Cyberattacks against the US water sector have reportedly reached utilities in at least 12 states, up from the seven states documented in earlier reporting, and Georgia has now been confirmed among the affected states after Clayton County reported a pump station disruption. The expansion marks a material escalation in a campaign that has pressed US critical water infrastructure for weeks.
How the Water-Sector Attack Footprint Expanded From Seven to Twelve States
Reporting on the water-sector attacks has traced a growing footprint, from an initial set of affected states to the current figure of at least 12. The escalation follows earlier attacks on Minnesota systems, where more than 30 systems were impacted in what investigations attributed to Iran-linked actors operating under the name CyberAv3ngers.
The Georgia Confirmation and the Clayton County Pump Station Disruption
Georgia’s inclusion was confirmed after Clayton County reported a disruption to one of its pump stations, establishing it as one of the attacked states. The confirmation widens the geographic spread of the campaign and shows that the impact is not confined to a single region but has crossed into multiple parts of the country.
The Escalation From Minnesota to a Multi-State Campaign
The current reporting builds on the Minnesota attacks, which involved more than 30 systems and drew an Iran-linked attribution. The move from that initial state-focused incident reporting to a footprint spanning at least 12 states indicates a broader and more sustained intrusion against the sector than a single localized event.
The Iran-Linked CyberAv3ngers Connection
Prior reporting attributed the Minnesota attacks to actors tied to Iran operating under the CyberAv3ngers name, and the Georgia confirmation extends a timeline in which the water sector has come under sustained pressure from nation-state-linked operators. The attack pattern suggests a deliberate focus on critical water infrastructure rather than opportunistic targeting.
What the 12-State Water Campaign Means for National Security
An expanding attack footprint across US critical water infrastructure raises national security and public-health concerns, because utilities supply essential services whose disruption can affect communities, hospitals, and emergency response. The expansion from seven to twelve states shows that these attacks are not isolated incidents but part of a sustained campaign that defenders will need to keep assessing for weeks.
The OT/ICS Response and Federal Coordination
CISA, the FBI, and state agencies are responding, and affected utilities are continuing remediation and monitoring. The coordinated response reflects the intergovernmental nature of protecting critical water systems, where federal agencies provide guidance and threat intelligence while local utilities manage the operational response.
What the Water-Sector Escalation Signals for Critical Infrastructure
The move from seven to twelve affected states confirms that the US water sector is under active and widening attack, and that operators across OT and industrial control system environments must treat water-system security as a front-line concern. The Georgia case shows that even municipal utility infrastructure is a target, not just large regional systems.
The Sustained Nature of the Campaign and Its Remediation Demands
The timeline of the campaign — from the Minnesota attacks that affected more than 30 systems through the expansion to at least 12 states — shows that operators are not facing a one-off incident but a sustained intrusion pattern. For utilities, that means remediation cannot be a single patching event; it requires continuous monitoring, hardening of internet-facing control systems, and coordination with federal and state agencies as the campaign continues to evolve.
The Iran-linked attribution and the sustained nature of the campaign point to a broader pattern of state-affiliated actors testing and stressing critical infrastructure resilience. For utilities, the practical consequence is that incident monitoring, hardening of internet-facing control systems, and coordination with federal and state agencies are essential, and the expansion means the response can no longer be treated as isolated to any single state.
The water sector’s importance to public health makes a 12-state campaign a national security issue as much as a technical one. The escalation supports a trend in which critical infrastructure is being probed and attacked at a scale that requires the response to sit at the federal level, alongside the operational defenses each utility must maintain on its own systems. As affected utilities continue remediation and monitoring with CISA, the FBI, and state agencies, the expanding footprint reinforces that water-system resilience is now a shared responsibility across the public sector rather than a problem any single municipality can solve alone.
