Other

Iranian IRGC CyberAv3ngers Water Utility ICS Attacks β€” US and Israel Infrastructure

πŸ“… 2023-11-22 🏒 Unitronics Vision Series PLCs (programmable logic controllers) at US water and wastewater facilities πŸ”Ž CVE-2023-6448
Primary Source β†—

Incident Details

Beginning 22 November 2023, CyberAv3ngers β€” a threat group affiliated with Iran’s IRGC Cyber-Electronic Command β€” conducted attacks against Unitronics Vision Series PLCs at water and wastewater facilities in the United States and Israel. The first publicly confirmed victim was the Municipal Water Authority of Aliquippa, Pennsylvania (MWAA), which announced on 25 November 2023 that CyberAv3ngers had taken over one of its booster stations’ PLCs, displaying a message reading ‘You have been hacked, Down With Israel.’ MWAA clarified that water safety was not affected. CISA, the FBI, EPA, and NSA issued a joint advisory on 1 December 2023 identifying the specific vulnerability: Unitronics PLCs running default passwords and exposed directly to the internet (CVE-2023-6448). Multiple US water utilities in Pennsylvania, Texas, and other states were similarly attacked. The attacks highlighted that critical infrastructure ICS/OT systems remained publicly internet-accessible with default credentials β€” a known and preventable configuration failure. CyberAv3ngers had previously attacked Israeli water infrastructure and was motivated by geopolitical opposition to Israel’s military operations. The attacks prompted emergency guidance from the EPA and water sector ISACs (WaterISAC). In February 2024, the US DOJ indicted six IRGC members in connection with the CyberAv3ngers water utility attacks. The campaign continued to generate concern into 2026, with DataBreachToday and CISA reporting ongoing prepositioned IRGC access to US water and energy sector ICS systems.

Technical Details

Initial Attack Vector
CyberAv3ngers (affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command, IRGC-CEC) exploited internet-exposed Unitronics Vision Series PLCs at water and wastewater facilities; the PLCs had default factory passwords and were directly internet-accessible without authentication
Vendor / Product
Unitronics Vision Series PLCs (programmable logic controllers) at US water and wastewater facilities
CVE / GHSA References
CVE-2023-6448

Timeline

  1. 2023-11-22 Breach occurred
  2. 2023-12-01 Publicly disclosed