New Jersey, Alabama Join States Targeted in Water Cyberattacks
Iranian hackers targeted water facilities in at least a dozen US states.
Summary
A cyberattack campaign, allegedly linked to Iranian hackers, has targeted industrial control systems (ICS) at water and wastewater facilities across at least a dozen US states since late July. While several states have confirmed attacks, including New Jersey and Alabama, the impact has been limited, with no reported disruptions to water services or safety concerns for drinking water. CISA has urged the water sector to enhance its operational technology (OT) security in response to these incidents.
Full text
New Jersey and Alabama have joined the list of US states that confirmed their water and wastewater facilities have been targeted in a hacking campaign that started in late July. At least 12 states have reportedly been hit, but not all have been identified. Minnesota was the first to confirm that over 30 water systems had their operational technology (OT) systems targeted. Michigan, South Dakota, and Georgia later also confirmed being targeted. The latest to join the list are New Jersey and Alabama. In New Jersey, Cape May and Woodbine water systems were targeted in cyberattacks on July 27, but officials said only phone systems were disrupted, according to Fox29. WVTM13 reported that the Childersburg Water, Sewer and Gas system in Alabama was attacked on the same day. Hackers targeted industrial control systems (ICS), but the attack did not disrupt water services. None of the water utilities or states that have come forward have reported significant impact — some shut down systems, but disruptions were limited — and they all informed citizens that drinking water is safe.Advertisement. Scroll to continue reading. Wisconsin, Pennsylvania, and Washington have issued warnings to water utilities but have not confirmed attacks. New York has not said whether its water utilities have been affected by the attacks, but officials have announced more than $9 million in grants to help the sector boost its cybersecurity. The FBI publicly confirmed that at least seven states had been targeted as of July 30, but neither the agency nor other government organizations have officially shared any updates. The attacks, linked to Iranian hackers, have targeted ICS devices made by Rockwell Automation and possibly other major vendors. CISA has urged the water sector to secure OT in light of the campaign. Related: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Truck Brake Controller’s Safety Recall Doubled as Hidden Security FixSnowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsMeta AI Hacked External Systems During Cybersecurity TestingHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 States Latest News Metabase Patches Vulnerability Exploited as Zero-DayNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilityCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityCorporate Data Stolen in Levi Strauss CyberattackCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetVishing Extortion Group UNC6671 Rebrands After Making Millions Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email