The U.S. State Department offered up to $10 million for information on six Iranian government hackers allegedly linked to the Islamic Revolutionary Guard Corps Cyber-Electronic Command and the CyberAv3ngers campaign targeting Unitronics Vision Series PLCs used in critical infrastructure, including U.S. water utilities. U.S. officials said the group exploited internet-exposed devices with default credentials and, in late 2023, defaced compromised systems with anti-Israel messages while claiming the attacks were retaliation for Israel’s actions in Gaza.
One of the most visible incidents hit the Municipal Water Authority of Aliquippa, Pennsylvania, which temporarily shifted to manual operations after an intrusion reached a pressure-regulating pump, though officials said water treatment and safe drinking water were not affected. In response, CISA began directly contacting water utilities with exposed Unitronics devices and urged operators to change default passwords, while the FBI and EPA said only a small number of utilities were known to be impacted but warned that exposed PLCs could provide a foothold for deeper network access and potential physical damage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The U.S. State Department identified six Iranian government hackers allegedly tied to the IRGC Cyber-Electronic Command and offered up to $10 million for information on their whereabouts. The officials were accused of involvement with CyberAv3ngers and attacks on Unitronics devices used by U.S. water utilities and other critical infrastructure.
CISA said it was identifying water utility operators with internet-exposed Unitronics devices and notifying them to reduce cyberattack risk. The agency urged operators to change default passwords and harden exposed systems.
U.S. officials said only a small number of water utilities were known to be impacted and that they had seen no access to operational water systems or disruption to safe drinking water. They warned that exposed PLCs could still provide a foothold for deeper network access and possible physical damage.
In October 2023, the CyberAv3ngers campaign became public when the group claimed the attacks were retaliation for Israel’s actions in Gaza and defaced compromised devices with anti-Israel messages. The claims drew attention to the use of exposed Unitronics controllers in U.S. critical infrastructure.
The Municipal Water Authority of Aliquippa in Pennsylvania was affected by an intrusion involving a Unitronics Vision series controller, prompting the utility to take systems offline and switch to manual operations. Officials said the compromise reached a pressure-regulating pump but did not affect water treatment or safe drinking water.
U.S. officials said the Iran-linked group had been compromising default credentials on internet-exposed Unitronics programmable logic controllers since at least 2023-11-22. The activity targeted devices used in critical infrastructure, including water utilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.