Drooid Logo
Back to story perspectives

Full Breakdown

Nationwide Water Utility Cyberattacks Highlight Infrastructure Vulnerabilities

8/7/2026, 11:39:07 PM

Coordinated Intrusions Disrupt Municipal Water Systems

In late July, cyber intrusions struck municipal water and wastewater utilities across the United States. On July 27, two New Jersey water systems—Cape May City Water and Sewer Department and the Borough of Woodbine Water Department—were forced to switch to manual operation after attackers gained remote access to their control networks. The same week, dozens of small-town water facilities in Minnesota, including Braham, experienced service interruptions when hackers breached the computers that regulate treatment processes. Federal agencies later confirmed that at least a dozen states faced similar incidents, with the FBI reporting 30 attempted attacks in seven states.

Growing Digital Exposure of Legacy Infrastructure

Decades-old water infrastructure has increasingly been retrofitted with internet-connected programmable logic controllers (PLCs). The pandemic accelerated remote-monitoring deployments, but many utilities lack dedicated IT staff or funding for robust security. PLCs originally intended for isolated, on-site access are now exposed on public webpages, sometimes without passwords or firewalls.

Scope of the Threat

  • 12 states reported cyber incidents affecting water systems as of July 30, 2026.
  • The FBI identified 30 attempted intrusions across seven states.
  • The United States operates roughly 151,000 water facilities; only about 420 participate in voluntary cybersecurity information sharing.
  • 97 percent of water systems are small, locally run utilities with limited security resources.

Official Statements & Responses

— “The investigations found that the incidents involved vulnerable Internet-exposed control systems, which temporarily limited operators' ability to monitor or manage them remotely,” — Christopher Thoresen, NJCCIC spokesman

— “We are taking every effort to protect and defend our water supply and production. We supply water to the City of Cape May, West Cape May, Lower Township, Cape May Point, and the United States’ only Coast Guard Training Center located in Cape May City,” — Cape May City Mayor

— Woodbine Mayor William Pikolycky: “Fortunately, Woodbine’s water system is constructed in such a way that any outside attempts at gaining access to the system are caught immediately and resolved just as quickly.”

Federal officials, including CISA and the FBI, have urged utilities to disconnect critical controls from the public internet where possible and to adopt manual fallback procedures.

Conflicting Reports & Gaps

Attribution remains unsettled. Multiple sources cite Iranian-aligned hackers as the prime suspect, yet the FBI has not formally assigned blame. — “As a scholar who researches cyber conflict, I find that the methods used in these incidents are typical of international cyberattacks. Initial suspicion has fallen on hackers allegedly aligned with Iran, but the U.S. government has yet to attribute the attack to anyone,” — William Akoto, American University.

What’s Next

State and federal agencies are working with affected utilities to harden network defenses, including deploying a software patch that addresses the exploited vulnerability. The NJCCIC has pledged continued collaboration with water operators statewide, while CISA and the EPA continue to issue guidance on securing PLCs. Utilities are also being encouraged to adopt “air-gap” strategies—physically isolating critical control systems from internet access—to reduce the attack surface.

These incidents underscore the urgent need for coordinated investment in cybersecurity across America’s aging water infrastructure, especially for the small municipalities that supply the majority of the nation’s drinking water.