Cyber Attack: Are we prepared? Citizens need to ask some hard questions.

Columbus Water Works went to manual operation on July 27. A second Georgia utility issued a boil water advisory the same week. Officials confirm the state was hit and will not say how widely.

706REPORT.COM · COLUMBUS, GEORGIA · AUGUST 2026

Columbus Water Works went to manual operation on July 27. A second Georgia utility issued a boil water advisory the same week. Officials confirm the state was hit and will not say how widely.

Continuing coverage of Project Ruby and Columbus Water Works

On Monday, July 27, somebody got into the systems that let Columbus Water Works watch its own water from a distance.

The utility caught it almost immediately. Staff shut off the automation and went back to doing the job with their feet. Chance Corbett, Columbus’s homeland security and emergency management director, described the change in plain terms. “They had to go from whether they were looking at a screen to see what the flow was or what was going on,” he said, “to actually having to go on site.”

Nothing happened to the water. “There was never a threat of loss of water or any of the quality of water,” Corbett said. Service was not interrupted. The utility activated its emergency plan and expected to be restored by the end of that week. Corbett said Columbus Water Works did a great job, and on the evidence available he is right.

The public found out eight days later, on August 4.

The equipment involved is worth naming, because it explains how ordinary this was. Programmable logic controllers are small industrial computers that open valves, run pumps and dispense chlorine. Saman Zonouz, a cybersecurity professor at Georgia Tech, calls them more rugged versions of the simple controllers in a home thermostat. “If that gets hacked into,” he said, “then that’s the brain of the system.”

Columbus was not the only Georgia utility with that problem in July.

The Second One Did Not Go As Well

The Clayton County Water Authority, south of Atlanta, was hit the same day. It did not stay invisible to customers.

A pump station failed around one in the morning. Homes lost pressure, or lost water. The authority restored pressure by four, issued a boil water advisory, and lifted it on July 28. Its spokesperson, Erin Thomas, said the affected equipment was the same kind. “Some of our pump stations went down,” Thomas said, adding that the team identified the problem and restored service. No customer billing data was taken. The authority is working with the FBI and CISA.

Thomas also said the thing most officials avoid saying out loud. “Things could get really dangerous if they could get manipulated or attacked.”

That is two confirmed Georgia water systems in one week, one of them with residents boiling their water. It is the second half of the story that is hard to get.

What Nobody Will Say

State and federal officials have confirmed that Georgia is among the affected states. They have not said which Georgia systems, or how many.

The two that are public are public because the utilities themselves confirmed them. Reporters got there by calling around. Fayette, Cobb and Gwinnett counties each said they had no intrusion. DeKalb County did not respond. Atlanta declined to discuss its cybersecurity at all, citing security. Columbus Water Works confirmed the breach and then did not answer questions about how the attackers got in.

The FBI issued a nationwide alert on Thursday, July 30, warning that malicious actors are targeting operational technology at water and wastewater utilities. It put the number at at least seven states. ABC News reported twelve. Asked about particular incidents, an FBI public affairs specialist would not confirm details: “The FBI is aware of recent public reporting around Water and Wastewater sectors.” A second FBI statement, from Jenna Sellitto, said the bureau and its partners “are fully engaged to protect critical infrastructure.”

So there is a national count and a national alert, and no state count.

The argument for withholding one is always the same. Telling the public what happened tells the next attacker what worked. That argument is serious, and it applies to a real category of information: which controller was reached, what credential was used, how long the intruder stayed. No reporter should ask for those, and this one is not asking.

A count is a different thing. How many Georgia systems were targeted tells an attacker nothing he does not already know, because he chose the targets. It tells residents whether what happened to their water utility happened to their neighbors’ too. Clayton County released far more than a count, named the equipment, and is still standing.

There is one more piece of information routinely treated as secret that is not. The America’s Water Infrastructure Act of 2018 requires every community water system serving more than 3,300 people to complete a risk and resilience assessment and certify it to EPA. The assessment is protected. The fact of its completion and certification is not. Whether Columbus Water Works has done one, and when it last certified, can be answered without exposing a single vulnerability.

Nobody has answered it.

About Who Did It

We want to be careful here, because the reporting does not all point the same direction.

CISA warned in an April advisory of ongoing Iranian-affiliated cyber targeting of American infrastructure. A Georgia Association for Water Professionals bulletin indicated the operatives in these attacks were affiliated with Iran. Iranian-linked groups have hit American water systems before, including a Pennsylvania utility in 2023.

But the FBI has not confirmed attribution, and investigators have not publicly connected the Columbus intrusion to the Iran-linked campaign. Georgia has two confirmed incidents and no named attacker.

The honest position is that the pattern is suggestive and the specific case is open.

Why This Lands Differently in Columbus

Every city in America has a water system worth protecting. Columbus is about to have something else.

Project Ruby is a hyperscale data center campus proposed for the northeast corner of Muscogee County, on 987 acres, with a formal request to Flint Energies for 600 megawatts of electricity at full buildout. That is more power than the entire city of Columbus draws at peak. In June, Council adopted a Technology Overlay District to govern it.

A facility like that does not arrive alone. It arrives attached to the water system and the power system that keep it running. And it changes what those systems are worth to somebody who wants leverage.

That is where the attack on Columbus Water Works stops being a local IT story.

The Ordinance Regulates Almost Everything Else

The Technology Overlay is not a weak document. Council amended it on the floor on June 9 and adopted it on second reading June 16, and the amendments made it stronger.

The residential buffer went from 200 feet to 500. Backup generators must be Tier IV, or Tier II with selective catalytic reduction, and diesel backup generators are prohibited outright. Noise is capped at 65 dBA daytime and 55 dBA at night at any property line abutting a residential district, measured as a rolling thirty-minute average. Cooling fluids containing PFAS, hydrofluorocarbons or perfluorocarbons are banned. Evaporative open-loop cooling is banned. The enforcement window tightened from thirty days to fifteen, after which the city can go to Recorder’s Court, seek an injunction, and revoke a certificate of occupancy. There is a $1,000 per day fine. The developer must fund decommissioning, and the city holds the money.

Council approved it 6 to 2. Joanne Cogle of District 7 and Simi Barnes voted against. Bruce Huff and Toyia Tucker were absent.

Councilor John Anker of District 9 described the buffer decision plainly. “We took the 500-foot recommended buffer by planning and zoning,” Anker said. “I’m prepared to vote no on any data center if it doesn’t follow 13 strong conditions.”

Read the whole thing and you will find no mention of cybersecurity. No mention of operational technology. No mention of drought, curtailment, redundancy, or continuity of service. The word does not appear in any form.

The closest the ordinance comes is subsection (M). Before any permit issues, the developer must obtain a letter from each utility confirming it can serve the site, and each utility must complete a system impact study first. That is a real requirement and it does real work. It asks whether Columbus Water Works can deliver the volume.

It does not ask whether Columbus Water Works can keep delivering it under attack.

The Power Side Has the Same Hole

The cyber question is not only about water. Ask it about electricity and the answer is stranger.

Flint Energies is the rural electric membership cooperative that serves northeast Muscogee County. Its entire service territory peaks at roughly 450 to 500 megawatts today. Project Ruby at full buildout would draw 600.

There is a mandatory federal cybersecurity standard for the electric sector. It is called NERC CIP, it has audits, and it has penalties. It applies to the Bulk Electric System. Local distribution systems are explicitly excluded from the definition of the Bulk Electric System. A distribution cooperative generally falls outside NERC CIP unless it owns qualifying assets or performs a registered reliability function.

So the mandate binds generation and transmission upstream. It does not reach the wires that would actually deliver power to a data center in Muscogee County. Who supplies Flint’s generation and transmission for this load, and whether that entity is NERC-registered, is not secret. It has also not been asked in public.

What the cooperatives have instead is voluntary and thinly funded. The National Rural Electric Cooperative Association received $15 million from the Department of Energy in November 2022 to monitor industrial control systems across its member co-ops, plus $4 million for preparedness, inside a program of roughly $20 million running through September 2028. That is for the entire cooperative sector nationally.

Two utilities would serve this campus. Neither one answers to an enforceable cyber standard.

Nobody Budgeted for This

Columbus Water Works is in the middle of the largest capital program in its history. It is worth understanding how large, because it explains a great deal about what did not make the list.

The utility’s 2026 Rate Update, presented to Council on October 28 and approved by the board on December 8, lays out a capital improvements plan of about $1.05 billion between 2026 and 2032. The wastewater treatment plant rebuild is $650 million of it. Master planning projects are $270 million. Fort Benning PFAS work is $100 million. Debt service climbs from $18.68 million in fiscal 2025 to $80.33 million in fiscal 2033, more than four times over.

The document runs twenty-one slides. It does not contain the word cyber. It does not contain the word security. It does not contain SCADA, resilience, or technology.

Here is what it does contain. Water, wastewater and sewer overflow charges rise 4.95 percent a year, every year, from 2026 through 2031. A new fixed monthly charge appeared on every bill in January. A typical residential bill went from $55.48 to $63.24, and the utility told Council most customers would see $7 to $9. More than half of residential bills are at or below that level of use.

The new charge is called the Regulatory Compliance Fee. It starts at $5 a month for a household and reaches $20 by 2029. For a large non-residential account it starts at $25 and reaches $100 by 2031. The rate priorities slide lists what regulatory compliance means: combined sewer overflows, nutrients, and PFAS.

Cybersecurity is also a regulatory requirement. It sits in Section 1433 of the Safe Drinking Water Act. In March 2024, EPA issued an enforcement alert saying that 70 percent of the water systems it had inspected since 2023 were in violation of it.

There is a fee on every water bill in Columbus named for regulatory compliance, and it does not list the one area of regulation with a documented 70 percent failure rate.

This Is What the Whole Sector Does

Columbus is not an outlier, and this article would be dishonest if it implied otherwise.

The Government Accountability Office reported on May 21, 2026 that roughly 170,000 water and wastewater systems in the United States remain exposed. It named the cause directly. Systems must choose between spending on regulatory compliance and spending on security, because clean-water compliance is mandatory and security is largely voluntary. GAO also found that EPA has identified significant limits on its own legal authority to close the gap.

The federal money available is countable. On August 5, 2025, EPA announced just over $9 million in grants for water systems serving 10,000 people or more. Applications closed October 6. The program covers extreme weather resilience as well as cybersecurity, so cyber draws on a fraction of $9 million for the entire country, awarded competitively.

A utility carrying a $1.05 billion capital program and a mandate to remove PFAS by 2031 is not going to fund a security program out of the margin.

The Cheap Fixes Are Genuinely Cheap

None of this means the problem is expensive to start on, and that is the part worth considering.

State guidance describes the basic controls as low to moderate cost, often achievable by reconfiguring equipment a utility already owns. Put a firewall or a VLAN between the SCADA network and the business network and the internet. Get the controllers off the open internet. Change the default passwords. Turn on multifactor authentication. Training is available at no cost from CISA and from WaterISAC. The American Water Works Association gives away its risk management guidance and an assessment tool that produces a prioritized list of controls.

That matters because of how these attacks actually work. Zonouz, the Georgia Tech professor, was blunt about the cause. The controllers “usually are exposed to the internet either misconfigured or for the operator’s convenience purposes,” he said. Many still run the password the manufacturer shipped them with. Some have gone decades without an update.

“You don’t have to be a rocket scientist to do this,” Zonouz said.

His prescription costs almost nothing. “The first thing to be done really is just take them off the internet.”

The scale of the exposure has been measured. Researchers found more than 7,000 programmable logic controllers sitting openly accessible on the internet. After the researchers alerted the owners, 30 percent were taken down. The other 70 percent were not.

Zonouz also explained why water in particular. He called water utilities a perfect target, and the reason he gave was not technical. It was that they have not invested enough in security.

The expensive part is not the firewall. It is continuous monitoring, incident response, and the people to do both. GAO’s finding was about workforce as much as hardware. That is an operating cost that recurs every year, and it is the hardest kind of money for a utility to find, because it never turns into a pipe anybody can point at.

The Cost of Hosting Something Worth Attacking

Now the part that appears in no rate table.

Start with something a reader can check without trusting anybody. A data center’s security perimeter ends at its property line. Everything the building needs in order to run crosses that line from systems it does not own and cannot inspect. Water comes from Columbus Water Works. Power comes across Flint Energies’ wires. Which means a data center cannot be hardened independently of the utilities underneath it, however much its operator spends inside the fence.

Which produces an uncomfortable arrangement. A hyperscale operator has capital, staff, and commercial motive to protect its own building to a standard a municipal utility cannot approach. Columbus Water Works has a billion-dollar capital plan with no security line in it and a workforce GAO says the sector does not have. The softest point in the combined system is not the data center. It is the utility. And the utility stays soft, because no mandate reaches it and the money available to the whole country is $9 million.

Be careful about the next step, because it is where this argument can be pushed further than the evidence supports. There is no documented case of a data center’s presence causing an attack on its host city’s water utility. And what happened in July points the other way. Columbus and Clayton County were reached through equipment that was exposed and underdefended, which is Zonouz’s whole point. Neither one was chosen for its strategic value. Columbus has no data center yet, and it was hit anyway.

The narrower version is the one that holds. Soft infrastructure gets hit opportunistically whether or not a data center is there. What a nationally significant asset changes is the payoff to a deliberate attacker, without changing the defenses of the dependency that attacker would go through. The distance between what is worth attacking and what is capable of being defended gets wider. Residents are standing in that gap, and they did not choose to be.

The Bipartisan Policy Center published a report on data center development this year that puts the cost question in a usable form. The test it recommends for host communities is a simple one. What costs would not be introduced but for the data center? The purpose, in the report’s words, is to make sure large loads “pay their fair share and protect residential customers from rate impacts.”

Columbus already applies that logic. Subsection (O) of the overlay makes the developer financially responsible for system upgrades, and requires a development agreement covering infrastructure costs for water, sewer, electric, gas and telecom, including off-site work. That is a but-for test for pipes and wires.

Nobody applied it to the security of the systems those pipes belong to.

There is a smaller detail in the rate tables that runs the same direction. On volumes above 15 ccf, the billing unit the utility uses, industrial customers pay $2.30 while everyone else pays $2.64. The largest industrial water user imaginable would pay the cheapest marginal rate on the system. The Regulatory Compliance Fee compounds it, because the fee is charged per account rather than per gallon. By 2031 one hyperscale campus pays $100 a month toward compliance. A household pays $20.

The Fix Is in a Document the City Still Controls

A large customer with a real security interest could improve a municipal utility’s position rather than weaken it. It has money the utility does not have. It has motive the utility cannot generate on its own. And there is already a place to put the commitment.

Subsection (O) requires a development agreement, negotiated before any permit issues, that must address infrastructure costs and can address more than that. Nothing in the ordinance prevents Council from asking for enforceable security and continuity commitments in it. Nothing in the ordinance requires them either.

So hosting this campus is not automatically a loss for Columbus. What makes it a transfer of risk is that the upside is optional and the downside is shared. The availability letters certify volume. The overlay is silent on security. The ratepayer absorbing 4.95 percent a year is the payer of last resort by default, not by decision.

Cogle gave a reason for her no vote in June that reads differently now. “This is a premature thing,” she said, “and I’m not completely satisfied the enforcement will protect citizens.”

Mayor Pro Tem Gary Allen of District 6, voting for it, made the point that the document is not yet aimed at anything. “This is a tool,” Allen said. “We have no applications (for a data center).”

Both things are true. It is a tool, and no application has been filed. Which means the development agreement has not been written yet, and the questions below can still change what goes in it.

What the Public Has Not Been Told

These questions could not be answered from the public record. We are printing them instead of chasing them, because the answers belong in public on their own, and because a resident asking a utility board a direct question at a public meeting carries a weight a reporter’s phone call does not.

Every item here could be disclosed voluntarily tomorrow. None of it requires an open records request. All of it would survive one.

To Columbus Water Works:

One. Is there a cybersecurity line in the operating budget, separate from the $1.05 billion capital plan? What is it, and has it moved since the intrusion?

Two. Has the intrusion changed the capital plan, or does the October 28 rate presentation still stand as written?

Three. Has CWW completed the risk and resilience assessment required by Section 1433, and when was it last certified to EPA? The assessment is protected. Its existence is not.

Four. Has EPA inspected Columbus, and was Columbus among the 70 percent found in violation in March 2024?

Five. Did CWW apply for the EPA cybersecurity and resilience grant that closed October 6, 2025, and what was the result?

Six. Does the Regulatory Compliance Fee cover Section 1433 work, or only the sewer overflow, nutrient and PFAS work listed on the rate priorities slide?

To the Georgia Emergency Management Agency:

Seven. The FBI put this campaign in at least seven states and Clayton County disclosed its own incident in detail, including the equipment involved. What is the basis for withholding the number of Georgia systems targeted when the national count is public and one Georgia utility has already talked?

To Columbus Council:

Eight. Will Council commit to putting enforceable cybersecurity and continuity-of-service commitments in the subsection (O) development agreement, which the ordinance permits but does not require?

Nine. The subsection (M) availability letters ask whether a utility can deliver the volume. Will Council ask whether it can keep delivering under attack?

Ten. Applying the but-for test to security and not only to pipes: if hardening is needed because of this facility, who pays for it?

To Flint Energies:

Eleven. Who supplies generation and transmission for the Project Ruby load, and is that entity NERC-registered? Whether any mandatory cyber standard reaches the power serving this campus depends on the answer.

If you get an answer to any of these, in writing or on the record at a public meeting, send it to us.

Sources

Technology Overlay District ordinance text: REZN-02-26-0289, “CCG Technology Overlay as amended on 6-9-26,” second reading June 16, 2026, Columbus Council agenda. Buffer, generator, noise, cooling, enforcement and development agreement provisions quoted from the adopted text.

Council vote, councilor statements and districts: Columbus Ledger-Enquirer, Kala Hunter, June 16, 2026.

Columbus Water Works intrusion, July 27 detection, switch to manual operation and Chance Corbett quotes: WTVM, August 4, 2026.

Clayton County Water Authority pump station failure, boil water advisory and Erin Thomas quotes: WSB-TV, August 2026; Cobb County Courier / Georgia Recorder, August 4, 2026.

Georgia utilities polled on intrusions, Atlanta declining comment and Columbus not answering how access was gained: WSB-TV, August 2026; Atlanta Journal-Constitution, August 2026.

Columbus Water Works capital plan, rate increases and Regulatory Compliance Fee: Columbus Water Works 2026 Rate Update, presented to Columbus Council October 28, 2025, prepared with Raftelis; board approval December 8, 2025; CWW 2026 Rates Fact Sheet.

Water sector exposure and the compliance-versus-security tradeoff: GAO-26-109159, Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector, May 21, 2026; GAO-24-106744.

EPA enforcement alert on Safe Drinking Water Act Section 1433 compliance: March 2024.

EPA grant program: EPA announcement August 5, 2025, Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability grants; applications closed October 6, 2025.

Basic control costs and free training resources: South Carolina Department of Environmental Services water utility cybersecurity guidance; AWWA Water Sector Cybersecurity Risk Management Guidance; CISA and WaterISAC.

Saman Zonouz quotes, the 7,000 exposed controllers and the 30 percent removal figure: Georgia Recorder / Cobb County Courier, August 4, 2026; Atlanta Journal-Constitution, August 2026.

Iranian-affiliated targeting: CISA advisory, April 2026; Georgia Association for Water Professionals bulletin, as reported by the Atlanta Journal-Constitution, August 2026. Attribution for the Columbus incident has not been confirmed.

FBI nationwide alert of July 30, 2026, the seven-state figure and FBI statements including Jenna Sellitto: WSB-TV and Cobb County Courier, August 2026. Twelve-state figure: ABC News, August 2026.

NERC CIP applicability and the exclusion of local distribution from the Bulk Electric System definition: NERC reliability standards and registry criteria.

NRECA cybersecurity funding: Department of Energy award, November 2022.

But-for cost test, transparency findings and recommendations on conditioning benefits: Bipartisan Policy Center, Key Considerations for Data Center Development, 2026.

Project Ruby power request and Flint Energies service territory: prior 706report coverage; Ledger-Enquirer / Yahoo News, February 25, 2026.

Published at 706report.com — Independent investigative reporting for Columbus & Muscogee County

Robert Haven
Robert Haven
Articles: 57