Skip to content

Cyber activity investigated after Clayton County water disruption

Summary

Clayton County Water Authority logo

Clayton County Water Authority said unauthorized cyber activity may have caused or contributed to a July 27, 2026, disruption affecting operational systems and water service in north Clayton County. Water pressure was restored within hours, the precautionary boil-water advisory was lifted July 28 after negative water-quality tests, and CCWA said it found no evidence that customer billing or payment information was accessed or compromised.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Safety risk or operational hazard

    The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub’s published report described Clayton County Water Authority’s investigation of unauthorized cyber activity following the July 27 water disruption. Separately, DysruptionHub assesses with high confidence that CCWA experienced a cyber-related operational incident because the authority itself later said unauthorized cyber activity may have caused or contributed to the disruption.

The authority’s wording confirms unauthorized cyber activity but remains qualified on causation. The public record does not establish whether the cyber activity directly caused the pump-station failure, amplified an equipment problem, or was discovered during the response to an unrelated outage. DysruptionHub therefore does not assign a specific PLC compromise, vulnerability, malware family, or initial-access method.

Operational significance

CCWA’s July 27 advisory said customers in Forest Park, Lake City and Morrow experienced low pressure or no water after a pump-station failure at about 1 a.m. Crews reestablished pressure around 4 a.m., and the authority issued a precautionary boil-water advisory because the pressure loss could affect water-system safety.

The disruption is operationally significant because it affected a public water utility serving more than 300,000 residents and businesses. The outage did not affect the entire county: CCWA said customers outside the identified north-county areas were unaffected and did not need to boil their water. The incident nevertheless temporarily reduced or eliminated water service for customers in several communities and required a public-health precaution while water samples were tested.

Disclosure posture

CCWA initially described the event as a pump-station failure and system outage. Its later security advisory added that unauthorized cyber activity may have caused or contributed to the disruption and said the authority coordinated with the FBI, CISA, law enforcement, regulators and cybersecurity partners. This represents an evolving public account rather than a contradiction: the operational effect was disclosed immediately, while the cyber dimension was disclosed after additional investigation.

The FBI and EPA issued a July 30 national alert warning that malicious actors had targeted internet-facing water-sector PLCs in at least seven states beginning July 27, causing effects including pressure loss. The timing and sector context are relevant, but neither CCWA nor the FBI publicly identified Clayton County as a confirmed victim of that specific campaign.

Current status

CCWA said water service was restored within hours. Its July 28 update lifted the boil-water advisory after all water-quality samples tested negative for harmful bacteria and said the water was safe to consume. These positive restoration and safety findings support a resolved operational status, although the cyber investigation remains ongoing.

Confidence and uncertainty

Confidence is high that the operational disruption occurred and was resolved because CCWA documented the outage, restoration, water testing and advisory lift. Confidence is also high that unauthorized cyber activity was detected or credibly suspected because CCWA stated this directly, but confidence is medium on the causal relationship between that activity and the pump-station failure because the authority used the phrase may have caused or contributed.

CCWA said there was no evidence that customer billing or payment information was accessed or compromised. That finding narrows the known data risk but does not establish whether operational data, device configurations, credentials, logs or other information were accessed or altered.

Analytic gaps

The public record does not identify the affected operational systems, PLC make or model, internet-exposure condition, initial access vector, compromised account, configuration changes, malware, actor, dwell time, lateral movement, broader data-access scope, extortion activity, or the technical relationship between the cyber activity and the pump-station failure. It also does not establish whether Clayton County was one of the utilities referenced in the FBI and EPA national alert.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Medium

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

CCWA documented a July 27 disruption affecting operational systems, water pressure and service while investigating unauthorized cyber activity that may have caused or contributed. Independent multistate reporting identifies Clayton County as Georgia’s public campaign confirmation, but no source establishes a PLC, common method, shared infrastructure, or actor.

Organizations involved

Impacted locations

Sources

Clayton County Water Authority investigates cyber activity after outage

DysruptionHub reported that Clayton County Water Authority was investigating unauthorized cyber activity that may have caused or contributed to the July 27 water-service disruption. The report distinguished the confirmed outage and official cyber investigation from the still-unconfirmed possibility that the incident was part of a wider campaign targeting water-sector operational technology.

Precautionary Boil Water Advisory Issued Due to a Pump Station Failure

CCWA said customers in the north end of Clayton County experienced low pressure or no water overnight after a pump-station failure at roughly 1 a.m. Pressure was reestablished around 4 a.m., and a precautionary boil-water advisory was issued for the affected area while water-quality testing was conducted.

Precautionary Boil Water Advisory Lifted for North End of Clayton County

CCWA lifted the boil-water advisory after all water-quality samples tested negative for harmful bacteria and said the water was safe to consume. It identified Forest Park, Morrow, Riverdale and Lake City as affected communities and said customers elsewhere in the county were not affected.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing PLCs

The FBI and EPA warned that malicious actors had targeted internet-facing water-sector PLCs in at least seven states since July 27. The actors changed device IP addresses and passwords, causing loss of monitoring or control, and reported operational effects included pressure loss and flooding; the alert did not publicly name Clayton County Water Authority.

Clayton County Water Authority investigating possible cyber threat after water disruption

WSB reported that CCWA was investigating unauthorized cyber activity that may have caused or contributed to the July 27 disruption. The report said reduced pressure led to a boil-water advisory, service was restored within hours, and CCWA found no evidence that customer billing or payment information was accessed or compromised.

Clayton County Water Authority Security Advisory: Cyber Activity Investigation

CCWA said it experienced a temporary disruption affecting a portion of its operational systems and water service in north Clayton County and was investigating unauthorized cyber activity that may have caused or contributed. It said service was restored within hours, partners including the FBI and CISA were involved, and there was no evidence customer billing or payment information was accessed or compromised.

Water supply under attack by cybercriminals; metro Atlanta system may have been targeted

WSB-TV reported that the Clayton County water disruption was being investigated in the context of cybercriminal attacks on water systems and that the metro Atlanta utility may have been targeted. The report treated the campaign linkage as possible rather than confirmed.

See something that needs correction?

Signed-in members can report an error, update, or missing source.