ATLANTA WIRE   |

August 7, 2026

Two Georgia Water Systems Hacked Through Programmable Logic Controllers as Federal Investigation Widens

Georgia Water Systems Hacked PLCs Cyberattack 2026
Photo Credit: Unsplash.com

Two Georgia water systems have confirmed they were targeted in cyberattacks that exploited programmable logic controllers (PLCs), the industrial minicomputers that automate water treatment, pressure regulation, and chemical dosing at utility facilities across the country. Clayton County Water Authority, which serves communities south of Atlanta, said a service disruption that temporarily knocked out water to parts of the county is under investigation as a possible cyberattack. Columbus Water Works confirmed a separate breach but said its drinking water supply was never compromised.

Key Takeaways

  • Clayton County Water Authority (metro Atlanta) confirmed that hackers targeted its system, causing pump station outages and triggering a boil water advisory for parts of the county.
  • Columbus Water Works also confirmed a cyberattack but said drinking water was never affected and its team detected the intrusion before operations were compromised.
  • The FBI issued a public service announcement warning that water and wastewater utilities in at least seven states have reported cyber incidents since July 27, 2026.
  • Attackers targeted Rockwell Automation/Allen-Bradley PLCs (MicroLogix 1100 and 1400 series), changing IP addresses and passwords to lock out operators and disable monitoring.
  • CISA expanded its advisory scope to include Schneider Electric, Siemens, and other PLC manufacturers as potential targets.
  • Georgia Tech researchers have identified more than 7,000 PLCs accessible on the open internet across water treatment plants, hospitals, airports, and military facilities nationwide.

Clayton County Pump Stations Went Down Before the Cause Was Identified

The first signs of trouble in Clayton County appeared as a routine service disruption. Residents received a boil water advisory and experienced low water pressure. It was not until days later that the Clayton County Water Authority publicly disclosed that the disruption may have resulted from unauthorized cyber activity. Spokesperson Erin Thomas confirmed that the investigation centers on programmable logic controllers, the devices that automate equipment ranging from pumps to water treatment and purification operations throughout the system.

“What we realized is that some of our pump stations went down,” Thomas told WSB-TV. The authority described the PLCs as the “last step between you and the equipment,” noting that manipulation of these devices “could get really dangerous.” Thomas said there is no evidence that customers’ billing or payment information was compromised and that the authority immediately began coordinating with state and federal partners, including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), to investigate the incident and secure affected systems.

Columbus Water Works, located approximately 100 miles southwest of Atlanta, confirmed a separate breach. The utility said its team detected the intrusion and that the city’s drinking water was never compromised during the incident. Both Georgia incidents are now part of a broader federal investigation spanning multiple states.

The FBI Says Water Utilities in at Least Seven States Have Been Hit

The Georgia incidents are not isolated. The FBI issued a public service announcement, jointly with the Environmental Protection Agency, warning that water and wastewater utilities in at least seven states have reported cyber incidents to federal authorities since July 27, 2026. Some of those incidents “degraded water operations,” the FBI stated. The number of affected states has since grown; ABC News reported the count had reached 12 as of early August.

The FBI said attackers targeted Rockwell Automation/Allen-Bradley PLCs, specifically the MicroLogix 1100 and 1400 series, which are widely deployed across small and mid-sized water utilities. After remotely accessing internet-facing devices, the attackers changed IP addresses and passwords, effectively locking operators out of their own systems and resulting in a loss of monitoring and control functionality. The FBI cautioned that while it has so far observed this specific behavior only against Rockwell devices, organizations using PLCs from other manufacturers should follow the same hardening guidance.

CISA issued a separate alert on July 30 urging water and wastewater system operators to remove publicly exposed PLCs from the internet immediately. CISA noted that threat actors have modified passwords to lock out operators, disconnected PLCs by changing IP addresses, and caused boil water notices and sustained manual operations at affected utilities. The agency emphasized that water organizations “of all sizes” are being targeted, including systems where cellular modems installed by operators, vendors, or system integrators may not be documented or included in routine security scans.

Researchers Found Over 7,000 PLCs Exposed on the Open Internet

The vulnerability that makes these attacks possible is not a software flaw in the PLCs themselves. It is the fact that thousands of these devices are connected directly to the internet without adequate security protections. Georgia Tech cybersecurity professor Saman Zonouz, whose research focuses on industrial control system security, compared PLCs to home thermostats. Both detect environmental conditions and trigger automated responses. A thermostat measures temperature and turns on an air conditioner. A PLC in a water treatment plant monitors water pressure, chlorine levels, and flow rates, then adjusts pumps, valves, and chemical dosing systems accordingly.

Zonouz and his research team found more than 7,000 PLCs accessible on the open internet across water treatment plants, airports, hospitals, energy facilities, and military installations. The exposure exists largely for convenience. Operators and maintenance teams connect PLCs to the internet to enable remote monitoring and troubleshooting, particularly at smaller utilities that may not have full-time on-site technical staff. That convenience creates a direct attack surface that adversaries can exploit without needing to breach any firewall or internal network.

“The reason,” Zonouz noted, is that operators prioritize functionality and accessibility over security, a trade-off that is especially common at small and mid-sized utilities with limited cybersecurity budgets. The research underscores a structural vulnerability that extends far beyond the water sector: the same PLCs used in water treatment are deployed across power grids, manufacturing facilities, oil and gas refineries, and building automation systems.

Small and Mid-Sized Utilities Face the Steepest Cybersecurity Gap

The pattern of attacks highlights a disparity in cybersecurity capacity between large metropolitan water systems and smaller utilities. Large systems like Atlanta’s Department of Watershed Management typically maintain dedicated cybersecurity teams, network segmentation between operational technology and information technology, and regular vulnerability assessments. Smaller systems, particularly those serving rural communities or mid-sized counties, often operate with lean staff and limited budgets for technology upgrades.

Clayton County Water Authority serves approximately 300,000 residents across unincorporated Clayton County and portions of southern Fulton and Henry counties. Columbus Water Works serves the city of Columbus and surrounding Muscogee County. Neither is a small rural system, but both are representative of the mid-tier utilities that federal agencies have identified as particularly vulnerable to PLC-based attacks.

State Rep. Sandra Scott, a Democrat whose district includes parts of Clayton County, said she has heard from constituents concerned about the incident. Scott emphasized that the investigation must be thorough because “we know that we all need water.” The political pressure to address water infrastructure cybersecurity is likely to grow as the number of affected states increases and as the federal investigation produces findings about the scope of the campaign.

CISA has recommended that water utilities immediately remove all PLCs from direct internet exposure, implement network segmentation between operational technology and corporate networks, require multi-factor authentication for remote access, and monitor for unauthorized changes to PLC configurations. The EPA’s Cybersecurity Technical Assistance Program for the Water Sector is available to assist utilities that lack in-house cybersecurity expertise.

FAQs

What Is a Programmable Logic Controller?

A programmable logic controller (PLC) is an industrial minicomputer that automates equipment operations in water treatment plants, manufacturing facilities, power systems, and other critical infrastructure. PLCs monitor conditions like water pressure and chemical levels and automatically adjust pumps, valves, and dosing systems in response.

Was Drinking Water in Georgia Contaminated?

Neither Clayton County Water Authority nor Columbus Water Works has reported any contamination of the drinking water supply. Clayton County issued a precautionary boil water advisory during the service disruption, which has since been lifted. Columbus said its team detected the breach before operations were affected.

What Should Water Utilities Do to Protect Against These Attacks?

CISA recommends removing all PLCs from direct internet exposure, implementing network segmentation, requiring multi-factor authentication for remote access, and monitoring for unauthorized configuration changes. The EPA’s Cybersecurity Technical Assistance Program offers free support for water utilities.

Atlanta Wire

Unraveling the tapestry of the Peach State.