Two New Jersey Municipal Water Systems Targeted in Cyberattacks as Federal Investigation Expands
Two New Jersey municipal water systems were targeted in cyber incidents during the week ending Aug. 5, according to state officials, as federal investigators examine a broader campaign involving water utilities in multiple states.
The New Jersey Cybersecurity and Communications Integration Cell, or NJCCIC, responded to the incidents and is working with the affected utilities, the FBI and the Cybersecurity and Infrastructure Security Agency. The names of the two systems have not been publicly identified, and officials have not disclosed whether the incidents affected operations.
The developments place New Jersey water infrastructure inside a wider investigation involving attacks or attempted intrusions reported in at least 12 states. The incidents involve operational technology, the computer systems and industrial controls used to monitor or manage water infrastructure.
What is known about the New Jersey incidents
The available information does not establish that New Jersey drinking water was contaminated or unsafe. It also does not establish that water service was interrupted anywhere in the state. An impacted water system does not necessarily mean that customers lost service or that the quality of water changed.
Officials have not disclosed the extent of any effect on the two systems’ operational technology, system integrity or sensitive infrastructure. They have also not identified the attackers. Investigators reportedly suspect that Iranian-affiliated hackers may be involved in the broader activity, but that remains an investigative suspicion rather than a final attribution.
That distinction matters because a cyber incident can involve an attempted intrusion, unauthorized access or manipulation of a control system without producing a confirmed outage or contamination event. The public record available for the New Jersey incidents does not specify which of those conditions occurred.
Federal warnings and state requirements
On April 7, the U.S. Environmental Protection Agency, FBI, CISA and National Security Agency issued a joint cybersecurity advisory about Iranian-affiliated cyberattacks against water systems. The advisory provided steps utilities could use to identify exploited vulnerabilities and strengthen their cyber resilience.
The federal warning focused on operational technology and internet-exposed industrial controls, which can create a pathway into systems used to monitor or control infrastructure. Water utilities depend on those systems for parts of their daily operations, making cybersecurity a direct public-service concern even when no customer-facing disruption has been confirmed.
New Jersey’s existing Water Quality Accountability Act requirements also establish a reporting process for qualifying cybersecurity incidents. A water purveyor whose industrial-control system experiences a covered incident must report it to NJCCIC within 30 days.
The requirements cover incidents involving adverse effects, disabling or manipulation of infrastructure, loss of service, contamination or infrastructure damage. Applicable purveyors must also maintain cybersecurity programs and reporting processes.
Investigation continues
The broader activity was reported after multiple states disclosed attacks or attempted intrusions against water systems. The FBI, CISA and other agencies are investigating the incidents, according to reporting by the Associated Press.
For New Jersey residents, the immediate confirmed development is the state’s response to two affected municipal systems, not a statewide compromise. There is no information in the approved reporting showing that all New Jersey water systems were targeted or that the incidents caused a general interruption of water service.
NJCCIC and its federal partners are expected to continue incident response and investigation. That work may determine how the systems were accessed, whether operational technology was affected and whether additional protective measures are needed. Until officials release more information, the names of the utilities, the scope of any system impact and the identity of the attackers remain unresolved.
Sources
- Water Quality Accountability Act, New Jersey Department of Environmental Protection
- EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks, U.S. Environmental Protection Agency
- FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems, Associated Press
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.