At least two New Jersey water systems were hit in a cyberattack that struck utilities across a dozen states part of what officials call one of the broadest known attacks on U.S. water infrastructure.
WEBDESK – SAMAN NOOR – NJNEWSLINE
A Quiet Attack on Critical Infrastructure
At least two municipal water systems in New Jersey were reportedly targeted in a coordinated cyberattack that also struck utilities across roughly a dozen states. The New Jersey Office of Homeland Security and Preparedness has not publicly named the affected utilities, but confirmed that incidents over the past week temporarily disabled automated systems used to monitor and operate water infrastructure. Once the breach was detected, both utilities shifted to manual operations to keep service running without interruption.
How the Hackers Got In
According to a July 30 federal alert, several states experienced cyberattacks targeting the pumps, water pressure systems and valves that keep treatment plants running. Authorities say hackers remotely accessed internet-connected devices, changed IP addresses and passwords, and effectively locked utilities out of their own monitoring and control systems. It’s a chilling reminder of how much modern infrastructure now depends on internet connectivity and how exposed that connectivity can leave essential services.
No Contamination, But a Clear Warning Sign
Officials have stressed that no contamination of drinking water has been reported as a result of these attacks. Still, authorities say the incidents highlight just how vulnerable aging, internet-connected water systems have become. In response, officials are urging utilities statewide to disconnect unnecessary internet-facing systems and strengthen their cybersecurity defenses immediately.
A Possible Iran Connection With Pushback
Multiple news outlets have reported that some officials suspect the attacks may be part of a broader campaign linked to Iran. However, President Donald Trump has publicly stated he doesn’t believe there was an Iranian cyberattack, according to Politico leaving the question of attribution unresolved even as the investigation continues.
A Risk Officials Flagged Years Ago
This isn’t the first warning New Jersey has received about this exact vulnerability. Back in March 2023, the state’s Cybersecurity and Communications Integration Cell identified water and wastewater systems as critical infrastructure at increasing risk of cyberattacks, urging utilities to adopt stronger defenses like multifactor authentication, regular software updates, employee training and formal incident response planning. With more than 600 community water systems serving 9.5 million people across the state, the stakes for getting this right couldn’t be higher.
A Coordinated Response Now Underway
Both systems have since been secured with strengthened access controls, according to a spokesperson for the state’s homeland security office. The agency says it continues working directly with the affected utilities, as well as water systems statewide, to reduce the risk of similar incidents happening again. That effort now includes coordination with federal partners, including the FBI and the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, as the investigation moves forward.
A Bigger Pattern Emerging Nationally
Axios has noted that this recent wave of incidents could represent one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date suggesting New Jersey’s experience may be just one piece of a much larger, still-unfolding national security story.

