Hackers gained remote access to Coweta County Water and Sewerage Authority controls in Georgia on July 27, prompting operators to switch to manual control but causing no disruption to water service, officials said.
The intrusion gave attackers access to operational technology used to control valves and pump stations. The authority, based in Newnan, says it provides water and wastewater services to more than 31,000 water customers and 3,500 sewer customers in Coweta County and surrounding communities.
Jay Boren, the authority’s CEO, told Atlanta News First that attackers gained access through what he described as “cellular channels,” changed passwords and shut down controls. The information technology team detected the intrusion after losing communication with a programmable logic controller that manages valves and pump stations, he said.
Operators shifted to manual control while passwords were reset. Boren said water service was not interrupted and customer data was not compromised. The authority did not notify customers because officials had identified no concerns involving water quality or customer data, he told the station.
WSB Radio separately reported that the attackers attempted to turn valves on and off after gaining access to the controls. Boren told the station that the utility was immediately alerted and that neither water quality nor customer information was affected.
The July 27 incident coincided with a broader series of attacks on U.S. water utilities. On July 30, the FBI and Environmental Protection Agency warned that water and wastewater utilities in at least seven states had reported incidents since July 27 involving malicious actors targeting internet-facing programmable logic controllers. Some incidents degraded water operations.
The federal alert said attackers remotely changed device IP addresses and passwords, causing operators to lose monitoring and control functions. The FBI and EPA specifically cited Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers in the activity they observed. Coweta officials have not publicly identified the manufacturer or model of the controller involved in their incident.
Federal agencies have separately warned that Iranian-affiliated hackers are conducting an ongoing campaign against internet-connected operational technology across several U.S. critical infrastructure sectors. A July 22 joint advisory attributed that broader activity to Iranian-affiliated actors and said some victims experienced operational disruption and financial loss.
That attribution has not been publicly applied to the Coweta incident or to the recent water-system attacks as a group. The FBI had not publicly identified a culprit in the recent attacks as of early August. CBS News reported that federal investigators suspected an Iran-backed connection but had made no formal attribution.
Coweta is the latest Georgia utility to disclose an incident during the same period. Clayton County Water Authority said unauthorized cyber activity may have caused or contributed to a July 27 disruption that reduced water pressure in parts of north Clayton County and prompted a precautionary boil-water advisory. Service was restored within hours, and testing found the water safe.
Columbus Water Works also disclosed a July 27 cyberattack in which operators shifted affected monitoring systems to manual control without a change in water quality or service. DysruptionHub has documented similar incidents involving water systems in Minnesota, New Jersey, Alabama, South Dakota and other states during the campaign.
No threat actor has been publicly confirmed in the Coweta intrusion, and no ransom demand has been disclosed. Officials said customer data was not compromised. The investigation remains underway. Public reporting did not specify whether all affected automated controls had returned to normal operation by Friday.