CYBER DESK · HONG KONG · WEEKLY

Fifteen Weeks Between Warning And Water Outage

A federal advisory told water utilities in April to take exposed controllers off the internet; the 12-state campaign that followed shows the warning needed an enforcement mechanism, not just publication.
KT

A Warning With No Deadline

Clayton County Water Authority in Georgia serves about 300,000 people around Atlanta, and the utility spent the first week of August running its treatment plant by hand. Intruders using techniques tied to CyberAv3ngers, a group the Cybersecurity and Infrastructure Security Agency has linked to Iran's Revolutionary Guard Corps, got into the utility's programmable logic controllers, the small industrial computers that open valves and dose chemicals, changed the passwords, and locked the operators out. A boil water advisory followed. Clayton County was not the first stop. Minnesota authorities reported the same campaign hitting roughly 30 community water systems starting July 26, and by the first week of August it had reached at least 12 states, including Michigan, New Jersey and South Dakota, with Georgia's Columbus Water Works also confirming disruption.

CISA had already told operators what to do about this. Advisory AA26-097A, issued April 7, described the exact technique: internet-exposed programmable logic controllers running default or weak credentials, reachable and rewritable by anyone who found them. That advisory built on one CISA first published in 2023, under the same group name. The gap between the second warning and the first confirmed breach was fifteen weeks.

The Determination Nobody Made

The FBI, EPA and CISA issued a joint advisory on July 30 describing the same exploitation technique without naming a country. Halcyon researcher Cynthia Kaiser called Iranian involvement almost certain. The agencies that would need to make that call formally have not made it, and that is not an oversight. CyberAv3ngers has a paper trail already: CISA named the group in a 2023 advisory, the Treasury sanctioned six of its officials in February 2024, and the State Department has a 10 million US dollar reward standing for information on its members. Naming Iran again, this time over water infrastructure inside US borders, is a different determination than naming a group, and it carries sanctions and diplomatic consequences neither agency is ready to commit to in a joint press release.

The default-credential configuration error is the finding here. A programmable logic controller with a default password reachable from the internet is not tradecraft, it is a configuration error, and retired NSA director Paul Nakasone said as much when he called for controllers to come off the public internet entirely and for higher security standards. CISA's twice-repeated request, the same default-credential fix from the 2023 and April 2026 advisories, floods a boil water advisory across 12 states.

The control that would have changed this outcome is not exotic: pull programmable logic controllers off the public internet, require unique credentials, and segment operational technology from anything routable. CISA said so in 2023. It said so again in April. A dozen states now have an incident that makes the point better than either advisory did. What CISA has never had is the authority to make an unpatched utility comply, and nobody in Washington is proposing to give it one before the next campaign starts.

Sources

PREVIOUS COLUMNS, CYBER INTEL DESK
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.