New Jersey officials confirmed Wednesday that two municipal water systems were targeted in cyberattacks over the past week. The attacks temporarily blinded automated systems, but both utilities moved quickly to manual operations and customers continued receiving safe drinking water.
The New Jersey Cybersecurity and Communications Integration Cell responded to two incidents this week. Investigators found that vulnerable, internet-exposed control systems were the entry point. That exposure temporarily limited operators' ability to monitor or manage the systems remotely.
In both cases, staff shifted to manual operations and there was no disruption to service. The affected utilities were not named. The state said the systems have been "secured with strengthened access controls."
Sources told ABC News that Iran remains the prime suspect in the attacks. The timing has raised concern because of rising tensions with the United States. Officials are also assessing whether a different state actor could be mimicking Iran's tactics to influence U.S. decisions.
The New Jersey incidents are not isolated. Water and wastewater utilities in at least a dozen states have been targeted recently. The hacks exploited a vulnerability in widely used utility software, sources said. A fix has been issued, but utilities across the country are racing to check whether they were exposed.
In Georgia, the Clayton County Water Authority briefly issued a boil-water advisory after being targeted. Columbus Water Works said it detected an intrusion, but its drinking water was unaffected.
ABC7 San Francisco carried the national report, but no California water agency has been named among the victims. For California utilities, the incidents underscore the importance of patching internet-connected control systems and limiting remote access. No local health or water disruptions have been reported.
Cyberattacks on water systems have become a growing concern for federal and state agencies. The recent string of attacks appears to have used a known vulnerability in third-party utility software, triggering a nationwide review. Officials have stressed that so far, no one has become sick and there have been no widespread water supply disruptions.
Investigators are still working to determine the full scope of the New Jersey incidents and the broader hacking campaign. Utilities nationwide are urged to apply the software fix and restrict internet exposure of operational controls. The public should watch for official updates, but there is no immediate indication that water quality has been affected.