Tidewater Telecom

Malicious traffic disrupted Tidewater Telecom and Lincolnville Communications internet service across coastal Maine beginning July 19, 2026, leaving some connections unusable and significantly limiting Damariscotta Town Office services. The providers reported near-normal service July 21, and their status page subsequently showed customer internet operational with no recurrence through July 26.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.
A primary service, system, platform, or operational capability became entirely unavailable.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Tidewater Telecom and affiliated Lincolnville Communications experienced malicious cyber activity that disrupted internet service across coastal Maine beginning July 19, 2026. Tidewater’s official status page said engineers were working with upstream providers to drop malicious traffic clogging the network, while the companies separately described an external, computer-generated attack against their internet systems.
The public description is consistent with a traffic-flooding event and could reflect distributed denial of service. Neither provider has expressly confirmed DDoS, identified attacking infrastructure, disclosed an intrusion path or named a threat actor. The specific mechanism therefore remains unresolved.
The outage affected residential, business and government connections across a broad Midcoast and coastal Maine service area. We reported that the providers’ service locations extended from Bangor and Bath to Belfast, Camden, Damariscotta, Rockland and Waldoboro, along with smaller towns and villages.
Effects varied from unreliable service to nonfunctional connections. The Damariscotta Town Office said it had spotty or no internet access and that most office functions depended on connectivity, significantly limiting what staff could accomplish. Residents were advised to call before visiting so employees could confirm whether a requested service was available. This establishes direct customer access restrictions, impaired staff work and downstream government-service disruption.
The public record does not establish that emergency communications, public safety operations or utility control systems were affected. A contemporaneous provider notice concerning damage to fiber and copper networks and reported Spectrum outages may have involved separate conditions; no source links them to the malicious traffic.
The providers acknowledged the outage through their operational status page and later explicitly described malicious traffic affecting the network. Their updates identified mitigation with upstream providers, warned that conditions remained dynamic and documented restoration progress.
The companies told News Center Maine that they found no indication customer data was compromised, as reported by DysruptionHub and Communications Today. That supports no known data impact, although the public record does not include a technical report explaining the investigation or scope of review.
Tidewater reported at 7:37 a.m. EDT July 21 that Tidewater and Lincolnville services had returned to near-normal operating conditions and asked customers with unusable or severely affected connections to report continuing problems. The live status page showed customer internet operational across all listed service locations during the July 26 review and reported no incidents from July 22 through July 26. These positive restoration indicators support resolved status and a July 21 operational end.
Confidence is high that malicious cyber activity caused material internet disruption because the providers directly acknowledged malicious traffic and the outage. Confidence is high that broad service was restored by July 21 because the provider reported near-normal operation and the later status page showed all internet locations operational without recurrence.
Confidence is lower on the mechanism. The mitigation pattern fits denial of service, but no authoritative source confirmed distributed traffic, attack volume, protocol mix or source infrastructure. No public evidence reviewed identified ransomware, extortion, malware, unauthorized access, data theft or a responsible actor.
The public record does not establish the attack’s origin, volume, protocol mix, exact packet-level duration, targeted services, mitigation provider or whether traffic reached customer-premises systems. It also does not identify compromise of internal systems, persistent access, malware deployment or law-enforcement involvement.
The providers have not published a post-incident technical report or explained the basis and scope of their no-customer-data-impact finding. Additional telemetry or provider disclosure would be required to confirm DDoS and determine whether the event was limited entirely to availability disruption.



Substantial service-area overlap through LCI and related operations, including Union, Hope, Appleton, Camden, Rockland and Rockport.
Core service area for Tidewater Telecom, including Damariscotta, Bristol, South Bristol, Bremen, Newcastle, Nobleboro, Edgecomb, Alna and surrounding communities.
Limited or peripheral service-area overlap, including Bowdoinham and Richmond; Bath appears in the broader customer-area list but is less clearly within the core regulated telephone footprint.
Northern service area associated primarily with Lincolnville Telephone Company and LCI, including Lincolnville, Northport and Belfast.
DysruptionHub reported that an external computer-generated attack and malicious traffic disrupted Tidewater and Lincolnville internet service across coastal Maine. Damariscotta documented spotty or no connectivity that limited Town Office work, and broad service returned to near-normal July 21.
The provider said July 20 that it was working with internet uplinks to drop malicious traffic clogging the network. It reported near-normal Tidewater and Lincolnville service July 21; by July 26 all listed customer internet locations were operational and no incidents had been reported since July 21.
Communications Today reported a widespread partial internet outage across more than 20 Maine towns after Tidewater and LCI identified an external computer-generated attack. The companies said no consumer data was affected, while Damariscotta said its office had spotty or no internet and significantly limited services.
Signed-in members can report an error, update, or missing source.