New Jersey and Alabama have recently become the latest states to report that their water and wastewater treatment facilities have been targeted in an ongoing cyberattack campaign. This hacking effort, which began in late July, has now expanded to at least 12 states, though not all have publicly identified themselves.
Expansion of Cyber Threats
The cyberattacks initially came to light when Minnesota confirmed that over 30 of its water systems had their operational technology (OT) systems compromised. Following this, Michigan, South Dakota, and Georgia also acknowledged similar breaches. The recent addition of New Jersey and Alabama to this list underscores the growing scale of the threat.
In New Jersey, the cyberattacks focused on Cape May and Woodbine water systems, disrupting phone systems on July 27. According to reports from Fox29, these attacks did not extend beyond communication disruptions. Simultaneously, Alabama’s Childersburg Water, Sewer, and Gas system also faced an attack targeting its industrial control systems (ICS). Fortunately, this intrusion did not affect water services, as reported by WVTM13.
State Responses and Public Safety
While these cyberattacks have been concerning, none of the affected states have reported significant operational impacts on their water utilities. Some facilities opted to shut down systems temporarily, but disruptions remained minimal. Officials have consistently reassured residents that their drinking water remains safe.
Other states, including Wisconsin, Pennsylvania, and Washington, have issued advisories to their water facilities to remain vigilant, although they have not confirmed any direct attacks. New York, while not confirming any incidents, has proactively allocated more than $9 million in cybersecurity grants to bolster the sector’s defenses.
Federal Involvement and Security Recommendations
The Federal Bureau of Investigation (FBI) publicly acknowledged that by July 30, at least seven states had fallen victim to these cyber threats. Despite this, there have been no further updates from federal agencies on the developments.
The attacks have been attributed to Iranian hackers, who have specifically targeted ICS devices manufactured by companies like Rockwell Automation. In response, the Cybersecurity and Infrastructure Security Agency (CISA) has strongly advised water utilities to enhance their security measures for operational technologies.
As these cyberattacks continue to unfold, the emphasis on improving industrial cybersecurity remains paramount. Both states and federal agencies are working to ensure that essential services like water remain protected from digital threats.
