
Iranian-Linked 'CyberAv3ngers' Expand Water Infrastructure Campaign Across Nine U.S. States
A coordinated cyber campaign targeting Rockwell Automation PLCs has expanded to water utilities in nine U.S. states, causing operational disruptions and prompting urgent federal warnings.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- APT
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
Over the past 48 hours, intelligence reports from federal agencies and private security firms have confirmed that the cyber campaign targeting U.S. water and wastewater systems (WWS) has expanded significantly. Initially detected in late July 2026, the activity has now impacted utilities in at least nine states, including recent confirmed breaches in Oregon, Alabama, and New Jersey. The actors, operating under the 'CyberAv3ngers' persona, are exploiting internet-facing Programmable Logic Controllers (PLCs) to disrupt operations and display political messaging. While many attacks have been limited to defacement of Human-Machine Interfaces (HMIs), recent incidents in at least two states have resulted in the actual degradation of water treatment operations, necessitating a shift to manual controls.
Threat Analysis
The campaign represents a strategic shift by Iranian-affiliated actors toward high-visibility, low-complexity attacks on critical infrastructure. By targeting the WWS sector, which often lacks the robust cybersecurity resources of the energy or financial sectors, the adversary achieves maximum psychological impact with minimal technical effort. The primary goal appears to be the demonstration of capability and the creation of public distrust in municipal services. Unlike ransomware groups, these actors are not seeking financial gain but are instead focused on geopolitical signaling and domestic disruption within the United States.
Technical Details
The attackers are specifically targeting Rockwell Automation/Allen-Bradley PLCs that are directly accessible via the public internet. The primary vector involves the exploitation of default administrative credentials and the lack of multi-factor authentication (MFA) on HMIs. Once access is gained, the actors have been observed altering setpoints, disabling alarms, and in some cases, causing the physical degradation of water treatment processes. Recent telemetry indicates the use of automated scanning tools to identify devices with port 44818 (EtherNet/IP) exposed. In the Oregon incident, the attackers successfully bypassed a legacy firewall that had not been updated in three years, highlighting the persistent risk of end-of-life (EOL) equipment in OT environments.
Attribution Assessment
While the actors use the 'CyberAv3ngers' moniker, technical overlaps in infrastructure and TTPs (Tactics, Techniques, and Procedures) strongly suggest a link to the Iranian Revolutionary Guard Corps (IRGC). The timing of the attacks and the specific targeting of Western-manufactured industrial equipment align with previous IRGC-linked operations. The use of propagandistic messaging on compromised HMIs further supports the assessment of a state-sponsored influence operation rather than a purely criminal endeavor.
Implications
The continued success of these attacks highlights a systemic vulnerability in the U.S. water sector. The degradation of water operations poses a direct threat to public health and fire safety. Furthermore, the ability of a foreign adversary to reach into small-town America and manipulate physical infrastructure serves as a potent tool for geopolitical leverage. If these vulnerabilities are not addressed, we anticipate similar campaigns targeting other under-resourced sectors, such as local transportation and emergency services.
Recommendations
Encrygma recommends that all OT operators immediately audit their networks for internet-facing PLCs. Critical steps include: 1. Disconnecting all industrial control systems from the public internet and utilizing secure VPNs for remote access. 2. Implementing robust password policies and immediately changing all default credentials. 3. Deploying hardware-based MFA for all remote access points. 4. Maintaining offline, verified backups of PLC configurations to ensure rapid recovery. 5. Enrolling in CISA’s free vulnerability scanning service to identify exposed assets before adversaries do.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

US Rewards $10M as Iranian Cyber Actors Target Critical Water and Energy Industrial Control Systems

Global Ransomware Surge Hits Record High as Critical Infrastructure Resilience Initiatives Accelerate

