Skip to content

Childersburg Water Works in Alabama reports cyberattack; water service unaffected

A programmable logic controller in the utility’s automated control system was targeted July 27, but manual operations kept water service running and the utility said the public supply was never in danger.

Childersburg Water Works in Alabama reports cyberattack; water service unaffected
Published:

Water Works, Sewer and Gas said a July 27 cyberattack targeted part of its automated control system, but water service in the Alabama city continued without interruption.

The board provides water, sewer and natural gas service to Childersburg and surrounding areas, according to the utility’s website. The targeted equipment was part of the utility’s supervisory control and data acquisition, or SCADA, system, which is used to monitor and control utility operations.

The attack targeted a programmable logic controller, or PLC, within that system, the utility told WVTM. After discovering the problem, workers took the SCADA system offline and shifted to manual operations, according to the station’s report. The utility said the manual systems were not affected and the public water supply was never in danger.

The utility also said it reported the incident to the FBI and other agencies and that multiple other public utilities were targeted, the station reported. The utility did not identify them or say whether the incidents were linked to the same actor.

Separately, the FBI and Environmental Protection Agency said in a July 30 alert that water and wastewater utilities in at least seven states had reported incidents beginning July 27 involving internet-facing programmable logic controllers. The agencies said attackers had changed device addresses and passwords in some cases, causing some utilities to lose monitoring or control capabilities and degrading water operations at some facilities.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The FBI and EPA alert specifically cited Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers. Childersburg has not publicly identified the model of its targeted PLC, so there is no public confirmation that its incident involved those devices or the same attackers. The federal alert did not identify a threat actor.

Water-sector control systems have faced similar targeting before. In 2023, the Cybersecurity and Infrastructure Security Agency warned that Unitronics PLCs used by U.S. water and wastewater systems were being actively exploited. Later federal guidance attributed that separate campaign to actors affiliated with Iran’s Islamic Revolutionary Guard Corps. Federal officials have not publicly linked that earlier campaign to the Childersburg incident.

Childersburg Water Works said the SCADA system remains offline while workers install additional security measures, a process expected to take about two weeks, according to WVTM. The utility said it continues to operate manually and that water service remains unaffected. No data theft, ransom demand or threat actor has been publicly disclosed.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all