Sabotage Watch: Homeland Infrastructure Under Pressure
Cyberattacks Are Moving Into America’s Physical Infrastructure
Recent incidents across the U.S. water sector illustrate how cyber activity can move beyond stolen data or disrupted computer networks and directly affect physical infrastructure. On July 30, the FBI and EPA warned that malicious actors had remotely accessed internet-facing Programmable Logic Controllers (PLCs) at water and wastewater utilities in at least seven states. In some cases, attackers changed IP addresses and passwords, resulting in loss of monitoring or control; reported operational effects included pressure loss and flooding. The agencies specifically warned that compromised water-system PLCs can create consequences for pumps, monitoring and other physical processes.
Local reporting shows that this is not simply a federal-level warning. In Georgia, the Clayton County Water Authority investigated unauthorized cyber activity following a July 27 disruption that caused reduced water pressure and prompted a precautionary boil-water advisory. In Oregon, state officials confirmed to OPB that hackers had gained access to the core operational technology of a drinking-water provider. More recently, Colorado officials disclosed that foreign actors breached two small water utilities in August and manipulated equipment settings, disabled alarms and remote access, and altered pumping cycles. Officials said there was no known impact to water quality or public safety in those incidents.
The broader concern is the convergence of cyber access, operational technology and physical infrastructure. Water utilities are particularly important because many rely on PLCs, SCADA systems and remote connectivity to operate pumps, treatment processes and distribution networks. The FBI and EPA have urged utilities to remove PLCs from direct internet exposure, strengthen authentication and maintain the ability to operate systems manually. Meanwhile, the FBI has separately warned that China-linked QTFY actors have targeted U.S. critical infrastructure, while the Justice Department has recently charged individuals allegedly connected to Russian intelligence operations involving surveillance and attacks against infrastructure overseas. The emerging indicator to watch is not simply whether a network is breached, but whether an adversary can move from digital access to control of the physical environment.
SOURCES
Federal Bureau of Investigation & U.S. Environmental Protection Agency — July 30, 2026
“Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions”
FBI Advisory
Clayton County Water Authority — August 3, 2026
“Security Advisory: Cyber Threat Awareness & Response”
Clayton County Water Authority
OPB — August 7, 2026
“Oregon drinking water system accessed in recent cyber attacks”
OPB reporting
CBS News Atlanta — August 4, 2026
“FBI warns of cyber threats to water utilities as Clayton County investigates possible attack”
CBS Atlanta reporting
Reuters — September 18, 2026
“Foreign hackers targeted Colorado water systems in August, governor’s office says”
Reuters reporting
FBI / NSA / Cyber National Mission Force — August 26, 2026
“China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure”
FBI Cyber Alert
U.S. Department of Justice — September 15, 2026
“Members of Russian Intelligence Services Network Charged…”
Department of Justice