Two New Jersey municipal water systems experienced cyberattacks that temporarily disabled automated controls; staff switched to manual operations and there were no service interruptions. The NJCCIC is coordinating the response with the FBI and CISA, and both systems have had access controls strengthened. Sources say Iran is the primary suspect, though investigators are also considering possible mimicry by another state actor. A software patch has been issued and utilities nationwide are auditing systems for compromise.
Two New Jersey Municipal Water Systems Targeted in Suspected Iran-Linked Cyberattacks

Two municipal water systems in New Jersey were targeted in cyberattacks last week, state officials said Wednesday. The affected utilities were not publicly named.
Automated control systems at both utilities were temporarily disabled, forcing staff to shift to manual operations while technicians worked to restore electronic control and monitoring. The state reported there was no interruption to service and customers continued to receive safe drinking water.
Response and Investigation
New Jersey's Cybersecurity and Communications Integration Cell (NJCCIC) said it responded to both incidents and is coordinating with the affected utilities and federal partners, including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA).
"The NJCCIC responded to two cyber incidents affecting New Jersey municipal water systems this past week," the state said, noting that both systems "have been secured with strengthened access controls."
Investigators determined the incidents involved vulnerable internet‑exposed control systems, which temporarily limited remote monitoring and management. In both cases, operators quickly moved to manual procedures to maintain safe service.
Attribution and Wider Context
Sources told ABC News that Iran is the prime suspect, though officials are also investigating whether another state actor might be mimicking Iran's tactics to influence U.S. actions. Similar intrusions exploiting a flaw in widely used utility software have been reported in at least a dozen states.
Georgia utilities such as the Clayton County Water Authority briefly issued a boil‑water advisory after a separate cyber incident, and Columbus Water Works also reported detecting an intrusion but said drinking water remained unaffected.
A patch for the exploited software has been released, and utilities nationwide that use the same products are racing to determine whether they were compromised. So far there are no confirmed illnesses or widespread interruptions to water supplies, and authorities continue to probe the full scope and potential impact of the attacks.
Help us improve.
























