Analyst assessment
Childersburg Water Works, Sewer, and Gas Board said a July 27 cyberattack targeted a programmable logic controller within its supervisory control and data acquisition environment. According to WVTM, the utility took SCADA offline after identifying the problem, reported the incident to the FBI and other agencies, and continued operating through unaffected manual systems. Our published report documented the same operational response. Separately, DysruptionHub assesses with high confidence that malicious cyber activity disrupted an operational-technology capability at the utility.
The public record does not establish how the attacker reached the PLC, what configuration or logic was changed, whether the attacker obtained sustained access, or which controller model was involved. The utility described the equipment as targeted but did not publish technical findings that would support a more specific attack mechanism.
Operational significance
The incident affected automation used to monitor and control utility operations, but it did not interrupt water, sewer or gas service. Staff shifted to manual operation, and the utility said the public water supply was never in danger. This distinction is operationally important: the attack removed a normal automated control capability and required a continuity procedure, but the available evidence does not support a public water outage, boil-water advisory, pressure loss, contamination event or interruption to sewer or natural-gas service.
An Aug. 9 report quoting Board Director Travis Mizzell said utility crews were installing additional cybersecurity protections and expected the work to take about another week. Continued manual operation indicates a material internal utility disruption even though customers continued receiving normal service. The incident therefore reflects partial loss of an operational capability rather than a complete service outage.
Disclosure posture
The first identified public confirmation appeared in WVTM’s August 7 report, which attributed the cyberattack, manual response and safety statements directly to the utility. The utility also said multiple other public utilities were targeted, but it did not identify them or establish that the incidents shared one actor or method.
A July 30 FBI and EPA alert described attacks beginning July 27 against internet-facing PLCs at water and wastewater utilities in at least seven states. The agencies said attackers changed device addresses and passwords in some cases, causing loss of monitoring or control. Childersburg has not publicly identified its PLC model or confirmed that its incident involved the specific controllers, configuration changes or actors described in the federal alert, so that campaign provides context rather than incident-specific attribution.
Current status
The incident is presumed resolved. The utility was still operating the affected SCADA function manually Aug. 9 while safeguards were installed, and officials expected that security work to take about two weeks. That expected period passed without a later report of continuing manual operation or another operational limitation. Water, sewer and gas service remained uninterrupted throughout the documented response. This is an analytic presumption based on the stated recovery timetable and absence of contrary evidence, not a utility-issued technical all-clear that automated control was restored.
Confidence and uncertainty
Confidence is high that a cyberattack affected the utility’s PLC/SCADA environment because the utility directly characterized the event and described its response. Confidence is also high that public utility service continued and the water supply remained safe, based on the utility’s statements.
The specific cyber mechanism remains unresolved because the public record does not establish unauthorized configuration changes, vulnerability exploitation, credential compromise, malware or another technical path in Childersburg. Ransomware involvement and threat-actor attribution are unresolved. No data theft, ransom demand or public actor identification has been disclosed.
Analytic gaps
The public record does not identify the PLC manufacturer or model, internet-exposure configuration, initial access vector, compromised credentials, exploited vulnerability, source address, configuration or ladder-logic changes, persistence, lateral movement, affected SCADA components, forensic indicators, data impact, ransom activity or responsible actor. It also does not establish which other utilities were allegedly targeted, whether the events were coordinated, or when Childersburg fully restored automated operations.