Two NJ Water Utilities Hit in Multi-State Cyberattack. Is Iran Really Behind It?

Green code on a dark screen, representing the cyberattack that hit water utilities in New Jersey and other states

Two NJ Water Utilities Hit in Multi-State Cyberattack. Is Iran Really Behind It?

Green code on a dark screen, representing the cyberattack that hit water utilities in New Jersey and other states

Staff

Recent cyber attacks on U.S. water infrastructure have reached New Jersey in a scene that makes Black Mirror feel less like fiction. 

Two New Jersey water utilities were caught up in a wave of cyberattacks this week that struck water and wastewater systems in at least seven states, with federal officials and multiple news outlets pointing to Iran as the likely source, according to a statement from the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC).

Neither affected New Jersey utility has been publicly identified. Both temporarily lost the ability to remotely monitor or manage their control systems after attackers exploited vulnerable, internet-exposed equipment, according to NJCCIC Chief Christopher Thoresen.

“In both cases, staff shifted quickly to manual operations, and there was no disruption to service,” Thoresen said in a statement. “Customers had uninterrupted access to safe drinking water throughout.” Both systems have since been secured with strengthened access controls, and the NJCCIC said it’s continuing to work with utilities statewide to reduce the risk of similar incidents.

A Wider Pattern

New Jersey wasn’t alone in this. Michigan, Minnesota, Georgia, and Wisconsin all got hit too, according to NBC10. Georgia actually saw it twice. The Clayton County Water Authority had to put out a brief boil-water notice after hackers got in, and Columbus Water Works found its own breach, though officials there insist the drinking water itself stayed clean.

The FBI and EPA put out a joint warning on July 30, flagging hackers going after internet-connected industrial control devices, the programmable logic controllers utilities use to run water and wastewater operations remotely. 6abc reported investigators traced it back to a software flaw used widely across the water sector. There’s a patch out now, but utilities everywhere are still combing through their own systems to check if they got hit too. That’s probably why the list of affected states keeps growing instead of settling.

Is Iran Responsible?

No one’s officially pointed the finger yet. Minnesota’s chief information security officer, John Israel, said investigators found “similarities” between the incidents but stopped short of confirming they’re all one connected attack. That said, NBC News, CNN, and The New York Times have all reported that federal and state sources believe Iran’s behind it, and a memo obtained by Wired reportedly ties earlier attacks in Minnesota to Iran-affiliated hackers.

Trump wasn’t buying it. He publicly waved off any Iranian involvement and instead blamed Minnesota’s state government, calling it incompetent. Minnesota Gov. Tim Walz shot back on social media, writing that the administration “knows exactly who is responsible for this attack,” and pointing to federal funding cuts at the Cybersecurity and Infrastructure Security Agency as a factor leaving water systems more exposed.

So far, no illnesses or widespread water disruptions have been reported in New Jersey or elsewhere. Federal officials are urging all water utilities to disconnect vulnerable control systems from the public internet and strengthen passwords and access controls to prevent further attacks.

It’s a stark reminder. In the digital era—where nearly everything around us connected to the internet in some way—even the most crucial systems aren’t completely safe from malicious actors.