Topic overview
In brief
- Two municipal water systems in New Jersey were targeted in cyberattacks last week.
- The attacks are believed to be linked to Iran, with investigations ongoing.
- Authorities confirmed that there was no disruption to service and that systems have been secured.
Summary
In the past week, two municipal water systems in New Jersey were subjected to cyberattacks, which are widely believed to be orchestrated by Iranian actors. The state authorities reported that the affected utilities, whose names have not been disclosed, experienced temporary disruptions in their automated systems, which led to a shift to manual operations. Fortunately, there was no interruption in service, and customers continued to have access to safe drinking water throughout the incidents. The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) responded promptly to these incidents, collaborating with federal partners, including the FBI and the Cybersecurity and Infrastructure Security Agency, to investigate the attacks. The investigations revealed that the cyber incidents exploited vulnerabilities in internet-exposed control systems, which limited the operators' ability to monitor and manage the systems remotely. Despite the challenges posed by the attacks, the utilities managed to secure their systems with strengthened access controls, ensuring that there was no disruption to service. The state officials indicated that while Iran is the prime suspect in these attacks, they are also considering the possibility that a different state actor may be mimicking Iran's tactics to influence U.S. actions. This incident is part of a broader trend, as water and wastewater utilities across at least a dozen states have faced similar cyber threats, exploiting vulnerabilities in widely used utility software. Although a fix has been issued, many utilities are currently assessing whether they have also been compromised. So far, there have been no reports of illness or widespread disruptions to water supplies, but officials are continuing to investigate the scope of the hacks and their potential implications for critical infrastructure.
