Other

BleepingComputer

πŸ“… 2024-10-03 🏒 American Water Works customer IT systems
Primary Source β†—

Incident Details

American Water Works, the largest regulated water and wastewater utility in the United States (serving 14+ million people across 14 states), detected unauthorized activity in its IT networks on October 3, 2024, and disclosed it via SEC 8-K filing on October 7. The company immediately disconnected affected systems and shut down its customer-facing MyWater portal and billing services, waiving late fees during the outage. Water and wastewater treatment operations were not impacted. The attack type and responsible threat actor were not publicly confirmed. American Water stated the incident was not expected to have a material financial effect. The incident highlighted critical infrastructure cybersecurity risk for water utilities, prompting CISA and EPA advisories.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
American Water Works customer IT systems

Timeline

  1. 2024-10-03 Breach occurred
  2. 2024-10-07 Publicly disclosed
  3. 2024-10-07 Customers notified