A cyberattack on the Municipal Water Authority of Aliquippa in Pennsylvania exposed a broader campaign targeting Unitronics Vision Series PLCs used in water and wastewater operations. Attackers linked to the pro-Iran Cyber Av3ngers group reportedly defaced facility screens and disrupted a remote water pressure station, prompting operators to take affected equipment offline and switch to manual or backup processes; officials said drinking water quality and core service were not affected because the compromised system was isolated from the main treatment plant. Reporting also cited a separate incident at a North Texas utility, underscoring concern that internet-exposed industrial control systems are being actively targeted across the sector.
U.S. and Irish authorities later tied similar activity to exploitation of weakly secured or internet-accessible Unitronics controllers, including default or poor password practices and the vulnerability tracked as CVE-2023-6448, which was added to CISA's Known Exploited Vulnerabilities catalog. In Ireland, attackers disrupted water service to about 160 households in County Mayo after compromising a PLC at a private group water scheme. CISA warned water operators to remove PLCs from direct internet exposure, change default credentials, enforce multifactor authentication where possible, and back up device configurations as officials and experts warned that undersecured operational technology poses an ongoing risk to critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Reporting linked the County Mayo outage to the pro-Iran Cyber Av3ngers group, which had targeted Israeli-made Unitronics devices elsewhere. The incident aligned with international concern over exploitation of Unitronics Vision Series PLCs and references to CVE-2023-6448 being added to CISA's Known Exploited Vulnerabilities catalog.
A cyberattack disrupted water service for about 160 households in the Erris area of County Mayo, Ireland, after attackers exploited a vulnerability in a programmable logic controller used by a private group water scheme. Irish authorities said the incident was part of a broader global exploitation campaign rather than necessarily a targeted attack on Ireland.
Further reporting indicated the Cyber Av3ngers group had hacked industrial controllers in multiple U.S. states, expanding the apparent scope of the activity beyond isolated incidents. The campaign reinforced concerns about insecure internet-connected industrial control systems.
Reporting on CISA's warning noted a separate cyber incident affecting a North Texas utility serving about 2 million people. While no confirmed link to Unitronics PLCs was established, the disclosure marked a broader escalation of concern beyond the Aliquippa case.
CISA issued an alert that threat actors were actively exploiting internet-exposed Unitronics Vision Series PLCs used in water and wastewater systems. The agency cited weak password practices and direct internet exposure as likely intrusion paths and urged mitigations including changing default passwords, enabling MFA, removing PLCs from the public internet, and backing up configurations.
Federal authorities began assisting the investigation into the Aliquippa water utility intrusion, and public officials including Rep. Chris Deluzio said they were monitoring the situation. The incident drew broader attention to cybersecurity risks facing U.S. water utilities.
Attackers displayed a message associated with the pro-Iran Cyber Av3ngers group on screens at the compromised Aliquippa facility, suggesting ideological targeting of Israeli-made technology. The affected pump system was reportedly isolated from the primary network and physically separate from the main treatment plant.
The Municipal Water Authority of Aliquippa in Pennsylvania suffered a cyberattack affecting a remote water pressure station that used Unitronics equipment. Operators took the affected system offline and used backup/manual processes, while officials said drinking water quality and overall service were not impacted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcescworld.com
Open sourcecybersecuritydive.com
Open sourcetherecord.media
Open sourcetherecord.media
Open sourcecnn.com
Open sourcetherecord.media
Open sourcecbsnews.com
Open sourcecbsnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.