New Jersey, Alabama Join States Targeted in Water Cyberattacks

The US Water Sector Under Siege: Cyberattacks Hit at Least 12 States, Raising Concerns Over Public Safety

A growing number of states across the country are coming forward to confirm that their water and wastewater facilities have been targeted in a coordinated hacking campaign. At least 12 states have reportedly been affected, with New Jersey and Alabama joining the list just this week. The attacks, linked to Iranian hackers, have raised concerns over public safety and highlight the need for improved cybersecurity measures in the water sector.

The hacking campaign, which began in late July, has targeted industrial control systems (ICS) used by water utilities across the country. ICS devices made by Rockwell Automation are among those believed to be vulnerable, although other major vendors may also be affected. In some cases, hackers have successfully breached these systems, disrupting phone services and forcing utilities to shut down systems as a precautionary measure. However, in most instances, the attacks appear to have been unsuccessful, with no significant impact on water quality reported.

Minnesota was the first state to confirm that its water systems had been targeted, with over 30 facilities affected. Michigan, South Dakota, and Georgia soon followed suit, and now New Jersey and Alabama have joined the list. Wisconsin, Pennsylvania, and Washington have issued warnings to water utilities but have not confirmed attacks. Meanwhile, New York has announced a $9 million grant program to help boost cybersecurity in the sector.

The FBI publicly confirmed that at least seven states had been targeted as of July 30, although neither the agency nor other government organizations have provided any updates since then. The US Cybersecurity and Infrastructure Security Agency (CISA) has urged water utilities to secure their operational technology (OT) systems in light of the campaign.

While the attacks may not have resulted in significant disruptions to date, they serve as a stark reminder of the vulnerability of critical infrastructure to cyber threats. As the water sector continues to rely on increasingly interconnected and complex systems, it is essential that utilities prioritize cybersecurity measures to prevent such incidents from happening in the future.

In practical terms, this means that water utilities must take immediate action to secure their ICS devices and OT systems. This may involve conducting vulnerability assessments, implementing security patches, and developing incident response plans. Furthermore, it is crucial for state and local governments to work together with federal agencies to share intelligence and best practices in addressing these threats.

By taking a proactive approach to cybersecurity, the water sector can minimize its exposure to such attacks and ensure that public safety remains the top priority. As we continue to navigate the complex landscape of cyber threats, one thing is clear: the need for robust cybersecurity measures has never been more pressing.


Source: SecurityWeek — 2026-08-10