# New Jersey Utilities Strengthen Water Cybersecurity

On August 5, 2026, New Jersey reported cyber incidents affecting two unnamed municipal water systems. Operators switched to manual controls, maintained uninterrupted service, and strengthened access controls. Iran is a leading suspect, but attribution remains unconfirmed; officials are also assessing whether another state actor may have mimicked its tactics. The reported vulnerability in widely used utility software has a fix available, making patching and operational resilience relevant priorities for water utilities and their contractors.

- Water utilities and contractors using the affected software should prioritize applying the available fix, reviewing exposure, and checking continuity plans, as described in the signal.
- The incidents show the operational importance of manual-control capabilities and access-control measures for maintaining water service during cyber incidents.
- NJCCIC, FBI, and CISA are among the relevant government cybersecurity entities identified in the signals; water-sector contractors supporting utilities may find cybersecurity and continuity services directly relevant.

**Jurisdictions:** sled
**Industries:** Information Technology, Construction & Infrastructure
**Topics:** Cybersecurity
**Published:** October 03, 2026

### Government Entities
- New Jersey Cybersecurity and Communications Integration Cell (NJCCIC)
- Cybersecurity and Infrastructure Security Agency (CISA)
- Federal Bureau of Investigation (FBI)
- Clayton County Water Authority
- Columbus Water Works

### Sources
- [New Jersey water utilities targeted in cyberattacks widely believed linked to Iran - ABC11 Raleigh-Durham](https://abc11.com/post/new-jersey-water-utilities-targeted-cyberattacks-widely-believed-linked-iran/19629579) - ABC11 News