Two municipal water systems in central and northern New Jersey were hit by a coordinated cyberattack during the first week of May. While the intrusion disrupted remote-access control systems, operators successfully maintained service through manual procedures.
The May breach of internet-exposed SCADA units
A coordinated cyberattack targeted two water utility control systems in New Jersey during the first week of May. The malicious activity occurred between a Thursday dawn and a Friday evening, specifically targeting the network-based control infrastructures of the utilities .
As reported by the source, the attackers specifically targeted internet-exposed supervisory control and data acquisition (SCADA) units.. These units are vital for allowing operators to remotely monitor tank levels, pump status, and valve positions. By disrupting these remote-access ports, the attackers temporarily degraded the ability of control rooms to query the status of critical equipment across several counties.
How manual valve adjustments prevented service drops
New Jersey municipal water departments successfully maintained service through the use of manual operational procedures. despite the digital disruption, no drop in service was reported by consumers, and all water deliverables remained within acceptable safety thresholds.
To keep water pressure and distribution unbroken, crews implemented a "line-of-sight workflow." This involved physically confirming pump operations, reading indicator panels on-site, and performing manual valve adjustments.. The Biden administration's infrastructure resilience agenda was exemplified by the successful mitigation of this digital threat, demonstrating that layered defenses and procedural redundancies can shield vital services even when digital systems falter.
The FBI and CISA probe into remote-access vulnerabilities
State investigators, working in partnership with the Federal Bureau of Investigation (FBI) and the U.S. Cybersecurity and Infrastructure Security Agency (CISA), are now probing the root cause of the intrusion. According to the report , early forensic outcomes suggest that the attackers exploited poorly configured remote-access protocols that were left open to the public internet.
The New Jersey Cybersecurity and Communications Integration Cell has responded with a new statewide security mandate to harden utility defenses.. These new requirements include:
- The enforcement of multi-factor authentication (MFA) for all remote access.
- Mandatory stricter segmentation of critical control networks to prevent lateral movement.
- New training initiatives to increase staff awareness of phishing vectors and anomalous network traffic.
The mystery of the unnamed New Jersey utilities
The identities of the specific water utilities involved remain confidential under state law. While the successful containment of the attack is a positive outcome, the lack of disclosure means residents in central and northern New Jersey do not know exactly which local providers were targeted.
The report indicates that several other details remain unverified, including the specific identity of the threat actors responsible for the coordinated attack. While investigators have pinpointed the technical vulnerability—poorly configured remote-access protocols—the full extent of the affected counties and the motivation behind the strike remain unknown.
Comments 0