KEMETIC MINDS
Infrastructure Watch — Daily Update — September 11, 2026
FirstEnergy Pennsylvania’s defensive systems block tens of thousands of automated malicious connection attempts against its public-facing services every month, the company’s chief security officer told a panel of state lawmakers.
The testimony came as Pennsylvania House members weigh whether utilities need new cybersecurity requirements — and who should pay for them.
- FirstEnergy Pennsylvania serves 2.1 million electric customers across 56 counties and says it blocks tens of thousands of automated malicious connection attempts each month (New Hope Free Press, 2026).
- Rep. Pat Gallagher (D-Philadelphia) said attackers aim to “manipulate, disrupt or disable the very control systems that provide light, heat and clean water for our communities” (New Hope Free Press, 2026).
- Craig Fahnestock of the Pennsylvania Municipal Authorities Association said cybersecurity “now competes for the same limited resources needed for pipes, pumps and capital improvements” (New Hope Free Press, 2026).
- His association represents nearly 700 municipal water authorities, many of them small (New Hope Free Press, 2026).
- Utility executives and experts agreed the spending is nearly as necessary as infrastructure investment — but warned the cost lands on ratepayers (New Hope Free Press, 2026).
- No confirmed breach, outage or lost service was described in the hearing account (New Hope Free Press, 2026).
1. FirstEnergy Blocks Tens of Thousands of Attacks a Month
What the company told lawmakers
Brian Harrell, chief security officer at FirstEnergy Pennsylvania, said his company’s defenses block tens of thousands of automated malicious connection attempts against public-facing services each month (New Hope Free Press, 2026).
“These statistics underscore why cybersecurity requires constant attention and continual enhancement,” Harrell told the panel (New Hope Free Press, 2026).
The utility serves 2.1 million electric customers across 56 counties, according to the account of the hearing (New Hope Free Press, 2026).
Attackers are going after control systems, not billing pages
Rep. Pat Gallagher (D-Philadelphia), who chairs the House Consumer Protection, Technology and Utilities Committee’s subcommittee on utilities, said the targets are the systems that keep the lights and water running (New Hope Free Press, 2026).
“They’re seeking to manipulate, disrupt or disable the very control systems that provide light, heat and clean water for our communities,” Gallagher said (New Hope Free Press, 2026).
He called for a “unified front, one that bridges private operators, public regulators, state agencies and both political parties” (New Hope Free Press, 2026).
The money problem: security now competes with pipes and pumps
Utility executives and cybersecurity experts agreed that cybersecurity investment has become nearly as necessary as spending on physical infrastructure (New Hope Free Press, 2026).
But they told lawmakers those dollars come out of ratepayers’ pockets, and asked that any new regulations or requirements take that into account (New Hope Free Press, 2026).
Craig Fahnestock, the Pennsylvania Municipal Authorities Association’s director of government relations, put the tradeoff bluntly: “These investments are necessary, but cybersecurity now competes for the same limited resources needed for pipes, pumps and capital improvements” (New Hope Free Press, 2026).
“We’re asking for requirements that are achievable,” he said (New Hope Free Press, 2026). His group represents nearly 700 municipal water authorities, many of them on the smaller side (New Hope Free Press, 2026).
Why small systems are the hard case
The pressure is not new. In recent years, criminal and state-sponsored actors have increasingly targeted critical infrastructure across America and Europe, according to the account given to lawmakers (New Hope Free Press, 2026).
As utilities and grid infrastructure rely more on internet connections to function, the tools available to attackers have grown more sophisticated (New Hope Free Press, 2026).
The testimony echoes other recent utility cyber incidents, including the Stadtwerke Landsberg cyberattack that knocked city phones offline.
What a small water authority with few staff can realistically afford is the question the panel did not resolve. The article by Ian Karbal of the Pennsylvania Capital-Star, published by New Hope Free Press, describes no bill, no vote and no deadline (New Hope Free Press, 2026).
“By Ian Karbal | Pennsylvania Capital-Star In the past year, FirstEnergy Pennsylvania has seen a growing number of attempted malware and cyberattacks around their critical infrastructure.”
New Hope Free Press — Read the full report →
What’s Disputed or Unconfirmed
The attack-volume figure — tens of thousands of blocked connection attempts per month — is FirstEnergy’s own number, presented by its own security chief. No independent regulator or third party has verified it in this account (New Hope Free Press, 2026).
No confirmed breach, outage, or affected customer was described. The testimony concerns blocked and attempted intrusions, not successful ones (New Hope Free Press, 2026).
The statement that criminal and state-sponsored actors are behind the targeting is a general characterization of the threat landscape, not tied in this account to a named group, a specific incident, or an open investigation (New Hope Free Press, 2026).
The cost warning comes from parties with a direct stake: a utility and an association representing municipal water authorities that would bear new requirements. Their position is one side of a funding debate, not an adjudicated finding (New Hope Free Press, 2026).
Black Excellence This Week
The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:
- ‘I made those!’: 11-year-old designer Brooke Sumpter makes history with American Girl collaboration
thegrio.com · 2026-09-10 - 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
blackenterprise.com · 2026-09-10 - By Us Beauty: The Best Black-Owned Beauty Launches From August 2026
essence.com · 2026-09-09 - HBCUs Are Building New Support Systems for Black Male Students
capitalbnews.org · 2026-09-08
What You Can Do This Week
Not just bad news — here is where to push.
- Contact your U.S. senators to demand federal cybersecurity funding for water and power utilities after the Pennsylvania attacks. — Find your U.S. senators
- Attend your city council meeting and ask whether your municipal water utility has completed a CISA cyber assessment. — Attend your city council meeting (USA.gov local officials)
- Report suspicious network activity or breaches targeting your local power or water utility to federal authorities. — CISA: report a cyber incident
Kemetic Minds Analysis
Today’s verified reporting covered: Power Supply. Every claim above traces back to a specific, dated, fetched source — treat the Key Takeaways as the verified factual floor, and the ‘What’s Disputed or Unconfirmed’ section as the honest boundary of what today’s sourcing actually supports versus what’s still allegation or one-sided claim. The two checklists below are static, agency-sourced preparedness guidance (FEMA/Ready.gov/CDC/USDA) and are not tied to today’s specific stories.
🛡️ Free Preparedness Guides
Two free, printable checklists you can download and keep on hand — one for water-supply disruptions, one for power outages.
📄 Get this checklist as a free, printable PDF you can keep on hand.
⬇️ Download the Water Supply Checklist (PDF)📄 Get this checklist as a free, printable PDF you can keep on hand.
⬇️ Download the Power Outage Checklist (PDF)SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →References
- New Hope Free Press. (2026, September 10). Cyberattacks On PA Power & Water Utilities Prompt Call For Action. newhopefreepress.com
Investigative Methodology: This roundup is generated once daily at 5:00 PM America/Chicago from live news sources published within the prior 24 hours. Every claim is grounded in fetched source text with an APA7 in-text citation; nothing is written from the model’s general knowledge. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint, published within the last 24 hours, and restricted to a credible-outlet allowlist before publication — none are written by the drafting model. Pull-quotes are extracted verbatim from the cited article, never composed. The preparedness checklists are static guidance sourced from FEMA/Ready.gov, the CDC, and the USDA, never generated by the drafting model, and are not medical, legal, or emergency-response advice.
Stay Connected

