WATER & WASTEWATER SYSTEMS PLC DEVICES AT INCREASED RISK
CISA advisory AA26-097A titled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure” was released April 7, 2026 but with the July 22 update, additional information and guidance have become available. A joint advisory was published by the FBI, CISA, NSA, EPA, DOE, UNMF, and US-Treasury urgently warning U.S. based organizations of an ongoing threat to operational technology including Rockwell Automation, Allen-Bradley, Schneider Electric, Siemens, and other similar manufacturers’ PLC devices. This ongoing threat has been linked to Iranian cyber actors and mentions similar activity which occurred during campaigns by “CyberAv3ngers” in 2023. Impacted devices include programmable logic controllers (PLC), human machine interfaces (HMI), and supervisory control and data acquisition (SCADA) displays and have led to operational disruptions.
CYBERAV3NGERS BACKGROUND & HISTORY
CyberAv3ngers is an Iranian IRGC-linked threat actor group (also tracked as Bauxite, Shahid Kaveh Group, APT Iran, Hydro Kitten, Mr. Soul, Soldiers of Solomon, Storm-0784, and UNC5691) known for their 2023 compromise of Aliquippa, Pennsylvania’s Municipal Water Authority. This attack utilized CVE-2023-6448, a vulnerability exploiting default passwords in Unitronics Vision PLCs.
CyberAv3ngers first appears in 2020 claiming credit for a hack of Israel’s railways which affected operations at 28 railway stations. Months later the group posted on X indicating they were selling data collected during the attack. The data claims to include thousands of employee records, and millions of travel records. In 2023 CyberAv3ngers accessed PLCs from the Unitronics series in several US entities to display the message: “You have been hacked, down with Israel. Every equipment ‘made in Israel’ in CyberAv3ngers legal target.” Around this time CyberAv3ngers claimed to have compromised 200 gas stations in Israel and the United States. By 2024 the groups malware, IOControl, had become publicly available in Open-Source Intelligence (OSINT) sandboxes. IOControl is a Linux backdoor developed for operational technology (OT) and internet of things (IOT) devices. While this malware appears primarily in attacks on operational technology such as Programmable Logic Controllers (PLC), Supervisory Control and Data Acquisition (SCADA) and Human-Machine Interfaces (HMI), it has also been found on IP cameras, routers, firewalls, and is modular enough to work on most Linux operating systems.
Current Advisory
The FBI released a July 30, 2026 advisory titled “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions”. This was in response to at least 7 states reporting attacks on their water, and wastewater facilities to the FBI. In late July, Minnesota reported more than 30 community water systems were targeted by, yet unnamed, malicious actors. These attacks have caused operational disruptions, such as low water pressure, but no major service disruptions. After accessing internet-facing PLC devices, the actors have been observed tampering with assigned IPs, user accounts, passwords, and in at least one case, the operational ladder logic. These attacks have not been attributed at this time but CISA AA26-097A references CyberAv3ngers due to operational similarities.
Indicators of Compromise
Shared indicators of compromise include traffic over OT/MQTT ports 102, 502, 1883, 2222, 8883, and 44818.
IP addresses:
|
Indicator |
Beginning of Association |
End of Association |
|
185.82.73[.]175 |
September 2025 |
February 2026 |
|
141.11.164[.]153 |
January 2026 |
June 2026 |
|
175.110.121[.]42 |
February 2026 |
March 2026 |
|
175.110.121[.]39 |
February 2026 |
March 2026 |
|
175.110.121[.]41 |
February 2026 |
March 2026 |
|
175.110.121[.]107 |
February 2026 |
February 2026 |
|
192.142.54[.]79 |
May 2026 |
June 2026 |
|
84.200.205[.]165 |
May 2026 |
June 2026 |
|
185.225.17[.]225 |
June 2026 |
July 2026 |
|
79.133.46[.]209 |
July 2026 |
July 2026 |
|
88.80.150[.]199 |
July 2026 |
July 2026 |
|
88.80.150[.]200 |
July 2026 |
July 2026 |
|
88.80.150[.]202 |
July 2026 |
July 2026 |
Defensive Measures & Mitigations
The CISA advisory found here and FBI advisory found here contain comprehensive measures that should be reviewed and implemented to secure PLC devices, a good starting point are these:
-
Disconnect the PLC from the public-facing internet. Follow the joint guidance Secure connectivity principles for OT to safely allow remote access. Specifically, “remove inbound port exposure,” so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled. Do this through a secure gateway (jump host) that brokers the connection.
-
Create and test strong backups of the logic and configurations of PLCs. Store backup files offline and secure the physical removal media to enable fast recovery.
-
Ensure device passwords are changed from their default and are configured to use complex, unique combinations of letters, numbers, and symbols that are not easily guessable.
Conclusion
These attacks and similar by actors in support of the Iranian Regime are likely to continue and could escalate. While the current targets have been water and wastewater systems, anyone with PLC systems, especially those noted in the CISA advisories, should take this opportunity to review their security posture and ensure proper security controls are in place. Organizations with internet facing PLC devices should treat this advisory as an urgent item that should be addressed immediately rather than a goal for the future.
