ICS/OT

Kansas Water Facility Switches to Manual Operations Following Cyberattack

Ransomware possibly involved in a cybersecurity incident at Arkansas City’s water treatment facility.

Water utility cybersecurity

Arkansas City, a small city in Kansas, says its water treatment facility was forced to switch to manual operations while a cybersecurity incident is being resolved.

The incident, described by local media as a cyberattack, was discovered on the morning of September 22 and led to precautionary measures being taken “to ensure plant operations remained secure”, the city announced in an incident notice.

According to city manager Randy Frazer, the water supply has not been affected and the incident has not caused disruption to service.

“Despite the incident, the water supply remains completely safe, and there has been no disruption to service. Out of caution, the water treatment facility has switched to manual operations while the situation is being resolved,” Frazer said.

He also noted that the city has full control of the situation and reassured residents that the drinking water is safe.

Arkansas City says it has notified the relevant authorities of the incident and that they are working with cybersecurity experts to address the issue and return the facility’s operations to normal.

Advertisement. Scroll to continue reading.

“Enhanced security measures are currently in place to protect the water supply, and no changes to water quality or service are expected for residents,” the city said.

While the city’s notification does not share further details on the incident, it appears that the water treatment plant might have fallen victim to a ransomware attack.

Switching to manual operations suggests that systems were shut down to contain the attack, which is the typical response to incidents involving ransomware.

SecurityWeek has emailed Arkansas City for additional information on the incident and will update this article as soon as a reply arrives.

It’s not uncommon for US water facilities to be targeted by threat actors and the government has been taking steps to increase the water sector’s resilience to cyberattacks. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 21-24, 2024 | Atlanta
www.icscybersecurityconference.com

Related: White House Issues National Security Memorandum for Critical Infrastructure

Related: DHS Launches New Critical Infrastructure Security and Resilience Campaign

Related: Snap-on Tools Hit by Cyberattack Claimed by Conti Ransomware Gang

Related Content

ICS/OT

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

Incident Response

The company has called in CrowdStrike and others to investigate the attack that caused global network disruption.

Cybercrime

The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.

ICS/OT

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

ICS/OT

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Cybercrime

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Government

The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.

ICS/OT

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version