Alpena Township in northeastern Michigan restored remote monitoring of its water and sewer systems after a July 27 cyberattack forced its utility operator to reprogram controllers at multiple sites.
Water and sewer service continued safely. The township was less severely affected than other UIS customers whose monitoring networks also controlled treatment operations, The Alpena News reported, citing the operator.
The township, home to about 9,100 residents around the city of Alpena, uses UIS SCADA’s CRUiSE cloud platform to remotely monitor wells, pumps, tanks and sewer stations.
F&V Operations and Resource Management, which operates the township’s water and sewer systems, told officials that UIS’s platform had been hacked and remote monitoring was lost. F&V reprogrammed programmable logic controllers at multiple sites to restore the connections.
UIS told customers the attack involved controllers and communications supporting its platform. The company said it was working with Michigan State Police, the FBI and the Michigan Department of Environment, Great Lakes, and Energy.
Township trustees voted Monday to postpone until September a $14,495 proposal to replace 15 older cellular modems. The proposed devices support firewalls and connections restricted to approved network addresses, protections UIS said the older hardware could not use. The township has not disclosed what safeguards are in place pending replacement or whether continued use of the modems presents an immediate security risk.
The Alpena incident occurred during a broader campaign of attacks on water and wastewater operational technology observed from July 26 through July 31. DysruptionHub has linked 13 incidents to the activity, which involved internet-facing controllers and caused losses of monitoring or control and some operational disruption across at least seven states.
The FBI and Environmental Protection Agency said attackers changed device IP addresses and passwords, causing operators to lose monitoring or control. The agencies documented a common technical pattern but did not attribute the activity to a specific actor. Public evidence has not established that one actor was responsible for every incident.
Michigan environmental officials separately said nine municipal water systems reported activity consistent with the federal warnings. Alpena Township is the first Michigan water utility publicly identified in connection with the July 27 attacks, though the state has not said whether it was among the nine. Officials said all nine systems continued operating safely and no known impacts posed a public health concern.
In another July 27 attack, Coweta County’s water utility in Georgia lost communication with a controller after attackers gained access through cellular connections. Operators switched to manual control, and water service continued.
Alpena officials have not disclosed how access was gained, the controller’s manufacturer or model, whether data was accessed or the investigation’s final technical findings. The township has not announced a technical all-clear, and Supervisor Abbi Kaszubowski said trustees postponed a decision on the modem purchase to gather more information.
Neither the township nor UIS responded to DysruptionHub’s requests for comment by publication time.