Skip to content

Tidewater cyberattack disrupts internet across coastal Maine

Malicious traffic clogged the provider’s network, limiting municipal services before connections returned to near-normal conditions Tuesday.

Tidewater cyberattack disrupts internet across coastal Maine
Tidewater Telecom’s sign outside its Nobleboro, Maine, headquarters lists affiliated Lincolnville and Coastal Telco companies.

A cyberattack disrupted Tidewater Telecom internet service across dozens of communities in coastal Maine beginning Sunday, limiting municipal operations before service returned to near-normal conditions Tuesday.

The outage affected residential, business and government connections across a broad coastal service area. Tidewater and affiliated provider Lincolnville Communications Inc. are part of a family-owned Maine telecommunications company that maintains thousands of miles of telephone and fiber-optic lines.

Tidewater and LCI determined that an external, computer-generated attack had targeted their internet systems, the companies told News Center Maine. They said they had found no indication that customer data was compromised.

The companies later described the attack as malicious traffic that was clogging their network. Engineers worked with upstream internet providers to block the traffic, according to Tidewater’s official status page.

The outage also disrupted local government services. The Damariscotta Town Office said it had spotty or no internet access, significantly limiting staff because most office functions depend on an internet connection.

Officials advised residents to call before visiting to confirm that employees could provide the service they needed.

Screenshot of a Damariscotta, Maine, Facebook post saying the Town Office had spotty or no internet service and asking residents to call before visiting.
The Damariscotta Town Office warned residents that a Tidewater Telecom outage left it with spotty or no internet service, limiting many office functions.

Tidewater initially said Monday morning that it had identified the problem and was implementing a fix. By Monday evening, the provider said conditions were improving but cautioned that the attack remained dynamic.

At 7:37 a.m. Tuesday, Tidewater said its and Lincolnville’s services had returned to near-normal operating conditions. It asked customers whose connections remained unusable or severely affected to contact the company. The status page listed customer internet service as operational, although traditional voice service was still classified as experiencing a major outage.

The provider’s status page listed internet service locations from Bangor and Bath to Belfast, Camden, Damariscotta, Rockland and Waldoboro, along with smaller coastal towns and villages. Tidewater offers residential and business internet, telephone and streaming television services from its headquarters in Nobleboro.

The Maine disruption followed a separate denial-of-service attack last week against Greenfield Communications in California. That outage cut internet service for nearly 48 hours in Rancho Murieta and other parts of Sacramento County, disrupting payments and local services.

Screenshot of Tidewater Telecom’s internet outage status page showing updates that malicious traffic was clogging the network and services later returned to near-normal conditions.
Tidewater Telecom’s status page said engineers blocked malicious traffic and restored Tidewater and Lincolnville services to near-normal operating conditions on July 21, 2026.

Tidewater had not publicly identified the specific attack type. Its description was consistent with a traffic-flooding attack, but the company had not confirmed that it was a distributed denial-of-service attack.

Spectrum customers also reported service problems in parts of coastal Maine during the Tidewater disruption, but no public evidence established that the outages were connected. The providers operate separate local networks, although they could depend on common regional fiber routes, transit carriers or interconnection facilities farther upstream.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Tidewater had not publicly identified the specific attack method. The company’s description of malicious traffic clogging its network was consistent with a traffic-flooding attack, but it had not confirmed a distributed denial-of-service attack.

DysruptionHub contacted Tidewater for additional information but did not receive a response by publication.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all