Water Sector Attacks Spread as More States Confirmed
New Jersey and Alabama join at least 12 states confirmed or linked to water system cyberattacks.

The cyber campaign against water utilities that began in late July continues to widen, with New Jersey and Alabama now confirming that systems in their states were targeted. The attacks, which have affected water and wastewater facilities across the country, have so far caused limited disruption, but the scope of the campaign is still unfolding.
Newest Confirmed Targets
In New Jersey, the Cape May and Woodbine water systems were hit on July 27, according to Fox29. Officials said only phone systems were disrupted, and no water services were impacted.
Alabama's Childersburg Water, Sewer and Gas system was attacked the same day, as reported by WVTM13. Hackers targeted industrial control systems (ICS), but the attack did not disrupt water services.
These two states join a growing list of confirmed targets. Minnesota was the first to confirm that over 30 water systems had their operational technology (OT) systems targeted. Michigan, South Dakota, and Georgia later also confirmed being targeted.
Limited Impact So Far
None of the water utilities or states that have come forward have reported significant impact. Some shut down systems, but disruptions were limited. Officials have consistently informed citizens that drinking water is safe.
Despite the lack of major damage, the campaign has raised concerns across the sector. Wisconsin, Pennsylvania, and Washington have issued warnings to water utilities but have not confirmed attacks. New York has not said whether its water utilities have been affected, but officials have announced more than $9 million in grants to help the sector boost its cybersecurity.
Federal Response
The FBI publicly confirmed that at least seven states had been targeted as of July 30, but neither the agency nor other government organizations have officially shared any updates. CISA has urged the water sector to secure OT in light of the campaign.
The attacks have been linked to Iranian hackers, and have targeted ICS devices made by Rockwell Automation and possibly other major vendors.
Quantified Impact
- At least 12 states have reportedly been hit, but not all have been identified.
- Minnesota confirmed over 30 water systems had OT systems targeted.
- New Jersey's Cape May and Woodbine systems were targeted on July 27.
- Alabama's Childersburg Water, Sewer and Gas system was attacked on the same day.
- New York announced more than $9 million in grants for cybersecurity.
- The FBI confirmed at least seven states targeted as of July 30.
Why It Matters
The expanding list of states underscores the breadth of this campaign, even if the immediate impact has been limited. The targeting of ICS and OT systems suggests that water utilities face a persistent threat that requires ongoing vigilance and investment in cybersecurity.
Sources
- SecurityWeek Original source
Continue Reading
Ceva Breach Reverberates Through Client Ecosystem
A Ceva Logistics data breach affecting European clients shows how supply chain attacks ripple outward.
Storm-1175 Debuts New Ransomware
Microsoft says China-linked Storm-1175 shifts from Medusa to the new StormEncryptor ransomware, likely via N-central flaw CVE-2026-18577.
Former Medusa Affiliate Debuts New Ransomware
Microsoft tracks Storm-1175's shift to StormEncryptor, following exploitation of an N-central flaw.