Skip to content

Alpena Township, Michigan, restores water and sewer monitoring after cyberattack

The attack disrupted remote monitoring but not water or sewer service, while its access method and the security of older modems remain unclear.

White water tower labeled “Alpena Township” against a clear blue sky, with communications antennas mounted on top.
An Alpena Township water tower in northeastern Michigan. The township restored remote monitoring of its water and sewer systems after a July 27 cyberattack. (Kat H/Tripadvisor)

Alpena Township in northeastern Michigan restored remote monitoring of its water and sewer systems after a July 27 cyberattack forced its utility operator to reprogram controllers at multiple sites.

Water and sewer service continued safely. The township was less severely affected than other UIS customers whose monitoring networks also controlled treatment operations, The Alpena News reported, citing the operator.

The township, home to about 9,100 residents around the city of Alpena, uses UIS SCADA’s CRUiSE cloud platform to remotely monitor wells, pumps, tanks and sewer stations.

F&V Operations and Resource Management, which operates the township’s water and sewer systems, told officials that UIS’s platform had been hacked and remote monitoring was lost. F&V reprogrammed programmable logic controllers at multiple sites to restore the connections.

UIS told customers the attack involved controllers and communications supporting its platform. The company said it was working with Michigan State Police, the FBI and the Michigan Department of Environment, Great Lakes, and Energy.

Township trustees voted Monday to postpone until September a $14,495 proposal to replace 15 older cellular modems. The proposed devices support firewalls and connections restricted to approved network addresses, protections UIS said the older hardware could not use. The township has not disclosed what safeguards are in place pending replacement or whether continued use of the modems presents an immediate security risk.

The Alpena incident occurred during a broader campaign of attacks on water and wastewater operational technology observed from July 26 through July 31. DysruptionHub has linked 13 incidents to the activity, which involved internet-facing controllers and caused losses of monitoring or control and some operational disruption across at least seven states.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The FBI and Environmental Protection Agency said attackers changed device IP addresses and passwords, causing operators to lose monitoring or control. The agencies documented a common technical pattern but did not attribute the activity to a specific actor. Public evidence has not established that one actor was responsible for every incident.

Michigan environmental officials separately said nine municipal water systems reported activity consistent with the federal warnings. Alpena Township is the first Michigan water utility publicly identified in connection with the July 27 attacks, though the state has not said whether it was among the nine. Officials said all nine systems continued operating safely and no known impacts posed a public health concern.

In another July 27 attack, Coweta County’s water utility in Georgia lost communication with a controller after attackers gained access through cellular connections. Operators switched to manual control, and water service continued.

Alpena officials have not disclosed how access was gained, the controller’s manufacturer or model, whether data was accessed or the investigation’s final technical findings. The township has not announced a technical all-clear, and Supervisor Abbi Kaszubowski said trustees postponed a decision on the modem purchase to gather more information.

Neither the township nor UIS responded to DysruptionHub’s requests for comment by publication time.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all