Local

Hackers targeted another Georgia water system. Officials say the water supply was not affected

COWETA COUNTY, Ga. — Hackers targeted another Georgia water system, marking at least the third incident to come to light this week as officials investigate a surge in cyberattacks against water and wastewater systems.

The Coweta County Water Authority confirmed to Channel 2’s Ashlyn Webb that hackers gained access to its system. Water Authority CEO Jay Boren says hackers attempted to change passwords and take control of equipment used to operate the county’s water and wastewater infrastructure.

Boren said the breach happened Monday, July 27, around midnight, and it did not affect the county’s drinking water.

[DOWNLOAD: Free WSB-TV News app for alerts as news breaks]

Boren told Channel 2’s Ashlyn Webb that the hackers attempted to manipulate valves but were unsuccessful.

“They were trying to gain control of our system,” Boren said. Hackers tried to access equipment controlling pumps and valves.

During the incident, the authority temporarily lost communication with its programmable logic controllers, commonly called PLCs. “So basically [the PLCs] control pump stations, lift stations, valves and everything like that,” Boren said.

As a precaution, the water authority shut down its automated system and switched to manual operations.

Boren said the water authority has found no evidence that financial information was the target. Instead, he believes whoever was behind the attack appeared interested in gaining physical control of the system.

“Like turning water on and off or affecting our lift stations to try to cause some physical incident, like a sewer spill, for example,” Boren said.

The Coweta County incident follows reported cyberattacks involving the Clayton County Water Authority and the City of Columbus.

RELATED:

The string of incidents comes as officials examine whether increased cyber activity targeting U.S. infrastructure could be connected to the war with Iran.

But-- who was responsible for the Coweta County attack remains unknown.

“We don’t have any clue,” Boren said.

Despite the attempted breach, Boren said the authority did not report the incident to the FBI, Environmental Protection Agency (EPA) or the state.

“Since there were no incidents, we didn’t report anything,” he said.

Luke Connolly, a threat intelligence analyst with Emsisoft who has been tracking attacks against water systems nationwide, said determining the initial point of entry is critical to avoid a repeat attack.

“It’s important to know how they got in so that adequate defenses can be communicated to all of the other water treatment facilities across the United States,” Connolly said. He says reporting helps authorities identify who the hackers are and how they got into the system.

As cyber attacks on U.S. water facilities surge, a large concern is if hackers could contaminate the water. So far, there’s no known evidence that drinking water was contaminated in any of the recent attacks.

However, in a 2021 incident involving a water treatment system in Oldsmar, Florida, hackers appeared to alter a setting controlling the amount of chemicals used in the treatment process. An operator noticed the change and reversed it before the water supply was affected.

The FBI released a public service announcement July 30 urging municipalities to take their PLCs off the internet to make the systems less vulnerable.

[SIGN UP: WSB-TV Daily Headlines Newsletter]

0