{"database": "press", "table": "releases", "rows": [["https://gottheimer.house.gov/posts/release-after-attacks-in-jersey-gottheimer-announces-bipartisan-federal-actions-to-protect-water-electric-systems-and-families-from-cyber-attacks", "RELEASE: After Attacks in Jersey, Gottheimer Announces Bipartisan Federal Actions to Protect Water, Electric Systems, and Families from Cyber Attacks", "2026-08-12", "2026", "2026-08", "Democrat", "House", "NJ", "Josh Gottheimer", "G000583", "gottheimer.house.gov", "gottheimer", "https://gottheimer.house.gov/press", "scraper", "Above: Gottheimer announces federal action to defend critical infrastructure.\n\nPARK RIDGE, NJ \u2014 Today, Wednesday, August 12, 2026, U.S. Congressman Josh Gottheimer (NJ-5) announced his bipartisan Critical Infrastructure Security Plan, a package of federal actions to bolster American critical infrastructure following a wave of attacks that targeted New Jersey municipal water systems and others in at least a dozen states across the country.\n\nWatch Gottheimer\u2019s full remarks here.\n\n\u201cEvery morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to,\u201d said Congressman Josh Gottheimer (NJ-5). \u201cI\u2019m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don\u2019t get out ahead of it, it could mean a disaster.\u201d\n\nOver the past two weeks, hackers have targeted water systems in New Jersey and at least a dozen other states. In Cape May County, two municipal systems were hit, forcing operators to manually turn valves and run pumps after the digital controls they rely on every day were wrenched away from them. The Federal Bureau of Investigation (FBI) is investigating incidents in at least seven states, and the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI issued a joint advisory urging the entire water sector to immediately lock down its systems. Investigators have pointed to Iranian-affiliated actors, while examining whether other adversaries are copying the same playbook.\n\nThere are roughly 150,000 public water systems in the country, and 97 percent of them serve small communities such as Park Ridge, often with just a handful of employees and no full-time cybersecurity team. Many were built decades ago for reliability, not for cybersecurity, leaving older controllers and outdated software exposed to anyone who knows where to look.\n\nGottheimer announced three federal actions to close that gap:\n\nThe bipartisan AI Cyber Defense Act, which he is introducing with Rep. Don Bacon (NE-2), Rep. Zach Nunn (IA-3), Rep. Hilary Scholten (MI-3), and Rep. Greg Landsman (OH-1) would give America\u2019s critical infrastructure operators free access to the most powerful, cyber-capable AI models. Today those tools are mostly used by the people trying to break in, not the people trying to keep them out. The bill would let a small water utility in New Jersey use the same caliber of AI a foreign intelligence agency might deploy against it, and turn it around to find the open door before an adversary does and patch the vulnerability before it becomes a headline.\n\nThe bipartisan Securing Our Critical Infrastructure Act, which he is introducing with Rep. Don Bacon (NE-2), Rep. Zach Nunn (IA-3), Rep. Hilary Scholten (MI-3), and Rep. Greg Landsman (OH-1) would create a dedicated rapid-response and threat notification service at CISA, built specifically for small and medium water and electric utilities. It would establish one clear point of contact to notify utilities the moment there is an active threat and give real support for the most resource-constrained systems.\n\nGottheimer is also sending a letter to CISA, the EPA, and the FBI demanding they immediately surge incident response teams and technical assistance to every water and wastewater utility hit by this campaign, especially the small and rural systems that can least afford to go dark. The letter also calls on the agencies to build lasting protection for the water sector, including guidance specific to water systems and a standing rapid-response framework, before the next campaign hits.\n\nGottheimer was joined by New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) Director Michael Geraghty, Bergen County Prosecutor Mark Musella, Bergen County Chief of Detectives Jeff Angermeyer, Senator Holly Schepisi (R-District 39), Park Ridge Mayor Keith Misciagna, Park Ridge Councilman Will Fenwick, and Park Ridge Councilman Bruce Goldsmith.\n\nBelow: Gottheimer announces federal action to defend critical infrastructure.\n\nGottheimer\u2019s remarks as prepared for delivery:\n\nThank you to everyone here with us. I\u2019m grateful for all of your work on the ground to protect our essential services.\n\nThank you all for being here in Park Ridge, right in front of the tanks that serve drinking water to Park Ridge and nearby Woodcliff Lake.\n\nI\u2019ve stood right here before when we announced steps the Park Ridge Water Department was taking to get lead and PFAS out of their drinking water. Today, we are here to discuss a different, looming, and potent threat to this critical infrastructure system, and ones like it across our state and country \u2014 cyber terrorism. I\u2019m talking about cyber attacks like the ones in South Jersey two weeks ago and those who attempt to infiltrate our water, electric, and other essential systems \u2014 what we call our critical infrastructure \u2014 every day in America.\n\nWith the explosion and advancement of AI, those threats have become even more common and deadly, and, unfortunately, far too easy to access for those who seek to do us harm. Enemies like Iran, Russia, and China.\n\nI\u2019m not here to scare you. As a Member of the House Permanent Select Committee on Intelligence and Ranking Member of the Subcommittee on National Security Agency and Cyber, I want us all to be aware of, and prepared for, this reality that we are facing here at home.\n\nToday, I am proud to announce my Critical Infrastructure Security Plan \u2014 to give towns, counties, and states the tools they need to protect our families and the water, electric, and other critical infrastructure systems that they rely on from cyber attacks.\n\nEvery morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to. That\u2019s the deal. You pay your water bill, the water shows up. You pay your electric bill, your power works.\n\nUnfortunately, those bills are too expensive these days, but that\u2019s a separate issue. I\u2019m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don\u2019t get out ahead of it, it could mean a disaster.\n\nPicture this: you wake up tomorrow, you go to make the coffee or take a shower before work, and nothing comes out of the tap. Or, you flip on the lights, and the power just isn\u2019t there. Imagine that across a major city. No power to hospitals, businesses, schools, or our homes.\n\nThat\u2019s not some doomsday scenario I\u2019m cooking up. That is what almost happened to Jersey families just two weeks ago.\n\nHere\u2019s what\u2019s actually going on. For the past two weeks, water systems across this country have been under attack. Not \u201ccould happen someday.\u201d It\u2019s happening right now, as we\u2019re standing here.\n\nIt started in Minnesota in late July, when hackers hit roughly thirty water systems in a single 48-hour window. Then it spread to Michigan, New Jersey, Minnesota, Georgia, South Dakota, and five other states.\n\nThe FBI is investigating these incidents right now, and the Cybersecurity and Infrastructure Security Agency, or CISA, the FBI, and the EPA had to put out a joint advisory telling the entire water sector to immediately lock down its systems.\n\nIn the same campaign, two municipal water systems in Cape May County, the City of Cape May and the Borough of Woodbine, got hit. The attack limited their operators\u2019 ability to monitor and manage their own equipment. Real people, Jersey families, could have lost water service \u2014 which could mean no clean drinking water or fire hydrants running dry in an emergency.\n\nStaff had to run out into the field and turn valves and run pumps manually because the digital controls they rely on every single day had been hacked \u2014 their control had been wrenched away from them. Although our power systems weren\u2019t impacted in this attack, many of our energy and power grid sectors utilize the same hardware and remote management protocols that were compromised.\n\nThankfully, both Jersey towns got things hardened and back under control fast, working with the state\u2019s cyber team and our federal partners, and service was not interrupted this time.\n\nBut let\u2019s not kid ourselves and call that luck. That was a warning for us all, and we can\u2019t just sit here and wait for the next attack. Because, by the way, Minnesota wasn\u2019t so lucky \u2014 the city of Braham [BRAM] had to shut down its well and water treatment plant for several hours.\n\nIn 2023, a Chinese state-sponsored actor named Volt Typhoon hacked into a small municipal utility in Massachusetts that serves 15,000 people and infiltrated its systems for nine months, waiting for the right time to sabotage it. In 2015, Russia hit an electric utility in Ukraine, cutting power to 225,000 consumers.\n\nA 2023 cyberattack in Aliquippa, Pennsylvania targeted the same systemsthat were attacked this summer and resulted in the operators needing to temporarily halt pumping. And a 2024 Muleshoe, Texas attack saw the pumps turned on \u2014 out of the operators control \u2014 and caused the tank water level to overflow.\n\nLet\u2019s be straight about who led this latest twelve state attack on our country. Reporting and government advisories have linked the cyber attacks to Iranian-affiliated actors, though officials are also looking into whether our other enemies are involved. This isn\u2019t some kid in a basement messing around.\n\nAccording to public reporting, this is potentially an enemy of our country, using state-backed hackers, testing whether they can reach out and shut off the water and power to American families, hospitals, farmers, and emergency services.\n\nThis also isn\u2019t an isolated incident. Over the last few years, attackers have targeted \u2014 albeit unsuccessfully \u2014 water systems and other critical infrastructure in California, Florida, Maine, Nevada, Kansas, and right here in New Jersey, where an undisclosed water system detected ransomware in its systems in 2020.\n\nAnd, they\u2019ll keep trying, especially with the latest AI frontier models \u2014 they make it even easier to launch cyber attacks.\n\nForeign governments now have access to powerful AI tools that can scan the internet, find potentially weaker utility systems, hand adversaries a target list, and help them exploit the vulnerabilities in our systems. The same technology that can help a small town\u2019s IT guy find and patch a gap in security can help a hostile government find a hundred more it hasn\u2019t even discovered yet. AI didn\u2019t create this threat, but it is accelerating it, and our defenses have to keep up. And it\u2019s only getting easier for them.\n\nIn these latest attacks in our state and across the country, the hackers found pumps and treatment equipment plugged directly into the internet; they logged in, and locked the real operators out. It worked because a lot of our water systems, especially the smaller ones, were built decades ago and not exactly with the most sophisticated systems to protect against cybersecurity. Many of these controllers have little to no built-in protections and run on outdated software. In other words, they\u2019re sitting wide open, vulnerable to anybody who knows where to look.\n\nNow, systems like Park Ridge aren\u2019t sitting on the internet \u2013 they operate offline, on their own closed system, making them less vulnerable to these types of cyber attacks. But, many of our smaller systems are sitting right in the bullseye. And, we have a lot of critical infrastructure systems out there.\n\nThere are roughly 150,000 public water systems in this country, and 97 percent of them serve small and mid-sized communities, just like here in Park Ridge. New Jersey itself has more than 600 community water systems that provide drinking water to approximately 87 percent of the state\u2019s population.\n\nNationwide, there are more than 900 rural electric cooperatives and 2,000 publicly owned utilities that deliver electricity to almost 100 million Americans. These are systems with a handful of employees, limited cybersecurity resources, and vulnerable systems.\n\nBelieve it or not, CISA found that more than 1 in 10 water systems have a critical cybersecurity vulnerability, and more than 80 percent of those vulnerabilities included software flaws discovered before 2017.\n\nCISA\u2019s work is absolutely critical to identifying and combating these threats, but the Trump administration has been slashing it to the bone. Since Trump took office, it\u2019s lost almost a third of its workforce, had their budget cut by $134 million, and the Administration has announced plans to cut another $700 million in the coming year and an additional 860 staff.\n\nThe North American Electric Reliability Corporation has identified similar weaknesses \u2014 the number of vulnerabilities hackers could exploit is rising by roughly 60 per day. If this isn\u2019t a screeching red alarm, I don\u2019t know what is.\n\nI should add, when I say critical infrastructure, I\u2019m not just talking about water or energy systems. In 2023, a ransomware attack forced two New Jersey hospitals \u2014 Hackensack Meridian Mountainside Medical Center and Hackensack Meridian Pascack Valley Medical Center \u2014 to temporarily divert ambulances and reschedule elective procedures.\n\nThe systems took weeks to restore and affected thousands of patients.\n\nHere\u2019s the part that should worry you the most: this isn\u2019t just a big-city problem with big-city budgets and full-time cybersecurity teams standing guard. Right now, federal funding for critical infrastructure cybersecurity has an uncertain future, and it has to compete for scraps against other infrastructure priorities. That\u2019s not fair to the people running these systems on a shoestring budget, and it\u2019s definitely not safe for the families here in Jersey depending on them.\n\nThat\u2019s why today, as part of my Critical Infrastructure Security Plan, I\u2019m announcing three bipartisan federal actions with Congressman Don Bacon of Nebraska, Congressman Zach Nunn of Iowa, and Congressman Greg Landsman of Ohio.\n\nFirst, I\u2019m introducing the bipartisan AI Cyber Defense Act. This new bipartisan legislation will give America\u2019s critical infrastructure operators free access to their most powerful, cyber-capable AI models to secure their systems. Right now, those tools exist. They\u2019re being used, but they\u2019re often way too expensive for these small towns and facilities to afford what they really need.\n\nThis bill will provide that funding, allowing a small water utility or power station, like ones right here in Bergen County, to use the same caliber of AI a foreign intelligence agency might use against them. With those resources, the facilities can take this cutting-edge technology and turn it around to secure their own systems first. They\u2019ll find the open door and lock it before someone tries to break in. They\u2019ll patch the vulnerability before it ever becomes a headline. This is about getting our defense to catch up to their offense, and making it free for the towns that need it most.\n\nA resource-constrained public works department in rural New Jersey should never have to outbid a nation-state just to protect itself. This bill will support the efforts of companies like Anthropic, OpenAI, and Google to get these powerful tools in the hands of those who need it most.\n\nSecond, I\u2019m introducing the bipartisan Securing Our Critical Infrastructure Act. This new bipartisan bill will create a dedicated rapid response and threat notification service at CISA, specifically for small and medium-sized water and electric utilities.\n\nRight now, if you\u2019re a small town utility and something looks wrong on your network, you might not have anyone to call, or you might not even know who to call in the first place. This commonsense legislation creates one clear point of contact within the federal government that will notify these utilities the moment there\u2019s an active threat or a sign that someone\u2019s already inside their systems, with extra support built in for the utilities that are stretched the thinnest. It will also give them a clear point of contact, so they\u2019re not running around trying to figure out who to call.\n\nThird and finally, I\u2019m sending a letter to CISA, the EPA, and the FBI demanding they immediately surge incident response teams and technical assistance to every water and wastewater utility hit by this campaign, including here in Jersey, especially the small and rural systems that can least afford to go dark. But, I\u2019m not just asking for a band-aid. I am also urging these agencies to build real, lasting protection for the water and energy sectors, including guidance specific to water and electric systems and a standing rapid-response framework, so that before the next campaign hits \u2014 because there will be a next one \u2014 our utilities are prepared.\n\nMy cybersecurity package works together to protect our towns and families. The legislation gives our utilities the tools to find their own weaknesses before an adversary does. The rapid response service makes sure small towns aren\u2019t fighting this alone. And, the federal surge makes sure the agencies whose job this is actually show up when it matters. There is nothing partisan about it. It\u2019s about as red, white, and blue as it gets.\n\nWe also need to make sure our states have the resources to support our local systems. That\u2019s why I\u2019m calling on the Senate to pass the PILLAR Act, which I was proud to have helped pass through the House. This critical piece of legislation will reauthorize the State and Local Cybersecurity Grant Program through 2033. These are dollars that towns can request and receive to build out and strengthen their existing cybersecurity systems. Unfortunately, this critical program has not received new funding in more than a year, and it\u2019s putting our local utilities at risk.\n\nI\u2019m also supporting efforts in the Senate to pass legislation to reauthorize the Rural and Municipal Utility Advanced Cybersecurity program, which I also helped pass through the House, which directly helps rural electric cooperatives and municipal utilities strengthen their cybersecurity defenses. I\u2019m also proud to have helped move the SECURE Grid Act through the House, which would ensure states are fully prepared to prevent and respond to the risks posed to the electric grid by cyberattacks, extreme weather, natural disasters, and other threats.\n\nWe can\u2019t afford to leave our state and local governments out to dry \u2014 we must instead empower our local leaders, like the New Jersey Cybersecurity and Communications Integration Cell, to help operators harden their systems.\n\nFinally, the cyber attacks over the last weeks must be a wake up call to every utility \u2013 water, power, or otherwise \u2014 that\u2019s part of our critical infrastructure. Park Ridge\u2019s systems weren\u2019t hit in this attack. But, in a rare move, the town hasn\u2019t waited around to get lucky. Over the past year, on their own initiative, they\u2019ve been upgrading their systems to put in place stronger protections and give better oversight.\n\nWater and power systems across the country need to follow suit and implement tamper-resistant controls, update and patch systems as soon as they are able, build end-to-end encryption, use secure networks, create authentication and access control procedures, test their systems regularly, and train their employees. But, I recognize that it\u2019s not easy \u2014 it\u2019s expensive \u2014 and they need our help. That\u2019s what the actions I\u2019m taking today are all about. They need the federal support behind them to actually make it happen.\n\nAgain, keeping the water running and the lights on isn\u2019t a Democratic issue or a Republican issue. It\u2019s the most basic American obligation we have to the people we serve, and it should never, ever be partisan. When a parent in Park Ridge turns on their kitchen faucet, she doesn\u2019t care which party controls Congress. They just want clean water to come out.\n\nWe caught this attack. And, I know that if we take the right action, we can get ahead of this. But, if we sit on our hands, we might not be so lucky next time. But, I\u2019m confident that when we invest in the people protecting our infrastructure, and give them modern tools instead of asking them to fight modern threats with yesterday\u2019s equipment, we will win.\n\nIf we keep working together to protect our friends and neighbors, in the greatest country in the world, I know that our best days will always be ahead of us. Thank you, God bless you, and may God continue to watch over and bless the United States of America.", 1, "2026-08-13T06:17:16Z", "2026-08-13T06:18:13Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://gottheimer.house.gov/posts/release-after-attacks-in-jersey-gottheimer-announces-bipartisan-federal-actions-to-protect-water-electric-systems-and-families-from-cyber-attacks"], "units": {}, "query_ms": 2.6970021426677704, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}