Menu
Browse

Cyber Incident Victim: New Jersey

Date

Jul 2026

Location

United States of America

Status

Resolved

Updated

2026-08-13 17:32

Timeline
Occurred
Undetermined
Discovered
Jul 2026
Disclosed
Aug 2026
Resolved
Jul 2026
Summary

A coordinated cyberattack targeted industrial control systems at water and wastewater facilities across several states, including New Jersey, leading to service disruptions and boil water advisories. Officials reported that at least seven states experienced similar outages, prompting local authorities to issue alerts, take manual control of pumps, and urge water conservation while backup supplies were used. The FBI confirmed the attacks, WaterISAC shared threat intelligence with its members, and the EPA held a webinar to discuss the cyber threat to the water sector.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

Between July 26 and July 28, 2026, a series of cyberattacks targeted the operating technology of water and wastewater facilities across the United States, beginning with incidents in Minnesota where a water tower in Plymouth and the Braham water plant experienced disruptions. In Braham, operators took the plant offline after detecting abnormal activity, urged the city’s approximately 1,700 residents to conserve water while they switched to a backup supply stored in a local tank, and restored service within a couple of hours by assuming manual control of the pumps. State officials soon learned that Braham was not isolated, as similar outages were reported in other Minnesota communities such as Maple Plain and in jurisdictions outside the state, including Clayton County near Atlanta where a boil water advisory was issued after a pump station failure, and in New Jersey and Michigan where comparable water system interruptions occurred. The attacks were described by cybersecurity experts and federal officials as a coordinated effort affecting industrial control systems nationwide, with suspicions pointing toward Iranian involvement based on prior activity and threat intelligence.

Cyber Incident Image

In response to the emerging crisis, local water authorities implemented immediate operational measures such as isolating affected systems from networks, deploying manual controls, and utilizing reserve water supplies to maintain service while investigations proceeded. WaterISAC, the sector’s information‑sharing organization, convened a call for its roughly 400 members to disseminate federal threat intelligence, and the EPA followed with a public webinar focused on urgent operational matters related to cyber threats to water infrastructure. The FBI confirmed that at least seven states had experienced comparable attacks on water and wastewater facilities and stated that its investigation remained ongoing. Throughout the incident, officials noted that the attackers had exploited low‑hanging vulnerabilities, including devices exposed to the open internet with unchanged default credentials, which allowed unauthorized access to operational technology. The disruptions prompted temporary public advisories, highlighted the reliance on backup supplies, and underscored the need for heightened situational awareness across the sector.

Beyond the immediate water sector impacts, experts expressed concern that the same tactics could threaten other critical infrastructure domains such as transportation and energy, referencing the potential for broader national‑scale effects. Statements from industry leaders emphasized that the equipment involved—often decades‑old operational technology—cannot be readily patched or replaced without taking facilities offline, which complicates defensive actions. The episode prompted discussions about the importance of timely information sharing among federal, private, and state‑local partners, and highlighted calls for increased resources to improve the cybersecurity posture of water utilities nationwide. While the investigation continued, the incident served as a stark reminder of the vulnerabilities inherent in internet‑connected industrial control systems and the real‑world consequences when those systems are compromised.

Sources
Sources available to members
1 source