Analyst assessment
DysruptionHub assesses with high confidence that Coweta County Water and Sewerage Authority experienced an operational-technology intrusion July 27, 2026. The authority’s CEO told Atlanta News First that intruders gained access through cellular channels, changed passwords and shut down controls. The IT team detected the event after losing communication with a programmable logic controller used for valves and pump stations. WSB Radio reported that the intruders attempted to turn valves on and off.
Those affected-organization statements establish unauthorized access and a cyber incident. They do not establish whether stolen credentials, a default password, a vulnerability or another weakness enabled entry.
Operational significance
The intrusion reached equipment used to monitor or control valves and pump stations in a public water system. Operators shifted to manual control while credentials were reset, preserving service but temporarily removing normal automated functionality. Authority officials said water service and water quality were not interrupted.
The FBI and EPA’s July 30 alert described a broader campaign beginning July 27 against internet-facing water-sector programmable logic controllers. The alert documents similar password and IP-address changes across multiple states, but it does not name Coweta or attribute this incident.
Disclosure posture
The authority’s cyber-specific statements were first published Aug. 7 through local news reports. No reviewed external source publicly characterized the Coweta event before those affected-organization statements.
Current status
The incident is presumed resolved. July 27 remains the only documented day of impaired automated control and manual operation, and no later source documented continuing operational impact by Aug. 26, 30 days after that observation. The status does not establish the exact automated-control restoration time or the conclusion of the investigation.
Confidence and uncertainty
Confidence is high that unauthorized access disrupted automated controls because two local reports carried detailed statements from authority officials. Officials said customer data was not compromised, but the reviewed sources do not provide a broader forensic data-impact assessment. Ransomware, extortion and threat-actor attribution remain unresolved.
Analytic gaps
The public record does not identify the cellular service or device, controller manufacturer or model, access vector, credential source, vulnerability, source infrastructure, dwell time, persistence, unauthorized configuration changes beyond passwords and attempted valve actions, threat actor, final automated-control restoration date or forensic conclusion.