CAPE MAY, NJ — Two municipal water systems in Cape May County were targeted in a cyberattack in late July, joining a series of similar incidents affecting utility infrastructure across the United States.
The Scope of the Breach: Cape May and Woodbine
Officials confirmed that the City of Cape May Water and Sewer Department and the Borough of Woodbine Water Department were targeted on July 27, 2026. The intrusions, which occurred nearly simultaneously, prompted an immediate response from local, state, and federal agencies, including the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA).
According to local leadership, the impact of the attack was limited:
-
No Service Disruption: Water treatment, supply, and monitoring systems remained functional throughout the event.
-
Safe Drinking Water: Officials have confirmed that drinking water in both municipalities remained safe for public consumption.
-
No Data Compromise: There is no evidence that any personal information or customer data was accessed or stolen during the breach.
How the Incident Was Managed
When the unauthorized access was detected, staff at both utility departments quickly shifted to manual operations, effectively isolating the control systems from the attackers.
Why the Impact Was Minimized
Local mayors emphasized the resilience of their infrastructure:
-
Non-Automated Systems: Cape May Mayor Zachary Mullock noted that the non-automated nature of much of the municipal water infrastructure provided a layer of protection, preventing hackers from gaining full operational control.
-
Rapid Incident Response: Woodbine Mayor William Pikolycky reported that the borough’s system was designed to catch unauthorized access attempts quickly. While the hackers succeeded in disrupting internal phone communications, staff were able to troubleshoot and restore the system within hours.
A Nationwide Pattern of Cyber Threats
These New Jersey incidents are part of a broader, concerning trend of cyberattacks targeting water and wastewater utilities in over a dozen states.
Potential Origins and Ongoing Investigations
-
International Ties: While federal investigators have not made a formal, definitive attribution, initial suspicions have pointed toward state-sponsored actors, with some reports linking the tactics to Iranian-aligned groups. Officials are also investigating the possibility of “copycat” actors attempting to influence U.S. policy.
-
Security Upgrades: In response, utility providers across the country are racing to install software patches and implement “strengthened access controls” to protect internet-connected control systems from future exploitation.
Authorities continue to work with local utilities to bolster defenses. Residents are encouraged to monitor official municipal channels for any further updates, though officials reiterate that no further action is required from the public at this time.
Comment