A cyber incident affecting a Georgia water system has reportedly become part of a broader investigation into attacks targeting the nation’s water infrastructure, according to local officials and reports.
Officials in Clayton County, located just south of Atlanta, said what initially appeared to be a routine boil water advisory has since been linked to the wider investigation into cyber threats facing water systems across the country. The development follows reports from last week that more than 30 water systems in Minnesota were also targeted in what local officials described as a coordinated cyberattack.
According to Channel 2 Action News, the Clayton County Water Authority said devices known as programmable logic controllers, or PLCs, may have been vulnerable because they were exposed to the internet.
Water Authority spokesperson Erin Thomas told the station that employees first realized something was wrong when several pump stations unexpectedly went offline.
“What we realized is that some of our pump stations went down,” Thomas told Consumer Investigator Justin Gray.
She warned that such systems could present significant concerns if they were successfully manipulated by attackers.
“Things could get really dangerous if they were to be manipulated or attacked or disturbed,” Thomas said.
Despite the disruption, Thomas said the utility’s staff quickly identified the issue and restored service before the situation escalated.
“However, our team promptly were able to identify that they were down and we were able get the service restored,” she added.
The incident comes as federal authorities continue monitoring cyber threats directed at critical infrastructure.
Last week, the Federal Bureau of Investigation issued an alert warning about the attacks, noting that seven states had been impacted.
Cybersecurity experts also say the vulnerabilities extend well beyond a single utility.
Georgia Tech cybersecurity professor Saman Zonouz told Channel 2 Action News that he and his research team had identified thousands of potential vulnerabilities affecting approximately 7,000 institutions.
According to Zonouz, many of the systems were improperly configured in ways that made them accessible over the internet.
“They are misconfigured to be exposed to internet,” Zonouz said. “And we were able to discover them. If we are able to discover them, adversaries would be able as well.”
The comments underscore concerns that internet-connected industrial control systems could be exploited if they are not properly secured.
Meanwhile, officials in Minnesota continue investigating what they have described as a coordinated cyberattack targeting multiple municipal water systems.
Local officials there have said more than 30 communities were affected as part of the coordinated effort.
Fox 9 first reported last week that four Minnesota cities publicly disclosed they had been targeted: Plymouth, South St. Paul, Maple Plain, and Braham.
According to local officials, the cyber incidents occurred on Sunday and Monday.
Authorities in those communities said the attacks were either limited in scope or successfully mitigated before causing more significant disruption. The incidents remain under investigation.
The developments in Georgia add another state to the growing list of jurisdictions responding to cyber threats involving water infrastructure. While investigators continue examining how the attacks occurred and whether they are connected, officials in both Georgia and Minnesota have emphasized that they acted quickly to identify the incidents and restore or protect affected systems.
Federal authorities, local utilities, and cybersecurity experts continue working to determine the full scope of the attacks and identify vulnerabilities that could expose additional water systems to similar threats.
