
criticalCritical Infrastructure
Iranian-Linked Cyberattacks Target Water Infrastructure Across 12 U.S. States; CISA Issues Emergency OT Guidance
Coordinated cyberattacks attributed to Iranian-affiliated actors have compromised water utilities in at least 12 states, including 30+ facilities in Minnesota. The campaign targets internet-exposed PLCs to disrupt automated controls.
07 August 2026Last updated 20 August 20264 min readCISA / Mandiant
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- Confirmed
- CVE:
- CVE-2026-61893
- Source:
- CISA / Mandiant
- Read Time:
- 4 min
Executive Summary\nAs of August 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have escalated their response to a series of coordinated cyberattacks targeting the Water and Wastewater Systems (WWS) sector across at least 12 U.S. states. This campaign, which gained significant momentum over the last 48 hours, has successfully compromised the operational technology (OT) of dozens of municipal utilities, most notably in Minnesota where over 30 community water systems reported unauthorized access. The attacks primarily target internet-exposed Programmable Logic Controllers (PLCs) used to regulate water pressure, temperature, and chemical distribution. While no immediate threats to water safety have been reported, the scale of the intrusion represents a significant escalation in nation-state activity against civilian critical infrastructure.\n\n## Threat Analysis\nThe current threat landscape is dominated by Iranian-affiliated actors who have demonstrated a sophisticated understanding of the U.S. water sector's reliance on legacy OT systems. These actors are not utilizing zero-day vulnerabilities but are instead performing wide-scale scanning for specific industrial hardware. The primary objective appears to be psychological impact and the demonstration of capability rather than immediate mass destruction. However, the ability to manipulate chemical dosing—such as sodium hydroxide levels—poses a latent kinetic risk to public health. The attackers have shown a preference for utilities with limited cybersecurity budgets, where OT systems are often directly connected to the internet for remote maintenance without the protection of a VPN or multi-factor authentication (MFA).\n\n## Technical Details\nThe technical vector involves the exploitation of Unitronics Vision-series PLCs and similar devices that utilize default administrative credentials (e.g., "1111"). Attackers are leveraging Shodan and Censys to identify exposed ports, specifically targeting TCP port 20256. Once access is gained, the actors deface the Human-Machine Interface (HMI) with political messaging and, in some instances, have attempted to alter setpoints for pump operations. Recent intelligence also suggests the potential use of vulnerabilities in the lib60870 library (CVE-2026-61893) to crash communication modules, leading to a denial-of-service (DoS) state for remote monitoring. This prevents operators from seeing real-time data, forcing a shift to manual operations. Furthermore, the "Bit2Watt" attack methodology is being monitored, where cloud-based GPU access is used to fluctuate power draws, though this has not yet been linked to the current water sector campaign.\n\n## Attribution Assessment\nWith high confidence, Encrygma attributes this campaign to the Iranian-linked group known as "Cyber Av3ngers," an affiliate of the Islamic Revolutionary Guard Corps (IRGC). This assessment is based on the specific targeting of Israeli-made technology (Unitronics), the use of familiar TTPs observed in previous 2023-2024 campaigns, and the distinct political signatures left on compromised HMIs. The timing of the escalation coincides with heightened regional tensions, suggesting the cyber operations are being used as a tool of asymmetric signaling against U.S. interests.\n\n## Implications\nThe implications of these attacks are twofold. First, they expose the systemic fragility of the U.S. water sector, which lacks the centralized regulatory oversight seen in the energy sector. Second, the successful compromise of 30+ utilities in a single state suggests a templated attack methodology that can be rapidly scaled. If these actors transition from defacement to active sabotage of filtration systems or pressure valves, the result could be significant physical damage to infrastructure or widespread water contamination.\n\n## Recommendations\nEncrygma recommends that all OT operators immediately implement the following: 1. Network Isolation: Remove all PLCs and HMIs from the public-facing internet. Use hardware-enforced unidirectional gateways where possible. 2. Credential Management: Change all default passwords on industrial controllers and implement strong, unique passwords for every device. 3. MFA Implementation: Require multi-factor authentication for all remote access to the OT environment via VPNs. 4. Integrity Checks: Regularly verify PLC ladder logic and setpoints against known-good configurations to detect unauthorized changes. 5. Incident Response: Conduct tabletop exercises specifically focused on manual override procedures for water treatment processes.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News RoomRelated Intelligence

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate
01 Oct 2026

Escalating Cyber-Physical Threats Target European and US Energy Grids
29 Sep 2026

Industrial Sector Faces Record Ransomware Surge as Qilin Group Targets Critical Infrastructure
30 Sep 2026
