Skip to content

Woodbine Water System Communications Cyber Incident

Summary

Woodbine Municipal Utilities Authority logo

A July 27, 2026, cyber intrusion disrupted phone communications with Woodbine, New Jersey’s municipal water system and required employees to reactivate and operate the system manually. Officials said water service continued, drinking water remained safe, no customer data was compromised and the system returned online without further issues.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • No known data impact

    Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that malicious cyber activity disrupted communications with the municipal water system in Woodbine, New Jersey, on July 27, 2026. Woodbine Mayor William Pikolycky said in NBC10 Philadelphia’s reporting that outside attempts to access the system were detected and that the attackers succeeded in interrupting phone communications with the water system. Employees manually reactivated the system while consulting a contractor, CISA, the Department of Homeland Security and the FBI.

The public evidence confirms a cyber intrusion and operational disruption, but it does not establish the initial access vector or specific technical mechanism. Although the incident occurred amid a broader series of attacks involving internet-connected industrial control devices at U.S. water utilities, the available Woodbine-specific reporting does not establish that a particular programmable logic controller, vulnerability or remote-access product was compromised.

Operational significance

The incident affected an operational communications channel and forced a manual workaround at a public water utility. FOX 29 reported that the Woodbine and Cape May systems were affected for approximately 12 hours and that Woodbine’s phone system was the only identified disrupted system. The interruption required staff to work outside normal remote communications procedures, but it did not stop water delivery.

Officials said water treatment, supply and monitoring continued safely, drinking-water quality was not affected and residents did not need to take action. They also said no personal information or customer data was accessed or compromised. Those statements materially limit the documented impact: the incident disrupted utility operations and communications, but the public record does not establish loss of water service, unsafe water, altered treatment settings or public exposure to an operational hazard.

Disclosure posture

Woodbine publicly identified the incident on August 6 alongside a separate cyber incident affecting Cape May’s water department. DysruptionHub’s published report distinguishes Woodbine’s narrower communications outage and manual response from Cape May’s broader computer-network disruption.

Woodbine’s municipal code says Ordinance 559-2016 dissolved the Woodbine Utilities Authority and transferred its powers and duties to the Borough’s Municipal Utilities Department. The borough’s current water page nevertheless continues to use the legacy Woodbine Municipal Utilities Authority name for contact information and water-quality reports. The affected service is therefore best understood as the borough-operated municipal water utility, despite the legacy authority label still present on the public webpage.

Current status

The mayor said the system returned online with no further issues once information gathering was complete. Our reporting, citing the Press of Atlantic City, said the incident was resolved by July 29. DysruptionHub therefore assesses the operational disruption as resolved, supported by a positive restoration statement rather than elapsed time alone.

Confidence and uncertainty

Confidence is high that cyber activity caused the communications disruption because the mayor described an outside access attempt and successful interruption, and multiple local outlets reported the same official account. Confidence is high that drinking-water service and safety were unaffected because officials said treatment, supply and monitoring remained safe and water continued running.

The incident is assessed as not ransomware with medium confidence. No reviewed source identifies encryption, a ransom demand, data theft, a leak threat or another extortion indicator, but officials have not published a technical incident report describing the attack tooling. Threat-actor attribution remains unresolved because no actor has been publicly named or confirmed.

Analytic gaps

The public record does not identify the initial access vector, exploited vulnerability, compromised device or account, malware or tooling, actor, motive, dwell time, or whether the same infrastructure was involved in the nearly simultaneous Cape May incident. It also does not provide a technical explanation of the communications architecture, the exact manual operating steps, forensic indicators, or a final investigative report from the borough, NJCCIC, CISA, the FBI or another responding agency.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Low

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The campaign now includes 15 named incidents; Michigan has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA, supporting a possible shared-provider exposure. That pattern does not prove UIS itself was compromised or establish common attribution, and the complete victim list remains unknown.

Why this incident is included

Woodbine experienced malicious access early July 27 that interrupted phone communications with its water system and required manual reactivation, nearly simultaneous with Cape May. No public source identifies a PLC, remote-monitoring or control loss, configuration change, shared infrastructure or actor, and officials described the phone system as the only disrupted system.

Organizations involved

Impacted location

  • Woodbine, New Jersey

    The affected municipal water system operates in the Borough of Woodbine, Cape May County, New Jersey.

Sources

Cyber incident disrupts Woodbine, New Jersey, water system communications

DysruptionHub reported that a late-July cyber incident disrupted communications with Woodbine’s municipal water system, forced manual reactivation and operations, and was resolved by July 29. Officials said water service and drinking-water safety were unaffected and no personal or customer data was compromised.

Cyberattack targets 2 water systems in Cape May County, NJ, officials say

NBC10 quoted Woodbine Mayor William Pikolycky saying outside access attempts were detected, attackers interrupted phone communications with the water system, employees manually reactivated the system, and the system returned online with no further issues. Officials said water treatment, supply and monitoring remained safe and no customer data was compromised.

Cape May, Woodbine report water-system cyberattacks similar to those in other states

The Press of Atlantic City reported on the Woodbine and Cape May water-system cyber incidents; DysruptionHub cited this report for the July 27 occurrence and July 29 resolution dates.

Cape May, Woodbine water systems hit by cyberattack; officials say drinking water safe

FOX 29 reported that the Woodbine and Cape May attacks occurred nearly simultaneously early July 27 and affected the systems for about 12 hours. Woodbine’s mayor said only the phone system was disrupted; water continued running, safety tests found no impact and customer data was not accessed.

Water Department

The Borough of Woodbine’s official Water Department page identifies the Woodbine Municipal Utilities Authority as the water utility contact and publishes WMUA water-quality reports and notices.

See something that needs correction?

Signed-in members can report an error, update, or missing source.