Crime & Safety
NJ Water Utilities Hit By Cyberattacks Affecting Multiple States, Officials Say
Water utilities in 12 states have been targeted but water safety has not been compromised, authorities say.
Two municipal water utilities in New Jersey have been the target of cyberattacks in recent days, state officials said.
New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) responded to two cyber incidents affecting New Jersey municipal water systems this past week. The NJCCIC is working directly with the affected utilities alongside our federal partners at the FBI and the Cybersecurity and Infrastructure Security Agency.
The incidents involved vulnerable internet-exposed control systems, which temporarily limited operators' ability to monitor or manage them remotely, said Christopher M. Thoreson, a spokesman for the New Jersey Cybersecurity and Communications Integration Cell.
Find out what's happening in Across New Jerseyfor free with the latest updates from Patch.
He did not identify the affected systems or give exact dates on when the cyber attacks happened.
Thoreson said the staff at both utilities shifted quickly to manual operations, and service was not disrupted.
Find out what's happening in Across New Jerseyfor free with the latest updates from Patch.
"Customers had uninterrupted access to safe drinking water throughout," he said.
Access at both utilities has since been strengthened, Thoreson said.
"The NJCCIC continues working with these utilities and with water systems statewide to reduce the risk of similar incidents going forward," he said.
The attacks are among several that have happened across the United States and that are believed to be the work of Iranian hackers, and have happened in at least 12 states, ABC News reported.
The first attacks were reported in Minnesota and affected at least 30 water utilities in that state, CBS News reported.
The FBI on July 30 said it is investigating incidents in at least seven states.
"After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality," the FBI said.
The perpetrator of the attacks has not been pinpointed but several reports, including the CBS report, said federal authorities are probing a possible connection to Iran, citing unnamed sources.
The federal Cybersecurity and Infrastructure Security Agency issued a warning on July 30 to water and wastewater systems operators to take actions to protect their systems, particularly the programmable logic controllers that are being targeted.
"CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," the warning said. "Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations."
The warning noted the hackers are "targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans."
The New Jersey water utilities affected shifted to manual operations, the 6ABC report said. There were no service disruptions and the systems have had their systems secured with stronger access controls, the report said.
Neither affected system in New Jersey has been identified.
How hackers are gaining access
The New Jersey Cybersecurity and Communications Integration Cell said water systems are not the only targets and said activity they have seen is directed at "critical infrastructure and public sector organizations, including local municipalities, school districts, and police departments."
"Threat actors send phishing emails with links intended to capture account credentials and compromise accounts, and then send additional phishing emails from legitimate accounts to avoid suspicion and keep their campaigns alive," the NJCCIC said. "They lure with shared documents for review, such as payroll or event calendars for department meetings; encrypted or secure messages; payroll processing errors; invitations for upcoming celebrations or events; past-due invoices for services; project proposals; expiring compliance training; and an updated benefits package."
"All users and organizations are highly recommended to practice good cyber hygiene, remain vigilant, and protect information," the state said.
Get more local news delivered straight to your inbox. Sign up for free Patch newsletters and alerts.