Unitronics and U.S. municipal water authority: KGW News

Unitronics and U.S. municipal water authority: KGW News

Cyberattack on U.S. Water Utility Linked to Iranian-Backed Hackers

A recent cyberattack targeting a U.S. municipal water authority has been attributed to Iranian-backed hackers, marking another escalation in state-sponsored cyber threats against critical infrastructure. The attack, detected in late November 2023, exploited vulnerabilities in Unitronics programmable logic controllers (PLCs), which are widely used in water and wastewater systems.

The hackers, identified as CyberAv3ngers, a group with ties to Iran’s Islamic Revolutionary Guard Corps (IRGC), gained access to the system by leveraging default passwords and unpatched software. While the attack did not disrupt water supply operations, it allowed the threat actors to deface a human-machine interface (HMI) screen with a pro-Iranian message, signaling their intent to intimidate and demonstrate capability.

The incident follows a broader pattern of Iranian cyber operations targeting U.S. and allied infrastructure, including previous attacks on energy and healthcare sectors. The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert in response, urging organizations to secure PLCs by changing default credentials, implementing network segmentation, and applying software updates.

This attack underscores the growing vulnerability of industrial control systems (ICS) to nation-state threats, particularly as geopolitical tensions drive increased cyber espionage and sabotage efforts. The water authority has since restored affected systems and is working with federal agencies to strengthen defenses.

Source: https://www.kgw.com/article/tech/data-breach-oregon-court-case-management-system/283-33c52d8f-4af9-4046-b9ec-a9b702d93f06

Unitronics TPRM report: https://www.rankiteo.com/company/unitronics_2

U.S. municipal water authority TPRM report: https://www.rankiteo.com/company/us-water-services-corporation

"id": "us-uni1788512130",
"linkid": "us-water-services-corporation, unitronics_2",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': 'Critical infrastructure, Water and '
                                    'wastewater',
                        'location': 'United States',
                        'name': 'U.S. municipal water authority',
                        'type': 'Water utility'}],
 'attack_vector': 'Exploitation of default passwords and unpatched software',
 'date_detected': '2023-11',
 'description': 'A recent cyberattack targeting a U.S. municipal water '
                'authority has been attributed to Iranian-backed hackers, '
                'marking another escalation in state-sponsored cyber threats '
                'against critical infrastructure. The attack exploited '
                'vulnerabilities in Unitronics programmable logic controllers '
                '(PLCs), widely used in water and wastewater systems. The '
                'hackers defaced a human-machine interface (HMI) screen with a '
                'pro-Iranian message, signaling their intent to intimidate and '
                'demonstrate capability.',
 'impact': {'operational_impact': 'No disruption to water supply operations',
            'systems_affected': 'Unitronics PLCs, human-machine interface '
                                '(HMI)'},
 'lessons_learned': 'Growing vulnerability of industrial control systems (ICS) '
                    'to nation-state threats; importance of securing PLCs by '
                    'changing default credentials, implementing network '
                    'segmentation, and applying software updates.',
 'motivation': 'Intimidation, demonstration of capability, geopolitical '
               'tensions',
 'post_incident_analysis': {'corrective_actions': 'Restoration of affected '
                                                  'systems, collaboration with '
                                                  'federal agencies to '
                                                  'strengthen defenses',
                            'root_causes': 'Exploitation of default passwords '
                                           'and unpatched software in '
                                           'Unitronics PLCs'},
 'recommendations': 'Change default credentials, implement network '
                    'segmentation, apply software updates, enhance monitoring '
                    'of ICS.',
 'references': [{'source': 'Cybersecurity and Infrastructure Security Agency '
                           '(CISA)'}],
 'regulatory_compliance': {'regulatory_notifications': 'CISA alert issued'},
 'response': {'network_segmentation': 'Recommended by CISA',
              'remediation_measures': 'Restored affected systems, working with '
                                      'federal agencies to strengthen '
                                      'defenses'},
 'threat_actor': 'CyberAv3ngers (IRGC-affiliated)',
 'title': 'Cyberattack on U.S. Water Utility Linked to Iranian-Backed Hackers',
 'type': 'Cyberattack',
 'vulnerability_exploited': 'Default credentials, unpatched Unitronics PLC '
                            'software'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.