Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Trump rejects Tehran theory, blames 'grossly incompetent' governor of Minnesota instead
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. Iran-backed hackers are the leading suspects, although the bureau has not publicly attributed the campaign.Officials in both states told journalists over the weekend that water facilities had detected activity consistent with the attacks on more than 30 Minnesota sites last week. Neither state reported operational disruption.Nine Michigan water systems reported hostile cyber activity to the state's Department of Environment, Great Lakes, and Energy.
Department communications director Dale George said the state received "a small number" of reports consistent with the activity seen in Minnesota, but no public health consequences followed.
"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," said George.Georgia also confirmed to ABC News that it was affected, but said the damage was limited.Neither Georgia nor Michigan has published any form of public-facing notification about the cyberattacks.The three states are among at least seven affected by the intrusions, according to an FBI advisory posted last week. The bureau did not name a culprit or mention Iran."Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations," it stated in its advisory.The FBI said it had so far observed the activity only against Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), although it warned organizations deploying other manufacturers' devices to follow the same hardening advice.A broader CISA advisory, updated on July 22, warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors.Security researchers at Tenable were among the first to publicly suspect Iran's involvement, citing similarities with previous attacks by the IRGC-linked CyberAv3ngers group.










