Skip to content
Beveiligingsnieuws

Water Cyberattacks: New Jersey en Alabama

water cyberaanvallen

New Jersey and Alabama have joined a growing list of US states reporting that their water and wastewater facilities were targeted in water cyberattacks that began in late July. The campaign appears to focus on operational technology, aiming at the devices that help run treatment and distribution systems.

Multiple states have said their systems were affected, while others have issued warnings without confirming attacks. Even where intrusions were acknowledged, officials have repeatedly stated that drinking water remains safe and that impacts—when present—were limited.

How the campaign spread across states

According to public reporting, at least a dozen states have reportedly been hit, although not all have been identified publicly. Minnesota was among the first to confirm that more than 30 water systems had their operational technology (OT) targeted.

After Minnesota’s announcement, additional states followed with confirmations. Michigan, South Dakota, and Georgia later reported that their water systems were targeted as well. As the list expanded, New Jersey and Alabama became the latest states to add formal reports.

New Jersey: targeted water systems and limited disruption

In New Jersey, two water systems were reported as having been targeted on July 27: Cape May and Woodbine. Local reporting indicated that only phone systems were disrupted, suggesting that while an intrusion occurred, it did not translate into a larger operational outage of water services.

While technical details were not broadly shared, the public message from officials emphasized continuity of service and reassurance to residents.

Alabama: industrial control systems targeted, services continued

In Alabama, the Childersburg Water, Sewer and Gas system was reported attacked on the same day, July 27. Reporting described that hackers targeted industrial control systems (ICS), which are closely tied to how critical processes in water infrastructure are managed.

Despite targeting ICS components, officials indicated that the attack did not disrupt water services. As with New Jersey, the key takeaway presented to the public was that residents should expect safe drinking water.

No major public impact reported so far

Across the states that have come forward, there has been no indication—at least publicly—that the incidents caused significant harm to water quality or large-scale loss of service. Some utilities reportedly shut down certain systems as a precaution, but disruptions described so far appear narrow in scope.

Utilities and state officials have also communicated directly with customers, repeating a consistent point: drinking water is safe. That messaging has been central to how authorities have handled the public visibility of the incidents.

States issued warnings without confirming attacks

Not all activity has been publicly categorized as a confirmed intrusion. Wisconsin, Pennsylvania, and Washington have issued warnings to water utilities about potential threats, but they have not formally confirmed that their water systems were targeted.

In New York, officials have not publicly stated whether any water utilities were affected. At the same time, New York announced more than $9 million in grants intended to help strengthen cybersecurity capabilities within the sector.

Federal confirmation and the lack of shared updates

The FBI publicly confirmed that at least seven states had been targeted as of July 30. However, neither the FBI nor other government organizations have provided broad updates that would clarify the full scope of the campaign across all affected regions.

This limited information flow can make it difficult for the public—and even for operators—to compare incidents. It also highlights why utilities continue to emphasize vigilance and incident readiness rather than relying on publicly visible outcomes alone.

Threat actor links and the focus on OT devices

Public reporting connects the campaign to Iranian hackers. The attacks have targeted ICS devices made by Rockwell Automation, and they may also involve other major vendors, indicating a broader effort to reach critical operational components.

Because OT environments differ from traditional IT networks—often relying on specialized equipment and long-lived systems—the same security assumptions do not always hold. That is part of why authorities have urged the water sector to strengthen defenses around OT.

CISA urges OT security for water infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) has urged the water sector to secure OT in response to the campaign. The message is straightforward: operational technology can be a primary pathway to disrupt essential services, even when public impacts appear limited.

In practice, that means water operators need to focus on protective measures tailored to ICS environments, including segmentation, monitoring for unusual behavior, and ensuring that remote access pathways and control interfaces are appropriately secured.

What utilities can learn from these incidents

Even where impacts were reported as minimal, the presence of water cyberattacks targeting ICS devices demonstrates that risk remains. Utilities can take several practical steps based on the themes emphasized by public authorities.

  • Assume OT is in scope: Protect control systems, not just business IT networks.
  • Prepare for partial disruptions: Some incidents may affect communications or support systems without stopping production—plans should reflect that reality.
  • Strengthen monitoring: Detecting suspicious activity early can reduce response time and limit spread.
  • Use vendor-aware risk management: When attacks target specific device families, patching and configuration reviews matter.
  • Communicate with customers: Clear guidance about drinking-water safety helps prevent confusion during incidents.

For local governments and operators, the combination of technical response and public messaging is becoming part of standard incident management in the water sector.

Conclusion: vigilance remains key

The confirmation of water cyberattacks in New Jersey and Alabama adds momentum to a broader picture affecting multiple states. While reported disruption has so far been limited and officials have emphasized drinking-water safety, the focus on operational technology and industrial control systems shows that these threats target the heart of critical infrastructure.

With federal updates still limited and warnings continuing across other states, the safest approach for utilities is proactive OT hardening and continuous monitoring—so that future incidents, even if detected early, do not translate into operational harm.

Source: https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/