# Twelve States, One Pattern: Whoever Is Hitting Water Utilities Isn't Stopping
Pump stations don't fail quietly. When Clayton County, Georgia reported a disruption to one of its water system's pump stations, operators had to explain to the public why something so fundamental to daily life had been knocked offline. They've since confirmed the cause: a cyberattack. And Georgia isn't alone — at least eleven other states are dealing with versions of the same problem.
The number twelve is what demands attention here. A single incident at a water utility is a local story. A dozen states, seemingly around the same window, is a campaign.
## The Infrastructure Nobody Wants to Defend
Water and wastewater systems occupy an uncomfortable position in America's critical infrastructure map. They are essential — a disrupted pump station means pressure drops, treatment falters, sewage backs up — but they are chronically underfunded, often managed by small municipalities with IT budgets that couldn't cover a mid-tier enterprise endpoint detection tool. The average water utility's security posture looks closer to a small business in 2012 than a critical infrastructure operator in 2026.
That's not an accident and it's not a secret. The EPA has spent years attempting to mandate cybersecurity assessments for water systems, only to watch those efforts blocked in federal court after industry groups challenged the authority. CISA has published guidance, held tabletop exercises, and pleaded with utilities to harden their industrial control systems. The sector has been largely unable to act on that guidance — not from indifference, but from genuine resource constraints.
What attackers have learned is that the water sector is porous and the consequences of a successful intrusion are immediate and physical. When the Oldsmar, Florida incident happened in February 2021 — an attacker remotely accessed the treatment plant's SCADA system and pushed sodium hydroxide levels to more than 100 times normal — it felt like an outlier. The kind of thing that generates Senate hearings and task forces. Five years later, we're looking at twelve states.
## Who Does This
The roster of threat actors targeting water infrastructure has expanded considerably. Iranian-linked Cyber Av3ngers made international headlines in late 2023 after hitting water utilities in Pennsylvania and other states, exploiting internet-exposed Unitronics PLCs running default credentials. That was notable for how simple it was — not a sophisticated supply chain compromise, just internet-facing industrial hardware with the factory password still set.
Then there's the longer-game concern. Volt Typhoon, the Chinese state-sponsored group, has been documented establishing persistent access inside U.S. critical infrastructure — water included — specifically described by CISA and the FBI as pre-positioning for potential disruption during a future conflict. That's a different threat model than ransomware or hacktivism. Pre-positioned access is designed to be dormant until it isn't.
The current multi-state incidents haven't been formally attributed in public reporting yet. But the pattern — multiple utilities, geographically distributed, appearing to share some common attack vector or timing — points either to a coordinated actor or an exploit being passed around at scale against a shared vulnerability. Neither conclusion is comfortable.
## Pump Stations Are Just the Start
Clayton County's disruption hit a pump station. That's a relatively recoverable failure point — operators can shift to manual controls, reroute flow, buy time. The deeper risk in water infrastructure attacks isn't immediate poisoning (though that remains on the threat model), it's degraded operations over time: pressure loss that makes firefighting harder, treatment gaps that take days to detect, sewage overflows that trigger public health responses.
The ICS and SCADA systems running water infrastructure often run on hardware and software that predates modern security expectations. Many utilities operate equipment with no network segmentation between IT and OT environments, remote access left enabled for vendor maintenance, and monitoring tools that weren't designed to detect anomalous behavior — only equipment failure.
## HackWire Analysis
The twelve-state figure is almost certainly an undercount, and that's the detail that should be driving the policy conversation right now.
Water utilities aren't required to report cyber incidents to a central authority with the same speed or specificity as, say, financial institutions or healthcare providers. There's no federal mandate compelling a rural water district in a non-Georgia state to notify CISA within 72 hours of detecting anomalous access on their SCADA network. That reporting gap means the actual scope of this campaign — if it is one — may be significantly broader than what's surfaced publicly. The twelve we know about are the ones operators recognized as attacks, investigated, and disclosed. The number that were written off as equipment glitches or network hiccups and never examined closely is unknowable.
The other thing missing from most coverage of water sector attacks is the downstream liability question. When a ransomware group hits a hospital, there are regulatory frameworks, insurance structures, and attorneys waiting. When a pump station goes down because someone popped an exposed HMI interface, the municipality absorbs the cost, the operators work overtime, and the federal response consists largely of advisories nobody had time to implement anyway.
CISA's WaterISAC exists precisely for threat sharing in this sector, but membership and active participation remain uneven. Defenders at utilities that are resourced should be doing three things right now: auditing any internet-facing OT assets, verifying network segmentation between corporate and operational networks, and ensuring anomalous access attempts on industrial systems actually generate alerts someone is watching. Most can't do all three. That gap is the campaign.
— HackWire Editorial
---
## Related Coverage