Skip to content

Coweta County water-control system intrusion

Summary

Coweta County Water and Sewerage Authority logo

Intruders gained remote access to Coweta County Water and Sewerage Authority controls on July 27, 2026, changed passwords and disrupted automated control communication, prompting operators to switch to manual operation. Authority officials said water service, water quality and customer data were unaffected. No later operational impact was documented, and the incident is presumed resolved; the final automated-control restoration time and responsible actor remain unknown.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Safety risk or operational hazard

    The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Coweta County Water and Sewerage Authority experienced an operational-technology intrusion July 27, 2026. The authority’s CEO told Atlanta News First that intruders gained access through cellular channels, changed passwords and shut down controls. The IT team detected the event after losing communication with a programmable logic controller used for valves and pump stations. WSB Radio reported that the intruders attempted to turn valves on and off.

Those affected-organization statements establish unauthorized access and a cyber incident. They do not establish whether stolen credentials, a default password, a vulnerability or another weakness enabled entry.

Operational significance

The intrusion reached equipment used to monitor or control valves and pump stations in a public water system. Operators shifted to manual control while credentials were reset, preserving service but temporarily removing normal automated functionality. Authority officials said water service and water quality were not interrupted.

The FBI and EPA’s July 30 alert described a broader campaign beginning July 27 against internet-facing water-sector programmable logic controllers. The alert documents similar password and IP-address changes across multiple states, but it does not name Coweta or attribute this incident.

Disclosure posture

The authority’s cyber-specific statements were first published Aug. 7 through local news reports. No reviewed external source publicly characterized the Coweta event before those affected-organization statements.

Current status

The incident is presumed resolved. July 27 remains the only documented day of impaired automated control and manual operation, and no later source documented continuing operational impact by Aug. 26, 30 days after that observation. The status does not establish the exact automated-control restoration time or the conclusion of the investigation.

Confidence and uncertainty

Confidence is high that unauthorized access disrupted automated controls because two local reports carried detailed statements from authority officials. Officials said customer data was not compromised, but the reviewed sources do not provide a broader forensic data-impact assessment. Ransomware, extortion and threat-actor attribution remain unresolved.

Analytic gaps

The public record does not identify the cellular service or device, controller manufacturer or model, access vector, credential source, vulnerability, source infrastructure, dwell time, persistence, unauthorized configuration changes beyond passwords and attempted valve actions, threat actor, final automated-control restoration date or forensic conclusion.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Medium

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The campaign now includes 15 named incidents; Michigan has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA, supporting a possible shared-provider exposure. That pattern does not prove UIS itself was compromised or establish common attribution, and the complete victim list remains unknown.

Why this incident is included

Coweta County’s July 27 intrusion closely matches the campaign’s reported technical and operational pattern: cellular remote access, loss of PLC communications, password changes, manual operations and attempted valve actions. No authoritative source explicitly names Coweta as a campaign victim or establishes the controller model, shared infrastructure or common actor.

Organizations involved

Impacted locations

Sources

Hackers accessed Coweta County water controls in Georgia

We reported that attackers accessed operational controls July 27, changed passwords and prompted a switch to manual control. Our reporting documented officials’ statements that service, water quality and customer data were unaffected and noted that full automated-control restoration and attribution remained unresolved.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions

The FBI and EPA warned that malicious actors had targeted internet-facing water-sector PLCs in at least seven states since July 27. Actors changed device IP addresses and passwords, causing loss of monitoring and control; some victims experienced degraded water operations.

Coweta County water authority targeted in cyberattack

Atlanta News First quoted CEO Jay Boren saying attackers accessed the water system through cellular channels, changed passwords and shut down controls. The utility detected the intrusion after losing communication with a programmable logic controller, moved to manual operations and reported no service interruption or customer-data impact.

Investigation underway after hackers targeted Coweta County Water System

WSB Radio reported that the authority confirmed cyber criminals gained access to controls and attempted to turn valves on and off. CEO Jay Boren said the incident did not disrupt water service and had no effect on water quality or customer information.

Coweta County Water and Sewerage Authority

The authority’s official website identifies Coweta Water & Sewerage Authority and says CCWSA provides water and wastewater services to more than 31,000 active water customers and 3,500 sewer customers in Coweta County and surrounding communities.

See something that needs correction?

Signed-in members can report an error, update, or missing source.