RELEASE: After Attacks in Jersey, Gottheimer Announces Bipartisan Federal Actions to Protect Water, Electric Systems, and Families from Cyber Attacks
Critical Infrastructure Security Plan Will Give Infrastructure Entities Access to Cutting-Edge AI Defenses, Create a Dedicated Cyber Rapid-Response Service, Help Restore Utilities Hit by Attacks

Above: Gottheimer announces federal action to defend critical infrastructure.
PARK RIDGE, NJ — Today, Wednesday, August 12, 2026, U.S. Congressman Josh Gottheimer (NJ-5) announced his bipartisan Critical Infrastructure Security Plan, a package of federal actions to bolster American critical infrastructure following a wave of attacks that targeted New Jersey municipal water systems and others in at least a dozen states across the country.
Watch Gottheimer’s full remarks here.
“Every morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to,” said Congressman Josh Gottheimer (NJ-5). “I’m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don’t get out ahead of it, it could mean a disaster.”
Over the past two weeks, hackers have targeted water systems in New Jersey and at least a dozen other states. In Cape May County, two municipal systems were hit, forcing operators to manually turn valves and run pumps after the digital controls they rely on every day were wrenched away from them. The Federal Bureau of Investigation (FBI) is investigating incidents in at least seven states, and the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI issued a joint advisory urging the entire water sector to immediately lock down its systems. Investigators have pointed to Iranian-affiliated actors, while examining whether other adversaries are copying the same playbook.
There are roughly 150,000 public water systems in the country, and 97 percent of them serve small communities such as Park Ridge, often with just a handful of employees and no full-time cybersecurity team. Many were built decades ago for reliability, not for cybersecurity, leaving older controllers and outdated software exposed to anyone who knows where to look.
Gottheimer announced three federal actions to close that gap:
- The bipartisan AI Cyber Defense Act, which he is introducing with Rep. Don Bacon (NE-2), Rep. Zach Nunn (IA-3), Rep. Hilary Scholten (MI-3), and Rep. Greg Landsman (OH-1) would give America’s critical infrastructure operators free access to the most powerful, cyber-capable AI models. Today those tools are mostly used by the people trying to break in, not the people trying to keep them out. The bill would let a small water utility in New Jersey use the same caliber of AI a foreign intelligence agency might deploy against it, and turn it around to find the open door before an adversary does and patch the vulnerability before it becomes a headline.
- The bipartisan Securing Our Critical Infrastructure Act, which he is introducing with Rep. Don Bacon (NE-2), Rep. Zach Nunn (IA-3), Rep. Hilary Scholten (MI-3), and Rep. Greg Landsman (OH-1) would create a dedicated rapid-response and threat notification service at CISA, built specifically for small and medium water and electric utilities. It would establish one clear point of contact to notify utilities the moment there is an active threat and give real support for the most resource-constrained systems.
- Gottheimer is also sending a letter to CISA, the EPA, and the FBI demanding they immediately surge incident response teams and technical assistance to every water and wastewater utility hit by this campaign, especially the small and rural systems that can least afford to go dark. The letter also calls on the agencies to build lasting protection for the water sector, including guidance specific to water systems and a standing rapid-response framework, before the next campaign hits.
Gottheimer was joined by New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) Director Michael Geraghty, Bergen County Prosecutor Mark Musella, Bergen County Chief of Detectives Jeff Angermeyer, Senator Holly Schepisi (R-District 39), Park Ridge Mayor Keith Misciagna, Park Ridge Councilman Will Fenwick, and Park Ridge Councilman Bruce Goldsmith.
Below: Gottheimer announces federal action to defend critical infrastructure.





Gottheimer’s remarks as prepared for delivery:
Thank you to everyone here with us. I’m grateful for all of your work on the ground to protect our essential services.
Thank you all for being here in Park Ridge, right in front of the tanks that serve drinking water to Park Ridge and nearby Woodcliff Lake.
I’ve stood right here before when we announced steps the Park Ridge Water Department was taking to get lead and PFAS out of their drinking water. Today, we are here to discuss a different, looming, and potent threat to this critical infrastructure system, and ones like it across our state and country — cyber terrorism. I’m talking about cyber attacks like the ones in South Jersey two weeks ago and those who attempt to infiltrate our water, electric, and other essential systems — what we call our critical infrastructure — every day in America.
With the explosion and advancement of AI, those threats have become even more common and deadly, and, unfortunately, far too easy to access for those who seek to do us harm. Enemies like Iran, Russia, and China.
I’m not here to scare you. As a Member of the House Permanent Select Committee on Intelligence and Ranking Member of the Subcommittee on National Security Agency and Cyber, I want us all to be aware of, and prepared for, this reality that we are facing here at home.
Today, I am proud to announce my Critical Infrastructure Security Plan — to give towns, counties, and states the tools they need to protect our families and the water, electric, and other critical infrastructure systems that they rely on from cyber attacks.
Every morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to. That’s the deal. You pay your water bill, the water shows up. You pay your electric bill, your power works.
Unfortunately, those bills are too expensive these days, but that’s a separate issue. I’m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don’t get out ahead of it, it could mean a disaster.
Picture this: you wake up tomorrow, you go to make the coffee or take a shower before work, and nothing comes out of the tap. Or, you flip on the lights, and the power just isn’t there. Imagine that across a major city. No power to hospitals, businesses, schools, or our homes.
That’s not some doomsday scenario I’m cooking up. That is what almost happened to Jersey families just two weeks ago.
Here’s what’s actually going on. For the past two weeks, water systems across this country have been under attack. Not “could happen someday.” It’s happening right now, as we’re standing here.
It started in Minnesota in late July, when hackers hit roughly thirty water systems in a single 48-hour window. Then it spread to Michigan, New Jersey, Minnesota, Georgia, South Dakota, and five other states.
The FBI is investigating these incidents right now, and the Cybersecurity and Infrastructure Security Agency, or CISA, the FBI, and the EPA had to put out a joint advisory telling the entire water sector to immediately lock down its systems.
In the same campaign, two municipal water systems in Cape May County, the City of Cape May and the Borough of Woodbine, got hit. The attack limited their operators’ ability to monitor and manage their own equipment. Real people, Jersey families, could have lost water service — which could mean no clean drinking water or fire hydrants running dry in an emergency.
Staff had to run out into the field and turn valves and run pumps manually because the digital controls they rely on every single day had been hacked — their control had been wrenched away from them. Although our power systems weren’t impacted in this attack, many of our energy and power grid sectors utilize the same hardware and remote management protocols that were compromised.
Thankfully, both Jersey towns got things hardened and back under control fast, working with the state’s cyber team and our federal partners, and service was not interrupted this time.
But let’s not kid ourselves and call that luck. That was a warning for us all, and we can’t just sit here and wait for the next attack. Because, by the way, Minnesota wasn’t so lucky — the city of Braham [BRAM] had to shut down its well and water treatment plant for several hours.
In 2023, a Chinese state-sponsored actor named Volt Typhoon hacked into a small municipal utility in Massachusetts that serves 15,000 people and infiltrated its systems for nine months, waiting for the right time to sabotage it. In 2015, Russia hit an electric utility in Ukraine, cutting power to 225,000 consumers.
A 2023 cyberattack in Aliquippa, Pennsylvania targeted the same systemsthat were attacked this summer and resulted in the operators needing to temporarily halt pumping. And a 2024 Muleshoe, Texas attack saw the pumps turned on — out of the operators control — and caused the tank water level to overflow.
Let’s be straight about who led this latest twelve state attack on our country. Reporting and government advisories have linked the cyber attacks to Iranian-affiliated actors, though officials are also looking into whether our other enemies are involved. This isn’t some kid in a basement messing around.
According to public reporting, this is potentially an enemy of our country, using state-backed hackers, testing whether they can reach out and shut off the water and power to American families, hospitals, farmers, and emergency services.
This also isn’t an isolated incident. Over the last few years, attackers have targeted — albeit unsuccessfully — water systems and other critical infrastructure in California, Florida, Maine, Nevada, Kansas, and right here in New Jersey, where an undisclosed water system detected ransomware in its systems in 2020.
And, they’ll keep trying, especially with the latest AI frontier models — they make it even easier to launch cyber attacks.
Foreign governments now have access to powerful AI tools that can scan the internet, find potentially weaker utility systems, hand adversaries a target list, and help them exploit the vulnerabilities in our systems. The same technology that can help a small town’s IT guy find and patch a gap in security can help a hostile government find a hundred more it hasn’t even discovered yet. AI didn’t create this threat, but it is accelerating it, and our defenses have to keep up. And it’s only getting easier for them.
In these latest attacks in our state and across the country, the hackers found pumps and treatment equipment plugged directly into the internet; they logged in, and locked the real operators out. It worked because a lot of our water systems, especially the smaller ones, were built decades ago and not exactly with the most sophisticated systems to protect against cybersecurity. Many of these controllers have little to no built-in protections and run on outdated software. In other words, they’re sitting wide open, vulnerable to anybody who knows where to look.
Now, systems like Park Ridge aren’t sitting on the internet – they operate offline, on their own closed system, making them less vulnerable to these types of cyber attacks. But, many of our smaller systems are sitting right in the bullseye. And, we have a lot of critical infrastructure systems out there.
There are roughly 150,000 public water systems in this country, and 97 percent of them serve small and mid-sized communities, just like here in Park Ridge. New Jersey itself has more than 600 community water systems that provide drinking water to approximately 87 percent of the state’s population.
Nationwide, there are more than 900 rural electric cooperatives and 2,000 publicly owned utilities that deliver electricity to almost 100 million Americans. These are systems with a handful of employees, limited cybersecurity resources, and vulnerable systems.
Believe it or not, CISA found that more than 1 in 10 water systems have a critical cybersecurity vulnerability, and more than 80 percent of those vulnerabilities included software flaws discovered before 2017.
CISA’s work is absolutely critical to identifying and combating these threats, but the Trump administration has been slashing it to the bone. Since Trump took office, it’s lost almost a third of its workforce, had their budget cut by $134 million, and the Administration has announced plans to cut another $700 million in the coming year and an additional 860 staff.
The North American Electric Reliability Corporation has identified similar weaknesses — the number of vulnerabilities hackers could exploit is rising by roughly 60 per day. If this isn’t a screeching red alarm, I don’t know what is.
I should add, when I say critical infrastructure, I’m not just talking about water or energy systems. In 2023, a ransomware attack forced two New Jersey hospitals — Hackensack Meridian Mountainside Medical Center and Hackensack Meridian Pascack Valley Medical Center — to temporarily divert ambulances and reschedule elective procedures.
The systems took weeks to restore and affected thousands of patients.
Here’s the part that should worry you the most: this isn’t just a big-city problem with big-city budgets and full-time cybersecurity teams standing guard. Right now, federal funding for critical infrastructure cybersecurity has an uncertain future, and it has to compete for scraps against other infrastructure priorities. That’s not fair to the people running these systems on a shoestring budget, and it’s definitely not safe for the families here in Jersey depending on them.
That’s why today, as part of my Critical Infrastructure Security Plan, I’m announcing three bipartisan federal actions with Congressman Don Bacon of Nebraska, Congressman Zach Nunn of Iowa, and Congressman Greg Landsman of Ohio.
First, I’m introducing the bipartisan AI Cyber Defense Act. This new bipartisan legislation will give America’s critical infrastructure operators free access to their most powerful, cyber-capable AI models to secure their systems. Right now, those tools exist. They’re being used, but they’re often way too expensive for these small towns and facilities to afford what they really need.
This bill will provide that funding, allowing a small water utility or power station, like ones right here in Bergen County, to use the same caliber of AI a foreign intelligence agency might use against them. With those resources, the facilities can take this cutting-edge technology and turn it around to secure their own systems first. They’ll find the open door and lock it before someone tries to break in. They’ll patch the vulnerability before it ever becomes a headline. This is about getting our defense to catch up to their offense, and making it free for the towns that need it most.
A resource-constrained public works department in rural New Jersey should never have to outbid a nation-state just to protect itself. This bill will support the efforts of companies like Anthropic, OpenAI, and Google to get these powerful tools in the hands of those who need it most.
Second, I’m introducing the bipartisan Securing Our Critical Infrastructure Act. This new bipartisan bill will create a dedicated rapid response and threat notification service at CISA, specifically for small and medium-sized water and electric utilities.
Right now, if you’re a small town utility and something looks wrong on your network, you might not have anyone to call, or you might not even know who to call in the first place. This commonsense legislation creates one clear point of contact within the federal government that will notify these utilities the moment there’s an active threat or a sign that someone’s already inside their systems, with extra support built in for the utilities that are stretched the thinnest. It will also give them a clear point of contact, so they’re not running around trying to figure out who to call.
Third and finally, I’m sending a letter to CISA, the EPA, and the FBI demanding they immediately surge incident response teams and technical assistance to every water and wastewater utility hit by this campaign, including here in Jersey, especially the small and rural systems that can least afford to go dark. But, I’m not just asking for a band-aid. I am also urging these agencies to build real, lasting protection for the water and energy sectors, including guidance specific to water and electric systems and a standing rapid-response framework, so that before the next campaign hits — because there will be a next one — our utilities are prepared.
My cybersecurity package works together to protect our towns and families. The legislation gives our utilities the tools to find their own weaknesses before an adversary does. The rapid response service makes sure small towns aren’t fighting this alone. And, the federal surge makes sure the agencies whose job this is actually show up when it matters. There is nothing partisan about it. It’s about as red, white, and blue as it gets.
We also need to make sure our states have the resources to support our local systems. That’s why I’m calling on the Senate to pass the PILLAR Act, which I was proud to have helped pass through the House. This critical piece of legislation will reauthorize the State and Local Cybersecurity Grant Program through 2033. These are dollars that towns can request and receive to build out and strengthen their existing cybersecurity systems. Unfortunately, this critical program has not received new funding in more than a year, and it’s putting our local utilities at risk.
I’m also supporting efforts in the Senate to pass legislation to reauthorize the Rural and Municipal Utility Advanced Cybersecurity program, which I also helped pass through the House, which directly helps rural electric cooperatives and municipal utilities strengthen their cybersecurity defenses. I’m also proud to have helped move the SECURE Grid Act through the House, which would ensure states are fully prepared to prevent and respond to the risks posed to the electric grid by cyberattacks, extreme weather, natural disasters, and other threats.
We can’t afford to leave our state and local governments out to dry — we must instead empower our local leaders, like the New Jersey Cybersecurity and Communications Integration Cell, to help operators harden their systems.
Finally, the cyber attacks over the last weeks must be a wake up call to every utility – water, power, or otherwise — that’s part of our critical infrastructure. Park Ridge’s systems weren’t hit in this attack. But, in a rare move, the town hasn’t waited around to get lucky. Over the past year, on their own initiative, they’ve been upgrading their systems to put in place stronger protections and give better oversight.
Water and power systems across the country need to follow suit and implement tamper-resistant controls, update and patch systems as soon as they are able, build end-to-end encryption, use secure networks, create authentication and access control procedures, test their systems regularly, and train their employees. But, I recognize that it’s not easy — it’s expensive — and they need our help. That’s what the actions I’m taking today are all about. They need the federal support behind them to actually make it happen.
Again, keeping the water running and the lights on isn’t a Democratic issue or a Republican issue. It’s the most basic American obligation we have to the people we serve, and it should never, ever be partisan. When a parent in Park Ridge turns on their kitchen faucet, she doesn’t care which party controls Congress. They just want clean water to come out.
We caught this attack. And, I know that if we take the right action, we can get ahead of this. But, if we sit on our hands, we might not be so lucky next time. But, I’m confident that when we invest in the people protecting our infrastructure, and give them modern tools instead of asking them to fight modern threats with yesterday’s equipment, we will win.
If we keep working together to protect our friends and neighbors, in the greatest country in the world, I know that our best days will always be ahead of us. Thank you, God bless you, and may God continue to watch over and bless the United States of America.
###