top of page
Search

The CyberSecureOT Report: State-Sponsored Threats and the Fragility of Municipal Water

  • Writer: Dennis Hackney
    Dennis Hackney
  • 10 minutes ago
  • 5 min read
CyberSecureOT report infographic of a glowing world map with orange attack routes and text on municipal water threats.

By Dr. Dennis Hackney, PhD in Information Security

Principal OT Cybersecurity & Host of CyberSecureOT


Don’t forget to tune in to our upcoming podcast episode on this exact topic, airing in one week! We will dive deeper into the updates on the water utility breaches impacting our people.


Welcome back to the CyberSecureOT blog. Over the past few weeks on the podcast, I have taken a deep dive into the sobering reality facing our critical infrastructure. The Water and Wastewater Systems (WWS) sector is under a coordinated, sustained assault from state-sponsored threat actors.


If there is one cohesive thread tying these recent incidents together, it is that security by obscurity is completely dead. From Iranian-backed groups targeting Israeli PLCs to widespread disruptions across the American Midwest, the adversaries are not relying on highly sophisticated, million-dollar zero-day exploits. They are simply walking through front doors left wide open by internet-connected hardware and default credentials.

Here is a breakdown of the critical intelligence and attack vectors we covered recently.


The CyberAv3ngers Playbook: Operation Unitronics


In early 2026, we saw the Iranian Government’s Islamic Revolutionary Guard Corps, operating under the moniker CyberAv3ngers, target US and UK water treatment facilities. Their specific target was the Israeli-developed Unitronics Vision Series Programmable Logic Controller (PLC).


Infographic titled THE CyberAv3ngers PLAYBOOK: OPERATION UNITRONICS shows a cyberattack on water plant PLCs, red alerts, and hackers.

The attack methodology was shockingly simple but highly effective:

  • Threat actors used automated scanners like Shodan to find Unitronics PLCs directly connected to the internet on default TCP port 20256.


  • Because administrators failed to set a basic password, the attackers gained immediate access via a blank password field.


  • They executed a denial of physical operation by wiping the legitimate ladder logic file from volatile memory and replacing it with a blank file, causing water pumps to immediately shut down.


  • To build a "digital barricade" and lock out defenders, they backdated the software version to create a version mismatch, disabled upload and download functions, generated a random password, and obfuscated the device's hostname.


  • Finally, they shifted the remote communication port from 20256 to 20257 and pushed an anti-Israel graphic file to the Human Machine Interface (HMI) screen.


The only remediation for operators was to physically walk to the plant floor and perform a hard factory reset to wipe the volatile memory.



The Handala Breach: The Pivot from Field Tools to Billing


We also tracked the Iranian hacktivist group "Handala" and their breach of the California Water Service (Cal Water).


Infographic of the Handala breach showing data flow from Cal Water field tools to billing server, PII stolen and 5 GB exfiltrated.

While Handala is linked to Iran's Ministry of Intelligence and Security (MOIS), they did not directly target the PLCs in this instance. Instead, they utilized an unexpected vector for initial access:


  • Attackers found an internet-exposed instance of RTKBase, an open-source platform used for managing high-precision GPS mapping of underground pipes and meters.


  • By compromising administrative credentials and NTRIP source passwords, Handala gained a foothold in the utility's geospatial infrastructure.


  • They maintained this access for over 700 hours (29 days) and laterally pivoted into the utility's billing environment.


  • The group successfully exfiltrated roughly 5 gigabytes of Personally Identifiable Information (PII), including customer names, addresses, and payment histories.


This incident is a textbook example of how state-sponsored actors find backdoors in ancillary, peripheral systems to bridge the gap into more sensitive environments.



The Minnesota and US Water Crisis: Mass Exploitation of Port 44818


Perhaps the most alarming incident occurred in late July 2026, when an attack forced more than 30 Minnesota community water systems to switch to 100% manual operations. This widespread event expanded to affect water and wastewater utilities in 12 states: Michigan, Wisconsin, South Dakota, New Jersey, and Georgia, with breaches acknowledged and others not released by investigators. This activity has prompted urgent joint warnings from the FBI, CISA, and EPA.


Technician in hard hat and hi-vis suit works on open PLC cabinet in a water plant; infographic text warns of digital lockout.

The anatomy of this attack highlights severe architectural flaws born of convenience:


  • The attackers targeted legacy Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs.


  • These controllers were left exposed to the public internet via cellular modems with open TCP port 44818.


  • Using unauthenticated Common Industrial Protocol (CIP) commands, the hackers rewrote the PLC IP configurations and updated administrative credentials in cleartext.


  • This severed the connection between the field controllers and the central SCADA servers, completely locking operators out of their automated systems.


In some cases, the attackers successfully modified the PLC ladder logic, resulting in a loss of system pressure and prompting municipalities to issue precautionary boil water advisories. Once again, the only remediation required operators to physically open the cabinet, remove the backup battery, and drain the volatile memory to execute a hard factory reset.


Please catch segments 1 and 2 in the CyberSecureOT podcast:  Minnesota Water Utilities Attack, Analog Devices Data Breach, GOLD EAGLE EO 14409


Correlating the Chaos: The Infracritical WICM


When managing a municipal water supply on a shoestring budget, you cannot rely on complex, heavy-lift IT solutions. To truly understand these threats, we must look at the objective data. Infracritical, an Operational Technology research group, recently published the Water Incident Correlation Matrix (WICM) in report IC-SCID-00150. 


Cybersecurity operations center with analysts at computers and a glowing WICM water-incident heatmap dashboard in blue and red.

The WICM tracks Tactics, Techniques, and Procedures (TTPs) against Target Fragility and Operational Impact. The data from these recent attacks reveals exactly how fragile our infrastructure is:


  • Access Vector: The matrix glows red around "Exposed Cellular Gateways" and "Default Credentials".


  • Asset Fragility: Unpatched, legacy Rockwell MicroLogix controllers sitting on the public internet scored a maximum fragility rating of 5.


  • Operational Consequence: Because attackers successfully modified PLC ladder logic to cause a loss of system pressure, the physical impact was rated as "Critical".


Securing the Future


Municipal budgets are stretched thin, but we must implement architecture that is Cost-effective, Operational, Reliable, and Efficient. The defense strategy isn't rocket science, but it requires strict discipline:


  1. Pull PLCs off the public internet. There can be no exceptions for contractor convenience.

  2. Enforce network segmentation. Basic segmentation between the IT enterprise, HMI layer, and Level 1 control networks prevents attackers from pivoting.

  3. Update your credentials. Change all default passwords and disable unused protocols or services on field devices.

  4. Implement OT-aware firewalls and VPNs with multi-factor authentication if remote access is absolutely required.


The threat actors are scanning for these vulnerabilities right now. It is time we start closing the doors.


Securing our municipal water systems is a monumental task, but it is entirely achievable when we commit to the C.O.R.E. methodology, building defenses that are Cost-effective, Operational, Reliable, and Efficient. The threat landscape is evolving rapidly, but the fundamentals of strong, practical architecture remain our best barricade against these state-sponsored adversaries.


Thank you for reading this week's breakdown. Be sure to tune in to the CyberSecureOT podcast for further deep dives into critical infrastructure protection, and keep an eye on the blog for ongoing intelligence updates.



— Dennis Hackney, Ph.D. OT Cybersecurity Leader | Creator of CORE | Host of CyberSecureOT


 Transparency Statement: AI tools were utilized to assist in drafting and structuring portions of this article, image, and video generation. The author maintains full responsibility for the final content and its intended message. This content is provided for informational purposes only and does not constitute formal professional or legal advice.

 
 
 

Comments


SIGN UP AND STAY UPDATED!

Thanks for submitting!

    © 2026 by CyberSecureOT

    bottom of page