Skip to content

Cape May Water System Cyberattack

Summary

City of Cape May Water and Sewer Department logo

A July 27, 2026, cyberattack blocked remote access to the City of Cape May Water and Sewer Department’s monitoring system, requiring manual controls until normal operations resumed July 28. The city manager said attackers did not change operational settings or take control, and officials said water service, drinking-water safety and customer data were unaffected.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Remote access disruption

    VPN, remote desktop, telework, remote administration, or other remote-access capabilities were unavailable or restricted.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that malicious cyber activity disrupted an operational-technology communications capability at the City of Cape May Water and Sewer Department. A Press of Atlantic City timeline said the department received an alarm early July 27 showing that communications with its remote monitoring system had been lost. Staff moved the system to manual controls, and a controller vendor later determined that the communications loss resulted from a potential cyberattack and notified the city and the New Jersey Cybersecurity and Communications Integration Cell.

FOX 29’s report adds that City Manager Paul Dietrich initially described recognizing that some settings had changed, then clarified that the attackers prevented remote access but did not change operational settings or take control of the system. DysruptionHub assesses that this most likely distinguishes an access or communications change from process-control changes, but the public record does not technically resolve the wording or identify the affected device.

Although a federal campaign involved internet-facing programmable logic controllers, Cape May officials have not publicly identified a PLC model, confirmed internet exposure, described a password or device-address change, or attributed the incident to the actor or method behind other water-sector events.

Operational significance

The incident removed remote monitoring communications and required on-site staff to use manual controls for approximately 12 hours. It also made monitoring telemetry unavailable through the normal remote channel. This was a material disruption to the department’s operating capability, but it was not a public water-service outage. NBC10 Philadelphia reported that city officials said treatment, supply and monitoring continued safely and that the safety and quality of drinking water were unaffected.

Cape May’s system serves the city and neighboring communities, including West Cape May, Cape May Point and parts of Lower Township, as well as the U.S. Coast Guard training center. Continuity therefore mattered beyond the city’s municipal boundary, but the available evidence does not support a loss of water pressure, contamination event, boil-water advisory, desalination-plant shutdown or interruption to customers in any part of the service area.

Disclosure posture

The first identified public reporting appeared August 6, after the system had returned to normal operations. The city’s statements disclosed that the incident affected part of the water department’s computer network, described coordination with cybersecurity specialists and state agencies, and stated that no personal information or customer data was accessed or compromised. DysruptionHub’s published report subsequently synthesized the timeline and distinguished Cape May’s limited internal disruption from the more severe operational effects reported at some other utilities.

A July 30 FBI and EPA alert described attacks beginning July 27 against internet-facing PLCs at water and wastewater utilities in at least seven states. That alert is useful campaign context, but it did not identify Cape May and does not establish that the city’s incident involved the cited Rockwell controller models, the same technical changes or a common actor.

Current status

The Press timeline said state cybersecurity personnel conducted a full evaluation on July 28 and that the system returned to normal operations that afternoon. City officials later described the incident as contained, while the investigation and defensive work continued. DysruptionHub therefore assesses the material operational disruption as resolved, even though the public record does not provide a final forensic report.

Confidence and uncertainty

Confidence is high that a cyberattack disrupted remote monitoring access and forced a manual-control workaround because city officials and the local operational timeline described the event and response. Confidence is also high that drinking-water service, treatment and safety continued, and that officials found no compromise of personal or customer data.

Confidence is high that authorized staff temporarily lost remote access to monitoring data. The wider confidentiality and integrity impact remains unresolved because officials have not explained whether credentials, device configurations, project files or telemetry were viewed or changed.

Ransomware involvement and threat-actor attribution remain unresolved. No public source identifies encryption, a ransom demand, a leak-site claim or an actor. The timing and general operational pattern are insufficient to attribute Cape May to the broader multistate campaign.

Analytic gaps

The public record does not identify the affected controller or communications equipment, manufacturer, model, firmware, internet-exposure configuration, initial access vector, exploited vulnerability, compromised credentials, source infrastructure, precise access or communications change, persistence, malware, forensic indicators or full network scope. It also does not establish whether the incident was technically linked to the broader multistate campaign or the Woodbine incident, whether any operational data was viewed or altered, or which security changes were implemented after containment.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Low

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The campaign now includes 15 named incidents; Michigan has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA, supporting a possible shared-provider exposure. That pattern does not prove UIS itself was compromised or establish common attribution, and the complete victim list remains unknown.

Why this incident is included

Cape May lost remote water-monitoring communications early July 27 and used manual controls until July 28, matching the campaign’s timing and loss-of-monitoring pattern. Officials said attackers did not change operational settings or take control, and no public source identifies a PLC, shared technical method, infrastructure or actor or directly names Cape May as a campaign victim.

Organizations involved

Impacted location

  • Cape May, New Jersey

    The affected department and water-system operations are based in the City of Cape May; neighboring service areas experienced no reported interruption.

Sources

Cyberattack hits Cape May water system in New Jersey

DysruptionHub reported that the July 27 cyberattack disrupted part of Cape May’s municipal water-system computer network but did not interrupt service or affect drinking-water safety. It said the incident was resolved within days, customer data was not compromised, and no threat actor or specific attack method had been disclosed.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions

The FBI and EPA warned that water and wastewater utilities in at least seven states reported incidents beginning July 27 involving internet-facing PLCs. Attackers changed device addresses and passwords in some cases, causing loss of monitoring or control, but the alert did not identify Cape May or a threat actor.

Cape May, Woodbine water systems hit by cyberattack; officials say drinking water safe

FOX 29 reported that the Cape May and Woodbine systems were affected for approximately 12 hours. Cape May City Manager Paul Dietrich said the incident prevented remote access but did not change operational settings or allow attackers to take control. Water continued running, safety tests found no impact and customer data was not accessed.

Cape towns share timeline of water system cyberattack

The local timeline reported that Cape May lost communications to its remote water-monitoring system early July 27, changed to manual controls, and learned from its controller vendor that the loss was caused by a potential cyberattack. State cybersecurity personnel evaluated the system July 28, and normal operations resumed that afternoon.

Cyberattack targets 2 water systems in Cape May County, NJ, officials say

NBC10 reported that city officials confirmed a cybersecurity incident affecting part of the Cape May Water and Sewer Department’s computer network. Officials said drinking-water safety and quality were unaffected, treatment, supply and monitoring continued safely, and no personal information or customer data was accessed or compromised.

See something that needs correction?

Signed-in members can report an error, update, or missing source.