some customers with low pressure or no water at all. Crews restored pressure within a few hours, and a precautionary boil-water advisory was lifted the next day after testing came back clean.
Here's the honest boundary on that incident: whether the pump-station failure was caused by the same intrusion vector reported elsewhere in the campaign has not been established publicly. Wider coverage of these water attacks has described tampering with internet-exposed programmable logic controllers, the small industrial computers that open valves and run pumps. But the specific technical cause at Clayton County — a cyber intrusion, a coincident equipment fault, or some combination — is still being investigated, and officials have been careful not to over-claim. Treat the pump-station disruption as confirmed; treat its precise cause as reportedly-linked, not proven.
How the Campaign Grew
This didn't arrive as a dozen-state event. It escalated. It began with more than 30 Minnesota water systems reported hit in a coordinated wave, then widened to seven states as Michigan, Georgia, and South Dakota were named. The move from seven to at least a dozen over the following days is what pushes this from a regional incident into a national one.
The attribution around it has been contested from the start. Federal agencies have pointed toward Iran-linked activity based on technical indicators and past targeting of the same class of industrial gear, while some political figures have pushed back on that framing — a split I covered when the story was still at seven states and centered on Minnesota's governor. What's changed with the 12-state count isn't the attribution debate; it's the surface area. Whatever is behind this, it now reaches far more utilities than the early framing suggested.
What Water Utilities Should Verify Now
The useful part for operators is that the defensive checklist doesn't depend on who did it. Every item below maps to guidance CISA has already issued for the water sector, and none of it waits on attribution:
- Audit for internet-exposed PLCs and OT. Find any programmable logic controller or operational-technology interface reachable from the public internet and pull it behind a firewall or VPN. This is the single most-cited exposure in the campaign.
- Disable or segment remote-management interfaces. Remote access into control systems should be off by default and, where needed, isolated from the business network.
- Rotate credentials on internet-facing OT. Assume default and reused passwords on any exposed device are known. Change them and kill the defaults.
- Hunt for undocumented cellular modems. Field gear sometimes ships with cellular connectivity that never made it into the network diagram — an out-of-band path attackers love.
- Rehearse manual-ops fallback. If the PLCs go dark or misbehave, can staff run the plant by hand? Clayton County's residents felt a pump go down; the recovery time depends on how ready the crew is to operate without automation.
I laid out the technical version of this after CISA's earlier warning to pull exposed PLCs off the internet. The advice hasn't changed; the number of utilities that should have acted on it has.
My read: the "at least 12 states" figure will probably keep climbing before it stabilizes — not necessarily because the campaign is still spreading, but because reporting catches up to incidents that already happened at small utilities with thin IT staff. The scary version and the boring version of this story point to the same fix: too many small water systems have control gear on the open internet, and closing that gap is cheaper than any incident response.
The Federal Response and State Funding Gap
The policy layer is starting to move. In Georgia, Senator Jon Ossoff said he is working across the aisle to shore up the state's water infrastructure against cyberattacks following the Clayton County incident. That's the pattern to watch: a named local disruption turns into a congressional talking point, which turns into pressure for funding.
The gap underneath all of it is resources. Many of the utilities in this campaign are small municipal or county systems that don't have a dedicated security team, let alone an OT specialist. Federal guidance is free; the staff and equipment to act on it are not. Whether the 12-state count translates into actual money for the smallest operators — the ones most likely to have a modem nobody remembers installing — is the open question that will decide how the next wave goes.
Open Questions
Three things remain genuinely unsettled. First, the full 12-state list: eight of the affected states have not been publicly named, and I'm not going to guess at them. Second, whether CISA will officially confirm the 12-state count or publish its own tally — right now that number is SecurityWeek's reporting, echoed by other outlets, not an agency figure. Third, whether the contested attribution applies uniformly across all 12 states or only to the earliest, best-documented incidents. Until those close, the responsible framing is the one the reporting supports: at least 12 states, reportedly, with one named pump station that briefly went down in Georgia.
Primary Documents
- SecurityWeek — Water Sector Cyberattacks Reportedly Hit at Least 12 States
- The Record — Cyberattacks on water systems expand to 12 states
- Axios — Number of states targeted in water-system cyberattacks jumps to 12
- Georgia Recorder — Expert on the Clayton County water system attack
- Sen. Ossoff — Working to protect Georgia's water infrastructure from cyberattacks