News Room
16
Share
Iranian-Linked Cyber Campaign Expands to Water Utilities in 12 States, Prompting Federal Emergency Response
highCritical Infrastructure

Iranian-Linked Cyber Campaign Expands to Water Utilities in 12 States, Prompting Federal Emergency Response

A coordinated cyber campaign targeting internet-exposed PLCs has disrupted water operations across 12 U.S. states. Federal agencies warn of escalating Iranian-linked activity aimed at critical infrastructure.

13 August 2026Last updated 18 August 20264 min readCISA/FBI Joint Advisory
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
High
Actor Type:
Nation-State
Geography:
North America
Confidence:
Confirmed
Source:
CISA/FBI Joint Advisory
Read Time:
4 min

Executive Summary

Over the last 48 hours, intelligence reports from CISA and the FBI have confirmed that the cyber campaign targeting U.S. water and wastewater systems (WWS) has expanded significantly. Initially identified in late July 2026, the attacks have now impacted utilities in at least 12 states, including New Jersey, Georgia, and Minnesota. The campaign specifically targets internet-exposed industrial control systems, leading to operational disruptions and, in some cases, the issuance of boil water advisories due to loss of pressure control. This activity represents a significant escalation in the targeting of U.S. municipal infrastructure by foreign adversaries.

Threat Analysis

The threat actors are systematically scanning the public internet for specific Programmable Logic Controllers (PLCs) used in water treatment and distribution. The primary targets are Unitronics Vision-series PLCs, which are often deployed in smaller municipal environments. The attackers exploit the fact that many of these devices are connected directly to the internet without a firewall or VPN, often retaining factory-default credentials. Once access is gained, the actors manipulate the Human-Machine Interface (HMI) to display political messages or alter operational parameters, such as pump speeds and chemical dosing levels.

Technical Details

Technical analysis of the incidents reveals that the attackers are targeting port 20256, which is associated with the PCOM protocol used by Unitronics devices. By sending crafted packets to this port, the actors can gain unauthorized access to the PLC's memory and logic. In recent incidents in Georgia and New Jersey, the attackers successfully modified the HMI screens to display anti-American and pro-Iranian messaging. More critically, the manipulation of pressure sensors led to automated system shutdowns, causing significant drops in water pressure across municipal grids. Forensic evidence suggests the use of automated scripts to identify and compromise these devices at scale.

Attribution Assessment

CISA, the FBI, and private sector intelligence firms like Mandiant have attributed this campaign with high confidence to Iranian-affiliated advanced persistent threat (APT) groups, specifically those operating under the 'Cyber Av3ngers' persona. This group has a history of targeting Israeli-made technology, and Unitronics is an Israel-based company. The timing and nature of the attacks suggest they are a response to ongoing geopolitical tensions. While the group presents itself as a hacktivist collective, their technical capabilities and coordinated nature align with state-sponsored objectives aimed at demonstrating the vulnerability of Western critical infrastructure.

Implications

The success of this campaign highlights a critical vulnerability in the U.S. water sector: the prevalence of 'security through obscurity' and the lack of basic cybersecurity hygiene in smaller utilities. The operational disruptions, while not yet resulting in water contamination, pose a direct threat to public health and fire safety due to pressure loss. Furthermore, the ability of a foreign adversary to simultaneously impact utilities across 12 states demonstrates a level of reach that could be leveraged for more destructive purposes in a future conflict.

Recommendations

Encrygma recommends that all OT/ICS operators immediately perform the following actions: 1. Audit all network perimeters to ensure no PLCs or HMIs are directly accessible from the public internet. 2. Change all default passwords on industrial equipment and implement strong, unique credentials. 3. Place all remote access behind a secure VPN with multi-factor authentication (MFA). 4. Implement the 'ICS Five Critical Controls,' including an ICS-specific incident response plan and a defensible architecture that segments OT networks from IT environments.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo