Analyst assessment
DysruptionHub assesses with high confidence that malicious cyber activity disrupted an operational-technology communications capability at the City of Cape May Water and Sewer Department. A Press of Atlantic City timeline said the department received an alarm early July 27 showing that communications with its remote monitoring system had been lost. Staff moved the system to manual controls, and a controller vendor later determined that the communications loss resulted from a potential cyberattack and notified the city and the New Jersey Cybersecurity and Communications Integration Cell.
FOX 29’s report adds that City Manager Paul Dietrich initially described recognizing that some settings had changed, then clarified that the attackers prevented remote access but did not change operational settings or take control of the system. DysruptionHub assesses that this most likely distinguishes an access or communications change from process-control changes, but the public record does not technically resolve the wording or identify the affected device.
Although a federal campaign involved internet-facing programmable logic controllers, Cape May officials have not publicly identified a PLC model, confirmed internet exposure, described a password or device-address change, or attributed the incident to the actor or method behind other water-sector events.
Operational significance
The incident removed remote monitoring communications and required on-site staff to use manual controls for approximately 12 hours. It also made monitoring telemetry unavailable through the normal remote channel. This was a material disruption to the department’s operating capability, but it was not a public water-service outage. NBC10 Philadelphia reported that city officials said treatment, supply and monitoring continued safely and that the safety and quality of drinking water were unaffected.
Cape May’s system serves the city and neighboring communities, including West Cape May, Cape May Point and parts of Lower Township, as well as the U.S. Coast Guard training center. Continuity therefore mattered beyond the city’s municipal boundary, but the available evidence does not support a loss of water pressure, contamination event, boil-water advisory, desalination-plant shutdown or interruption to customers in any part of the service area.
Disclosure posture
The first identified public reporting appeared August 6, after the system had returned to normal operations. The city’s statements disclosed that the incident affected part of the water department’s computer network, described coordination with cybersecurity specialists and state agencies, and stated that no personal information or customer data was accessed or compromised. DysruptionHub’s published report subsequently synthesized the timeline and distinguished Cape May’s limited internal disruption from the more severe operational effects reported at some other utilities.
A July 30 FBI and EPA alert described attacks beginning July 27 against internet-facing PLCs at water and wastewater utilities in at least seven states. That alert is useful campaign context, but it did not identify Cape May and does not establish that the city’s incident involved the cited Rockwell controller models, the same technical changes or a common actor.
Current status
The Press timeline said state cybersecurity personnel conducted a full evaluation on July 28 and that the system returned to normal operations that afternoon. City officials later described the incident as contained, while the investigation and defensive work continued. DysruptionHub therefore assesses the material operational disruption as resolved, even though the public record does not provide a final forensic report.
Confidence and uncertainty
Confidence is high that a cyberattack disrupted remote monitoring access and forced a manual-control workaround because city officials and the local operational timeline described the event and response. Confidence is also high that drinking-water service, treatment and safety continued, and that officials found no compromise of personal or customer data.
Confidence is high that authorized staff temporarily lost remote access to monitoring data. The wider confidentiality and integrity impact remains unresolved because officials have not explained whether credentials, device configurations, project files or telemetry were viewed or changed.
Ransomware involvement and threat-actor attribution remain unresolved. No public source identifies encryption, a ransom demand, a leak-site claim or an actor. The timing and general operational pattern are insufficient to attribute Cape May to the broader multistate campaign.
Analytic gaps
The public record does not identify the affected controller or communications equipment, manufacturer, model, firmware, internet-exposure configuration, initial access vector, exploited vulnerability, compromised credentials, source infrastructure, precise access or communications change, persistence, malware, forensic indicators or full network scope. It also does not establish whether the incident was technically linked to the broader multistate campaign or the Woodbine incident, whether any operational data was viewed or altered, or which security changes were implemented after containment.