A cyberattack disrupted parts of Cape May’s municipal water system computer network in New Jersey in late July, but officials said drinking water remained safe and service continued without interruption.
The incident occurred July 27 and was resolved by July 29, The Press of Atlantic City reported, citing local officials. Cape May activated its incident response procedures and worked with cybersecurity specialists and state agencies to investigate and contain the intrusion.
NBC10 Philadelphia, citing city officials, reported that the attack did not affect the safety or quality of public drinking water. Water treatment, supply and monitoring systems continued to operate safely, and no personal information or customer data was accessed or compromised.
Cape May’s water system serves the city as well as West Cape May, Cape May Point, parts of Lower Township and the U.S. Coast Guard training center in Cape May. Another utility targeted in the recent wave, Columbus Water Works in Georgia, also provides water and wastewater services to a military installation, Fort Benning.
“We acted quickly to contain the incident and continued to work with cybersecurity experts to strengthen our systems while maintaining uninterrupted service to our community,” City Manager Paul Dietrich said in a statement reported by The Press of Atlantic City.
Mayor Zachary Mullock said the city was working with state and federal agencies to protect its water supply and desalination plant from further threats.
The Cape May incident came as utilities in several states dealt with similar cyber activity against water and wastewater systems. Federal officials warned July 30 of increased threats against internet-connected operational technology used by water utilities.
Those incidents included attackers changing passwords or otherwise interfering with remote access, in some cases forcing operators to switch to manual controls. Federal agencies urged utilities to remove vulnerable control equipment from direct internet exposure, strengthen authentication and restrict access.
A second Cape May County water system, in Woodbine, also reported an incident from the same period. The Press of Atlantic City and NBC10 Philadelphia reported that attackers interrupted phone communications with the system, forcing employees to reactivate equipment manually.
The Cape May incident was part of a broader wave of attacks that began around July 27. The FBI said water and wastewater utilities in at least seven states reported incidents, including more than 30 systems in Minnesota and systems in Michigan, Georgia, South Dakota and Alabama. Some operators were forced to switch to manual operations.
No threat actor has been publicly confirmed in the Cape May attack, and officials have not disclosed a specific malware strain or other attack method. The investigation remains ongoing.