The water systems in Cape May and Woodbine were targeted in a cybersecurity incident late last month that temporarily prevented officials from remotely monitoring the systems but did not affect water supply or treatment operations, according to Cape May City Manager and City Engineer Paul Dietrich.

In Woodbine, communications with the borough’s remote monitoring system were lost around 12:15 a.m. Monday, July 27, according to an Aug. 6 press release issued by the two municipalities.

Environmental & Technical Services, LLC (ETS) arrived about 45 minutes later and manually operated the water system while investigating the loss of communication. The system remained under manual operation as ETS and the borough’s controller vendor worked to troubleshoot the issue.

By the early morning hours of Wednesday, July 29, the vendor advised the ETS Licensed Operator that the communication failure may have been related to a potential cybersecurity incident. By 11 a.m., ETS and the vendor had completed corrective actions and restored control of the borough’s SCADA system, allowing the water system to return to automatic operation.

By 11 a.m. Wednesday, ETS and the borough’s controller vendor had completed the necessary corrective actions and successfully regained control of the borough’s SCADA system. The water system was subsequently returned to automatic operation.

“Fortunately, Woodbine’s water system is constructed in such a way that any outside attempts at gaining access to the system are caught immediately and resolved just as quickly,” said Borough of Woodbine Mayor William Pikolycky in the municipalities’ joint press release. “Bad actors were only successful in interrupting our phone communication to the water system. This resulted in a few bad hours for the Borough of Woodbine Water Department personnel as they reactivated the system manually and consulted with the contractor, CISA, Homeland Security and the FBI. Once the information gathering was complete, the system was back online with no further issues.”

In Cape May, the incident began around 1:30 a.m., when the city’s water system alerted staff that communications had been lost. City employees arrived around 2:30 a.m. and initially investigated whether the problem was related to a more routine issue, such as a power outage or loss of network connectivity, Dietrich told Shore Local.

After staff could not identify an obvious problem, they began troubleshooting and took the system off remote monitoring so they could maintain direct control of it. Dietrich said the water system continued operating while employees worked to determine what had happened.

The city’s controller vendor arrived around 8 a.m. and conducted a more detailed examination. By later that morning, officials determined that the communications problem was the result of a cyberattack.

Dietrich said the determination was based in part on unauthorized changes to passwords and IP addresses within the system.

The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) was notified later that day and arrived in Cape May the following morning to help assess the extent of the incident.

Cape May’s automated operations were restored by July 28, Dietrich said, allowing employees to once again remotely monitor the system. He said the overall impact on the city lasted slightly more than 24 hours.

Woodbine and Cape May were among water systems nationwide targeted in similar attacks.

The attack did not alter the water system’s operating settings or affect the quality or safety of the water, Dietrich said. Staff were able to monitor key parameters, including chlorine levels and pumping and treatment operations, once they regained access.

“It just prevented us from getting remote access to the system. At no time did it change any settings within the water system. From a work quality or safety standpoint, that was never affected. It just made it so that we couldn’t see the operating parameters of our system remotely,” Dietrich said.

Officials said water service continued throughout the incidents, and routine testing confirmed the drinking water remained safe in both Cape May and Woodbine. They also said customer information was not compromised.

The identity of whoever carried out the attack is still under investigation, Dietrich said.

Cape May’s response

In response to the incident, Dietrich said Cape May is working to eliminate one of the methods officials believe was used to gain access to the system. Dietrich said the city plans to remove cellular modems and rely more heavily on hardline connections.

“We are taking every effort to protect and defend our water supply and production. We supply water to the City of Cape May, West Cape May, Lower Township, Cape May Point, and the United States’ only Coast Guard Training Center located in Cape May City,” said Cape May City Mayor Zachary Mullock, according to the Aug. 6 press release. “We are working with state and federal agencies to ensure our water desalination plant is protected from any adversarial threat.”

Dietrich said the city’s entire water system is connected to the internet or otherwise remotely accessible, highlighting the importance of cybersecurity measures as water infrastructure becomes increasingly dependent on digital systems.

The incident comes as federal officials continue to warn about cybersecurity risks facing water and wastewater utilities. NJ.com reported that the Cybersecurity and Infrastructure Security Agency had urged utilities to remove exposed control systems from the internet when possible.

For Cape May County residents concerned about the incident, Dietrich emphasized that protecting public health and maintaining dependable water service remain the city’s top priorities.

“We take it very seriously, and we follow all of the standard and required protocols from the DEP, and we’ll continue to do so … [and] make sure that we update our systems to meet those standards,” he said.

Dietrich also encouraged residents to view the incident as a reminder to take their own cybersecurity seriously.

“We can all take this time to realize that everyone is vulnerable to a cyber attack. Whether it’s the city directly through our water department [or] as individuals,” he said.

Dietrich encouraged people to review their passwords and other security practices, noting that strong cybersecurity habits are important both at work and at home.

“I think it’s just a good time for us to reflect. That’s one of the things we train here, within the city,” he said. “Good cyber hygiene is not just a workplace thing. You have to take that and make sure you’re doing it at home to make sure your personal information is protected.”