Other

IBM Security Intelligence

πŸ“… 2024-01-18 🏒 Unitronics PLC / Muleshoe, TX water tower SCADA
Primary Source β†—

Incident Details

In January 2024, Russian hackers affiliated with Sandworm (a GRU/Russian military intelligence cyber unit) infiltrated water treatment systems in Muleshoe, Texas, causing a water storage tank to overflow. The attack exploited internet-exposed Unitronics programmable logic controllers (PLCs) with default credentials β€” the same vulnerability exploited in November 2023 by Iran-affiliated group CyberAv3ngers against US water utilities. The Muleshoe incident involved several small Texas municipalities and was disclosed publicly in April 2024 after CISA and FBI investigated. No drinking water safety impact was reported, but the incident demonstrated that OT/ICS systems at small utilities are directly accessible from the internet with default credentials and represent a significant physical-world risk.

Technical Details

Initial Attack Vector
CWE-1188: Insecure Default Initialization of Resource (default credentials on internet-exposed industrial control systems)
Vendor / Product
Unitronics PLC / Muleshoe, TX water tower SCADA

Timeline

  1. 2024-01-18 Breach occurred
  2. 2024-04-18 Publicly disclosed
  3. unknown Customers notified