News Room
16
Share
Iranian-Linked 'Cyber Av3ngers' Escalate CNI Campaign: UK Power Plant and US Water Utilities Under Siege
criticalCritical Infrastructure

Iranian-Linked 'Cyber Av3ngers' Escalate CNI Campaign: UK Power Plant and US Water Utilities Under Siege

Recent intelligence confirms a coordinated surge in OT-targeted attacks by Iranian-linked actors, resulting in a multi-day outage at a UK power facility and disruptions across 12 US water systems.

30 August 2026Last updated 30 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global (UK/US focus)
Confidence:
High Confidence
Source:
Mandiant
Read Time:
5 min

Executive Summary

Over the past 48 to 72 hours, intelligence reports from the UK National Cyber Security Centre (NCSC) and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have confirmed a significant escalation in cyber operations targeting Critical National Infrastructure (CNI). A major UK power plant was forced offline for four days following a suspected Iranian-linked intrusion, while the number of U.S. states reporting water utility disruptions has risen to twelve. These incidents represent a shift from simple data exfiltration to the active manipulation of Operational Technology (OT) and Industrial Control Systems (ICS), specifically targeting internet-connected Programmable Logic Controllers (PLCs).

Threat Analysis

The current campaign is characterized by a high degree of coordination and a focus on the 'long, undefended tail' of critical infrastructure—smaller, municipal-level utilities that lack the robust security budgets of national providers. In the UK, the attack on a small-scale generator highlights vulnerabilities in the decentralized energy market. In the U.S., utilities in Minnesota, Washington, and New Jersey have reported pressure loss and flooding caused by unauthorized access to human-machine interfaces (HMIs). The primary objective appears to be psychological impact and operational disruption rather than long-term espionage, likely in retaliation for recent geopolitical developments involving Western support for regional adversaries.

Technical Details

Technical analysis of the recent breaches reveals the use of AI-generated scripts to automate the discovery and exploitation of Siemens S7 and Unitronics Vision-series PLCs. Attackers are leveraging default credentials and known vulnerabilities in web-facing OT interfaces. Once access is gained, the actors deploy custom payloads designed to modify logic parameters, such as chemical dosing levels in water systems or turbine synchronization in power plants. A joint advisory from the NSA and FBI notes that the actors are increasingly using AI to refine their phishing lures and to generate code that bypasses traditional signature-based detection systems. The use of 'living-off-the-land' (LotL) techniques, such as abusing legitimate administrative tools like PowerShell and SSH, has also been observed to maintain persistence within the OT environment.

Attribution Assessment

With high confidence, Encrygma attributes these activities to Iranian-affiliated threat actors, specifically groups operating under the 'Cyber Av3ngers' persona, which is believed to be linked to the Islamic Revolutionary Guard Corps (IRGC). The TTPs (Tactics, Techniques, and Procedures) align with previous Iranian operations, including the targeting of Israeli-made technology and the use of hacktivist-style messaging on social media to amplify the perceived impact of the attacks. While the actors claim to be independent hacktivists, the sophistication of the PLC-specific payloads and the timing of the operations suggest state-level direction and support.

Implications

The successful disruption of a UK power plant marks a dangerous precedent for the energy sector. It demonstrates that even small-scale facilities can be leveraged to create regional instability. For the water sector, the widening scope of attacks across 12 U.S. states indicates a systemic vulnerability in municipal infrastructure. If these attacks continue to evolve, there is a high risk of cascading failures where the loss of power or water impacts transportation and healthcare services. Furthermore, the integration of AI into the attacker's toolkit significantly lowers the barrier to entry for complex OT exploitation.

Recommendations

Encrygma recommends that all CNI operators immediately implement the following measures:

  1. Network Segmentation: Ensure that OT networks are physically or logically isolated from IT networks and the public internet.
  2. Credential Hardening: Change all default passwords on PLCs, HMIs, and gateway devices; implement multi-factor authentication (MFA) for all remote access points.
  3. Anomaly Detection: Deploy OT-specific monitoring solutions capable of detecting unauthorized changes to PLC logic or unusual traffic patterns on industrial protocols.
  4. Incident Response: Review and exercise incident response plans, specifically focusing on manual override procedures for critical processes in the event of a total HMI failure.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo