Hackers target two New Jersey municipal water systems in nationwide cyberattack
State officials said some analysts suspect Iranian hackers sought to disrupt U.S. infrastructure amid the war, according to a report.

Two New Jersey municipal water systems were targeted in a cyberattack that affected multiple local water agencies across the U.S. last week.
The FBI and the Environmental Protection Agency issued a public warning last Thursday to all critical infrastructure operators that hackers are targeting vulnerable internet-connected control systems responsible for delivering drinking water. At least seven states, including New Jersey, Georgia, Minnesota, Michigan, and Wisconsin, have reported cyber incidents to the FBI since July 27.
The two New Jersey municipal water systems targeted in the cyberattack have not been publicly disclosed.
“Both systems have since been secured with strengthened access controls,” said Christopher Thoresen, spokesperson for the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), part of the New Jersey Department of Homeland Security. “The NJCCIC continues working with these utilities and with water systems statewide to reduce the risk of similar incidents going forward.”
Three state officials who were briefed on the cyberattack investigation told the New York Times last week that the methods used to exploit the water systems and the lack of a ransom demand had led some analysts to “tentatively conclude” that the cyberattack could be traced back to Iran, amid the U.S.-Iran war. However, federal investigators have not publicly linked Iran to the cyberattacks.
Hackers accessed the water systems by exploiting small internet-connected devices, called programmable logic controllers (PLCs), that are used to remotely monitor and control aspects of industrial equipment, according to the NJCCIC.
In July’s attack, hackers targeted logic controllers in municipal water systems that control the pumps and valves used to deliver drinking water. After accessing these devices, hackers changed IP addresses and set new passwords, locking water agencies out of remote monitoring capabilities.
In New Jersey’s incidents, the municipal water agencies sent out staff to operate the systems manually, leading to no disruption to service or access to drinking water, according to the NJCCIC.
Cyberattacks were also reported in Minnesota, where 30 water-system facilities were targeted, and in Michigan, where nine were attacked. Similar to New Jersey, state officials said at no point during the attacks was drinking water unsafe.
To protect from future cyberattacks, the FBI is advising all critical infrastructure operators to remove direct internet connections from PLCs through secure firewalls, stronger passwords, and more secure authorized communication.
In July’s cyberattack, hackers exploited the MicroLogix 1100 and 1400 series of Rockwell Automation/Allen-Bradley PLCs, but the FBI warned that other branded devices can be vulnerable as well.

