Skip to content

Childersburg water utility SCADA cyberattack

Summary

Childersburg Water Works, Sewer, and Gas Board logo

The utility kept water, sewer and gas service operating manually after the July 27 SCADA attack and expected security work to take about two weeks. That period passed without a later continuing limitation, so the incident is presumed resolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Childersburg Water Works, Sewer, and Gas Board said a July 27 cyberattack targeted a programmable logic controller within its supervisory control and data acquisition environment. According to WVTM, the utility took SCADA offline after identifying the problem, reported the incident to the FBI and other agencies, and continued operating through unaffected manual systems. Our published report documented the same operational response. Separately, DysruptionHub assesses with high confidence that malicious cyber activity disrupted an operational-technology capability at the utility.

The public record does not establish how the attacker reached the PLC, what configuration or logic was changed, whether the attacker obtained sustained access, or which controller model was involved. The utility described the equipment as targeted but did not publish technical findings that would support a more specific attack mechanism.

Operational significance

The incident affected automation used to monitor and control utility operations, but it did not interrupt water, sewer or gas service. Staff shifted to manual operation, and the utility said the public water supply was never in danger. This distinction is operationally important: the attack removed a normal automated control capability and required a continuity procedure, but the available evidence does not support a public water outage, boil-water advisory, pressure loss, contamination event or interruption to sewer or natural-gas service.

An Aug. 9 report quoting Board Director Travis Mizzell said utility crews were installing additional cybersecurity protections and expected the work to take about another week. Continued manual operation indicates a material internal utility disruption even though customers continued receiving normal service. The incident therefore reflects partial loss of an operational capability rather than a complete service outage.

Disclosure posture

The first identified public confirmation appeared in WVTM’s August 7 report, which attributed the cyberattack, manual response and safety statements directly to the utility. The utility also said multiple other public utilities were targeted, but it did not identify them or establish that the incidents shared one actor or method.

A July 30 FBI and EPA alert described attacks beginning July 27 against internet-facing PLCs at water and wastewater utilities in at least seven states. The agencies said attackers changed device addresses and passwords in some cases, causing loss of monitoring or control. Childersburg has not publicly identified its PLC model or confirmed that its incident involved the specific controllers, configuration changes or actors described in the federal alert, so that campaign provides context rather than incident-specific attribution.

Current status

The incident is presumed resolved. The utility was still operating the affected SCADA function manually Aug. 9 while safeguards were installed, and officials expected that security work to take about two weeks. That expected period passed without a later report of continuing manual operation or another operational limitation. Water, sewer and gas service remained uninterrupted throughout the documented response. This is an analytic presumption based on the stated recovery timetable and absence of contrary evidence, not a utility-issued technical all-clear that automated control was restored.

Confidence and uncertainty

Confidence is high that a cyberattack affected the utility’s PLC/SCADA environment because the utility directly characterized the event and described its response. Confidence is also high that public utility service continued and the water supply remained safe, based on the utility’s statements.

The specific cyber mechanism remains unresolved because the public record does not establish unauthorized configuration changes, vulnerability exploitation, credential compromise, malware or another technical path in Childersburg. Ransomware involvement and threat-actor attribution are unresolved. No data theft, ransom demand or public actor identification has been disclosed.

Analytic gaps

The public record does not identify the PLC manufacturer or model, internet-exposure configuration, initial access vector, compromised credentials, exploited vulnerability, source address, configuration or ladder-logic changes, persistence, lateral movement, affected SCADA components, forensic indicators, data impact, ransom activity or responsible actor. It also does not establish which other utilities were allegedly targeted, whether the events were coordinated, or when Childersburg fully restored automated operations.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Medium

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The campaign now includes 15 named incidents; Michigan has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA, supporting a possible shared-provider exposure. That pattern does not prove UIS itself was compromised or establish common attribution, and the complete victim list remains unknown.

Why this incident is included

Childersburg reported a July 27 attack targeting a PLC in its SCADA environment, loss of automated monitoring and control, manual fallback, FBI notification and safe continued service. Those incident-specific characteristics strongly match the federal campaign window and operational pattern, but no public source confirms the controller model, internet exposure, changed address or password, shared provider or common actor.

Organizations involved

Impacted location

  • Childersburg, Alabama

    The affected organization is Childersburg's public utility board and the identified impact was within its local utility operations.

Sources

Childersburg Water Works in Alabama reports cyberattack; water service unaffected

Our reporting found that a cyberattack targeted a PLC in the Childersburg utility’s SCADA environment and that workers shifted to unaffected manual operations. Water service and the public supply remained safe, SCADA was still offline, and no data theft, ransom demand or threat actor had been disclosed.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions

The FBI and EPA warned that water and wastewater utilities in at least seven states reported incidents beginning July 27 involving internet-facing PLCs. The agencies said attackers changed IP addresses and passwords in some cases, causing loss of monitoring or control, but did not identify Childersburg or a threat actor.

Childersburg Water, Sewer and Gas reports cyberattack; service unaffected

WVTM reported that the utility said a July 27 cyberattack targeted a PLC within its SCADA system. The utility took SCADA offline, continued uninterrupted manual operations, said the water supply was never in danger, reported the event to the FBI and expected additional security work to take about two weeks.

The Childersburg Water, Sewer, and Gas Board was recently targeted by an attempted cyber attack

GCVTV reported Aug. 9 that Board Director Travis Mizzell said the utility remained on manual operations while crews installed additional cybersecurity protections. Water, sewer and gas service continued without interruption, and the safeguards were expected to take about another week.

See something that needs correction?

Signed-in members can report an error, update, or missing source.