Overview
- Two municipal water departments in Cape May County were breached on July 27th, causing about 12 hours of lost remote monitoring and communications but never interrupting water service.
- In Cape May attackers changed the water department computer’s IP address which temporarily locked out officials, and Woodbine lost phone and remote monitoring access before staff reactivated systems manually.
- Routine water testing after the incidents found no impact on treatment or supply and officials say no customer personal data was accessed.
- The New Jersey Cybersecurity and Communications Integration Cell is working with the FBI and CISA on the investigation and both towns have tightened access controls and secured affected systems.
- The intrusions match a broader wave of attacks that exploit internet-facing control devices at small water utilities and prior federal advisories have linked similar tactics to Iranian-affiliated actors though attribution for these specific breaches remains unresolved.