Skip to content

Cyberattack on Columbus Water Works monitoring systems

Summary

Columbus Water Works logo

Columbus Water Works detected and contained a cyberattack on July 27, 2026, affecting portions of its automated monitoring systems. Operators shifted to manual control, and officials reported no interruption to water service or drinking-water quality; the access method and responsible actor remain unknown.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Columbus Water Works experienced malicious cyber activity affecting portions of its automated water-utility monitoring environment on July 27, 2026. DysruptionHub’s published report said the utility detected and contained the attack and that operators immediately moved affected monitoring functions to manual control.

The public evidence supports a cyber incident involving operational technology or closely related monitoring systems, but it does not establish the specific device class, controller model, software platform or initial access method. The utility did not publicly identify the equipment affected, and authorities had not publicly linked the incident to the broader multi-state campaign against internet-connected industrial controllers.

A March 2026 preliminary official statement for Columbus water-system revenue bonds said the utility’s operations depend on IT and operational technology, including SCADA, billing systems and other computerized controls. It also disclosed three cyber incidents during the preceding five years, none of which caused extortion demands, data breaches or operational-system impacts; one 2025 incident produced an approximately $60,000 insurance-deductible expense. That history makes the July event analytically distinct because it is the first incident in the disclosed period with a publicly documented operational workaround. It does not, however, establish that a SCADA component or PLC was compromised in July.

Operational significance

The incident is operationally significant because Columbus Water Works provides water and wastewater services in Columbus and at nearby Fort Benning, and the affected systems supported automated monitoring of essential utility operations. Operators’ immediate use of manual controls demonstrates a real operational workaround even though officials said they never lost control of the system.

Officials reported that drinking water remained safe and that water service was not interrupted. The available record therefore does not support a complete or partial utility-service outage, water-quality degradation, a boil-water advisory or a public-health effect. The principal documented impact was the loss or impairment of some automated monitoring capability and the resulting need for manual operation.

Disclosure posture

The strongest public account available to DysruptionHub is media reporting based on statements from Columbus emergency-management leadership and the utility’s president and chief executive. Those statements confirmed the attack, the affected monitoring function, the switch to manual control and the absence of public-facing water impacts, but they did not provide a technical incident report or a detailed recovery timeline.

The utility’s 2025 Report to the Community said it had completed targeted security enhancements and continued investing in physical security, cybersecurity, emergency-response planning and operational resilience. Those pre-incident measures provide context for the rapid manual response, but they do not independently establish which safeguard contained the July attack.

Current status

The attack was described as contained, and officials reported no interruption to service or water quality. However, the public record does not state when all affected automated monitoring functions were restored, so DysruptionHub assesses the operational impact as presumed resolved rather than positively confirmed as fully restored. The FBI, Georgia emergency-management officials and other federal partners were still investigating as of the August 4 report.

Confidence and uncertainty

Confidence is high that a cyberattack affected monitoring systems because officials directly described malicious activity and the operational response. Confidence is also high that water service and drinking-water quality were not affected, based on consistent statements attributed to utility and emergency-management officials.

Ransomware is not established. No ransom demand, encryption event, data theft or threat-actor attribution had been confirmed publicly. The broader federal warning about attacks on water and wastewater utilities provides relevant context but does not prove that Columbus Water Works was part of that campaign.

Analytic gaps

The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account, affected controller or software product, malware family, persistence mechanism, dwell time or whether the attacker changed configurations or credentials. They also do not establish whether any administrative or operational data was accessed, copied, altered or destroyed.

The public record does not identify a threat actor, motive, ransom demand or payment request. It also does not provide a final restoration notice for automated monitoring, a forensic conclusion or an authoritative determination linking this incident to the multi-state attacks reported by federal agencies.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Low

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

Columbus Water Works documented a July 27 cyberattack that impaired portions of automated monitoring and required immediate manual control, matching the campaign’s start date and a core operational pattern in the federal alert. No public source confirms a PLC, shared access method, configuration change, common infrastructure or actor, and no authoritative source directly names Columbus as a campaign victim.

Organizations involved

Impacted locations

Sources

Cyberattack contained at Columbus Water Works in Georgia

Columbus Water Works detected and contained a cyberattack July 27 that affected portions of its automated monitoring systems. Operators switched immediately to manual controls, officials said water service and drinking-water quality were not affected, and investigators had not identified an access method, threat actor, data theft or ransom demand.

Preliminary Official Statement dated March 18, 2026

The bond statement says Columbus Water Works depends on IT and operational technology, including SCADA, and had three cyber incidents in the preceding five years. None caused extortion, a data breach or operational-system impact; one 2025 incident produced an approximately $60,000 insurance-deductible expense.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers

The FBI said water and wastewater utilities in at least seven states had reported incidents since July 27 involving malicious access to internet-facing programmable logic controllers, with some activity degrading water operations. Authorities had not publicly confirmed that Columbus Water Works was part of that campaign.

Columbus Water Works detects cyberattack; officials say water is safe

WRBL reported that Columbus Water Works operators switched affected monitoring systems to manual controls and never lost control. Columbus emergency-management director Chance Corbett and utility CEO Jeremy Cummings said the rapid response prevented public impact and that the water remained safe.

2025 Report to the Community

Columbus Water Works said it completed targeted security enhancements in 2025 and continued investing in physical security, cybersecurity, emergency-response planning and operational resilience.

See something that needs correction?

Signed-in members can report an error, update, or missing source.