Skip to content

New Jersey’s Hamilton Township water utility removes cyber threat

The utility said drinking-water quality was unaffected but did not explain what it removed or whether an intruder gained access.

New Jersey’s Hamilton Township water utility removes cyber threat
A Hamilton Township Municipal Utilities Authority sign outside Hamilton Township Town Hall in New Jersey. (Hamilton Township Municipal Utilities Authority via Facebook)
Published:

A New Jersey water utility said it detected and removed a threat from its system but described the activity as an unsuccessful cyberattack, leaving unclear whether an intruder gained access.

The Hamilton Township Municipal Utilities Authority disclosed the incident Aug. 7, saying staff had determined two days earlier that a cyberattack had likely been attempted “in recent days.”

The authority did not say whether its defenses blocked the activity before unauthorized access occurred or whether an intruder gained access but failed to disrupt operations. It also did not identify what it removed from the system or what was targeted.

Hamilton Township Municipal Utilities Authority community update dated Aug. 7, 2026, saying it isolated and removed a threat and that drinking-water quality was unaffected.
An Aug. 7, 2026, community update from the Hamilton Township Municipal Utilities Authority discusses its response to what it described as an unsuccessful cyberattack attempt. (Hamilton Township Municipal Utilities Authority)

Hamilton Township MUA said a July 29 Environmental Protection Agency briefing about cyber incidents affecting water utilities prompted the review. The authority reported the matter to the FBI, checked its water distribution system for similar activity and added security measures.

The authority said the incident did not affect drinking-water quality.

The FBI and EPA issued an alert July 30 about attackers remotely accessing internet-facing controllers at water and wastewater utilities in at least seven states. The agencies said some victims lost monitoring or control functions after attackers changed device addresses or passwords.

Later reporting placed the campaign in at least 12 states. An Aug. 18 CSIS analysis cited New York Times reporting that at least 100 facilities were targeted and said it had identified locations for 55 across nine states. DysruptionHub’s campaign file tracks 12 publicly named incidents with confirmed or possible links to the late-July attacks, including HTMUA, across five states.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

HTMUA did not say whether its incident involved a programmable logic controller or any of the methods described in the federal alert, leaving its connection to the broader campaign unconfirmed.

Two other New Jersey water systems reported cyber incidents around the same time. Cape May said parts of its computer network were disrupted without interrupting water service, while Woodbine used manual operations after communications with its water system failed.

HTMUA said it had contained the threat. The authority did not respond by publication time to questions about what it removed from the system and whether an intruder gained access.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all