--- Source 2 --- Iranian-Backed Cyberattack on Water Utilities in Multiple U.S. States
Key Points: Attack Details: Iranian-backed cyberattack group, "Cyber Av3ngers," claimed responsibility for compromising Unitronics Vision Series PLCs in U.S. water facilities. Vulnerability: The attackers exploited a default password vulnerability in Unitronics Vision Series PLCs, specifically targeting devices exposed to the public internet. Impact: While the attackers claimed to have caused operational disruptions, the affected utilities reported minimal impact, primarily limited to defacement of human-machine interfaces (HMIs). Targets: The attacks targeted water utilities in multiple U.S. states, including Pennsylvania and Minnesota. Attribution: The FBI and CISA attributed the attacks to Iranian-backed actors, citing the use of "Cyber Av3ngers" branding and anti-Israel messaging. Recommendations: CISA and the FBI issued a joint advisory (AA23-335A) urging critical infrastructure organizations to secure their PLCs, change default passwords, and implement network segmentation.
Full Story:
A sophisticated cyberattack, attributed to an Iranian-backed group known as "Cyber Av3ngers," has targeted water utilities across multiple U.S. states, including Pennsylvania and Minnesota. The attackers claimed responsibility for compromising Unitronics Vision Series Programmable Logic Controllers (PLCs), exploiting a default password vulnerability in devices directly exposed to the public internet.
The "Cyber Av3ngers" group, known for its anti-Israel rhetoric, defaced the human-machine interfaces (HMIs) of the compromised PLCs with messages such as "EVERYTHING FOR ISRAEL IS UNLAWFUL." While the attackers boasted of causing significant operational disruptions, the affected utilities have largely reported minimal impact, primarily limited to the HMI defacement.
The FBI and CISA have jointly attributed these attacks to Iranian-backed actors, citing the consistent use of the "Cyber Av3ngers" moniker and the political messaging displayed on the defaced systems. This attribution aligns with broader concerns regarding nation-state sponsored cyber activities targeting critical infrastructure.
In response to these incidents, CISA and the FBI have issued a joint advisory (AA23-335A), providing urgent recommendations for critical infrastructure organizations. These recommendations include immediately changing all default passwords on PLCs and other operational technology (OT) devices, implementing robust network segmentation to isolate OT networks from IT networks, and regularly patching and updating systems. The advisory emphasizes the importance of reducing the attack surface by ensuring that OT devices are not directly accessible from the public internet.
The attacks highlight the ongoing threat posed by nation-state actors to critical infrastructure and underscore the necessity for enhanced cybersecurity measures within the utility sector.
--- Source 3 --- Iranian Hackers Target U.S. Water Systems: A Growing Threat
Key Details: Attack Group: "Cyber Av3ngers," an Iranian-backed hacking group. Targeted Systems: Unitronics Vision Series PLCs. Vulnerability Exploited: Default passwords on internet-exposed PLCs. Impact (Confirmed): Defacement of Human-Machine Interfaces (HMIs) with anti-Israel messages. Impact (Claimed by Attackers): Operational disruptions and control over water systems. Affected States: Confirmed incidents in Pennsylvania and Minnesota; claims of attacks in seven states. Official Response: FBI and CISA issued a joint advisory (AA23-335A) urging immediate action. Recommendations: Change default passwords, implement network segmentation, monitor OT networks.
Full Report:
An Iranian-backed hacking group known as "Cyber Av3ngers" has claimed responsibility for a series of cyberattacks targeting water systems across the United States. The group specifically exploited Unitronics Vision Series Programmable Logic Controllers (PLCs) that were found to be exposed to the public internet and still utilizing their default passwords.
Confirmed incidents include the defacement of Human-Machine Interfaces (HMIs) at water facilities in Pennsylvania and Minnesota. The defaced screens displayed anti-Israel messages, including "EVERYTHING FOR ISRAEL IS UNLAWFUL," aligning with the "Cyber Av3ngers" group's known political motivations. While the attackers have claimed to have achieved operational disruptions and taken control of the targeted water systems, the affected utilities have largely reported that the impact was limited to the HMI defacement. There is no official confirmation of widespread operational disruption or damage to the water supply.
The FBI and CISA have jointly issued an advisory, AA23-335A, in response to these attacks. The advisory attributes the incidents to Iranian-backed actors and provides urgent recommendations for critical infrastructure organizations, particularly those in the water and wastewater sector. These recommendations emphasize the immediate necessity of changing all default passwords on PLCs and other operational technology (OT) devices. Furthermore, the advisory stresses the importance of network segmentation to isolate OT networks from enterprise IT networks, thereby limiting potential lateral movement for attackers. Organizations are also urged to continuously monitor their OT networks for suspicious activity and to ensure that OT devices are not directly accessible from the internet.
The "Cyber Av3ngers" group has claimed to have targeted facilities in at least seven U.S. states, though specific details beyond Pennsylvania and Minnesota remain unconfirmed by official sources. This campaign underscores the persistent and evolving threat that state-sponsored cyber actors pose to critical infrastructure sectors globally. The exploitation of basic vulnerabilities like default passwords highlights a significant security gap that organizations must address to protect essential services.






