Iran-Linked Cyberattacks Hit US Water Systems in 12 States via Exposed PLCs
Cyberattacks targeting US water utilities have expanded to at least a dozen states, with cybersecurity investigators pointing to Iran-linked threat actors as the likely perpetrators. The intrusions exploit Programmable Logic Controllers (PLCs) manufactured by Unitronics that were left directly exposed to the public Internet without authentication or network segmentation. CISA, the FBI, and the EPA have jointly urged water and wastewater operators to disconnect vulnerable devices from public-facing networks and implement proper access controls. Researchers at Claroty and Microsoft have independently linked the campaign to a cluster tracked as "CyberAv3ngers," an Iranian state-aligned group known for ideological targeting of Israeli and Western critical infrastructure.
The attack chain is straightforward but devastating in its simplicity. Adversaries use port scanning against the industrial control system's default TCP port (typically 2020 or 502), identify the Unitronics Vision series PLC's web-based HMI interface, and brute-force or bypass the default password to seize full control. Once inside, attackers have deflated dashboards with anti-Israel imagery, changed setpoints, and in at least one confirmed case manipulated chemical dosing parameters at a Pennsylvania treatment facility. Defenders monitoring the same exposed footprint can use a WHOIS lookup on suspicious command-and-control IPs to corroborate attribution alongside infrastructure overlap with prior IRGC-affiliated operations.
Mitigation guidance from CISA emphasizes placing PLCs behind VPNs with multi-factor authentication, disabling unused network services, and applying firmware updates from Unitronics. Organizations responsible for operational technology should also run continuous port scanning and external attack surface assessments to identify any remaining Internet-exposed controllers before adversaries do. Water utilities operating on tight budgets and legacy equipment remain the most exposed, and regulators are now weighing whether to extend mandatory incident-reporting rules under the upcoming CIRCIA framework to cover these previously underserved small and mid-sized operators.