Iran suspected after cyberattacks hit two New Jersey water systems

By 
, August 5, 2026 
Category:

Hackers exploited a flaw in widely used utility software to breach two New Jersey municipal water systems in the past week, and federal investigators believe Iran is the prime suspect.

New Jersey announced Wednesday that its Cybersecurity and Communications Integration Cell, known as NJCCIC, responded to the two incidents alongside the FBI and the Cybersecurity and Infrastructure Security Agency. The attacks knocked out automated monitoring, forcing both utilities to switch to manual operations. No customers lost water service, and state officials said no one has reported getting sick.

But the breach extends well beyond New Jersey. Sources told ABC News that hackers exploited a vulnerability in a single piece of software used by water and wastewater systems nationwide, and that at least a dozen states have been affected by recent intrusions targeting those same systems. Utilities across the country are now scrambling to determine whether they, too, were compromised.

Operators lost remote control, and nobody told the public which towns were hit

The state of New Jersey laid out the basics in a public statement but withheld the names of the two affected municipalities. Officials said the hackers targeted "vulnerable internet-exposed control systems," temporarily stripping operators of the ability to monitor or manage water infrastructure remotely.

Staff at both utilities moved to manual operations quickly enough to avoid any service interruption. The state said both systems have since been "secured with strengthened access controls." A fix for the exploited software vulnerability has been issued, though officials did not say who issued it or when.

That leaves residents in at least two New Jersey communities without a clear answer about whether their local water system was among those breached, a gap that matters when the target is infrastructure people depend on every day.

Georgia utilities hit too, including one that issued a boil-water advisory

New Jersey was not the only state dealing with fallout. In Georgia, the Clayton County Water Authority briefly issued a boil-water advisory after being targeted by hackers. Columbus Water Works, also in Georgia, detected an intrusion but said its drinking water was unaffected.

Officials have not publicly confirmed whether the Georgia incidents and the New Jersey breaches stem from the same vulnerability or the same campaign. The scope of the hack remains under active investigation.

Iran is the prime suspect, but investigators haven't ruled out a copycat

Sources identified Iran as the leading suspect behind the attacks. The suspected motive: retaliation as President Trump threatens to escalate the ongoing conflict. Trump has said a new Iran deal is "imminent" and that more details would be announced within 48 hours, according to linked reporting referenced by ABC News.

Investigators are also assessing whether a different state actor may be responsible, one mimicking Iran's known tactics. That distinction matters. If a rival government is impersonating Iranian hackers to provoke a response, the strategic calculus changes significantly.

Either way, the attacks underscore a vulnerability that cybersecurity officials have warned about for years: small municipal water systems often run aging software with internet-exposed controls that make them easy marks for state-backed hackers.

A dozen states affected, and officials still mapping the damage

The full picture is still forming. At least a dozen states have seen recent hacks targeting water and wastewater utilities, and officials are still working to understand the total scope. The fact that a single software vulnerability opened the door to breaches across that many states points to a systemic weakness, not a one-off failure in New Jersey.

So far, no widespread disruptions to water supplies have been reported, and no illnesses have been linked to the attacks. Those are the reassuring numbers. The less reassuring ones: investigators do not yet know how many utilities were compromised, how long the hackers had access, or what they may have been able to do inside those systems before anyone noticed.

Foreign adversaries do not probe American water systems for sport. When a hostile government, whether Iran or someone wearing Iran's fingerprints, can reach into the control systems that keep drinking water safe, the country has a problem that manual overrides and after-the-fact patches will not solve.

About Ken Jacobs

STAY UPDATED

Subscribe to our newsletter and receive exclusive content directly in your inbox