SEVN-X CEO Matt Barnett on NBC10 with investigative reporter David Charns. Click to watch on NBCPhiladelphia.com.
In the Media · NBC10 Investigators
SEVN-X Threat Intelligence | August 13, 2026 | 5 min read
Two water utilities at the Jersey Shore were breached this month, and the part that should get every executive's attention is not what the attackers did. It is how close they got. NBC10 investigative reporter David Charns brought the story to SEVN-X CEO Matt Barnett, who walked through what the intrusions likely were, what they were not, and why a quiet "we're here and then gone" visit to a water system is worth losing sleep over. The attackers reached the layer that watches, not the layer that controls. The warning is that the two sit closer together than most utilities think.
What happened
The Cape May Water and Sewer Department and the Woodbine Water Department, both in Cape May County, were hit in separate cyber intrusions disclosed in early August. Officials said the hackers reached the departments' monitoring systems but did not get into the computers that actually control water operations. Cape May City Manager Paul Deitrich described the intrusion in plain terms.
"They just went in and said, 'Hi, we're here,' and left."
Paul Deitrich, Cape May City Manager
The intrusions landed about a week after a July 30 alert from the Cybersecurity and Infrastructure Security Agency warning that cyber actors were getting into utility systems and changing passwords. NBC News has reported that Iran is believed to be behind a wave of these attacks across seven states, New Jersey among them.
The SEVN-X read
NBC10 asked Barnett what a breach like this actually signals. His answer reframed it from a local IT headache into something with a much wider footprint.
"When you look at these types of attacks, the motivation is really about disruption to our way of life."
Matt Barnett, CEO, SEVN-X
Barnett's point is that attacks on water, power, and other utilities are rarely about stealing data. They are about probing for weaknesses that could one day let someone interfere with the physical process itself: the valves, the pumps, and the chemicals that go into the water supply. He was clear that there is no indication any of that happened in Cape May or Woodbine, and that he is not directly involved in those investigations. The concern is the direction of travel, not this one incident.
What the access actually was
The reassuring detail is also the instructive one. As far as anyone can tell, the access sat on the read-only side of the house.
"It's possible that what we're looking at now is access to the read-only components, or the kind of monitoring systems, and not necessarily the systems that allow changes to those pieces."
Matt Barnett, SEVN-X
That distinction is the whole ballgame in operational technology. Monitoring systems let an intruder see. Control systems let an intruder act. The gap between the two is supposed to be wide, enforced by network segmentation, and hard to cross. When an attacker plants a flag in the monitoring layer and then leaves, the message is that they found a way in and wanted someone to notice. Getting from there to the controls is the real fear, and closing that path is exactly the job utilities cannot afford to get wrong.
What the agencies and officials said
CISA's July 30 guidance was specific: disconnect critical control systems from the internet, strengthen passwords, and restrict remote access to cut the risk of service disruption or physical damage. Several water agencies across Delaware, New Jersey, and Pennsylvania told NBC10 they were not affected, and credited one thing in particular. Their systems are not connected to the internet at all.
Investigations in Cape May and Woodbine remain ongoing with help from state counterterrorism officials. On the policy side, a bipartisan group of senators, including Pennsylvania Republican Dave McCormick, reintroduced legislation to fund cybersecurity upgrades for the smaller utilities that are often the softest targets.
Why business leaders should care
It is tempting to file this under "government problem" and move on. Barnett's framing makes clear why that is a mistake. The systems in question are not abstractions.
"These are things that keep the lights on and keep the water flowing for American citizens, and anything that puts that at risk or has the potential to disrupt that could likely impact the lives, and maybe even the safety, of hundreds, thousands, millions of people."
Matt Barnett, SEVN-X
The pattern that hit two small water departments applies to any organization that runs operational technology, or that depends on a vendor which does: manufacturers, healthcare systems, building management, logistics. The attacker's playbook is to find the internet-facing seam, get a foothold in something low-privilege, and see how far it reaches. The defense is unglamorous, and it is the same everywhere.
What leaders can take from this
Separate what watches from what controls
Keep monitoring systems and control systems on segmented networks, so that access to one does not hand over the other. That gap is what kept these intrusions from becoming something far worse.
Get critical controls off the public internet
The agencies that were not affected had one thing in common. Their control systems were not reachable from the internet. Air-gapping or tightly restricting remote access to operational technology is the single highest-value move a utility can make.
Kill default and reused passwords everywhere
The federal alert that preceded these attacks pointed at cyber actors changing passwords on utility systems. Enforce strong, unique credentials and multifactor authentication on every account that touches operational technology.
Assume you are being tested
A quiet, "we were here" intrusion is reconnaissance, not a prank. Treat any unexplained access as a probe for a bigger move, investigate it fully, and close the way in before someone comes back to use it.
The bottom line
Two water departments at the Jersey Shore got a warning shot, and so did everyone who runs critical systems. The attackers reached the layer that watches, not the layer that controls, and that line held. The job now is to make sure it keeps holding: separate monitoring from control, take critical systems off the open internet, lock down credentials, and treat every quiet intrusion as the rehearsal it probably is. As Barnett put it, the stakes here are not data. They are the lights and the water, and the people who depend on both.
Worried about the operational technology in your own environment?
SEVN-X helps organizations find the internet-facing seams before someone else does.
Meet with an expertSource. This post recaps reporting from NBC10 Philadelphia, "Experts warn of growing threat after hackers hit New Jersey water utilities," by David Charns (published August 7, 2026), which featured SEVN-X CEO Matt Barnett. Watch the original segment and read the full story on NBCPhiladelphia.com. Additional analysis and recommendations are SEVN-X commentary.