Friday, August 07, 2026

Well known Hackers with ties to Iran Hit Water Systems in 12 US States since March 2026

Bad news! Very concerning!

Maybe future wars will not be so bloody anymore as far as the military is concerned, but more devastating if not dangerous to the civilian population.

"Cyberattacks have hit water and wastewater systems in at least 12 states, officials say, with an Iran-linked hacking group suspected of trying to disrupt American infrastructure as the war drags on.

The self-proclaimed “CyberAv3ngers,” which cybersecurity experts tie to Iran’s Revolutionary Guard, locked administrators out of more than 30 systems in Minnesota alone and blocked water from being pumped into towers. No supplies were harmed, but sources say hackers could have reached chemical dosing controls.

President Trump doubted Iran’s involvement, instead blaming “grossly incompetent” Minnesota leaders after an attack shut down a water plant there. ..."

"... The Federal Bureau of Investigation (FBI) and U.S. Environmental Protection Agency (EPA) stated in their July 30 joint public service announcement (Alert: I-073026-PSA) that since July 27, 2026, water and wastewater utilities in at least seven states had reported incidents, and that some of that activity had "degraded water operations." The FBI stated that reported operational effects have included pressure loss and flooding, and identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as the targeted devices. The PSA does not attribute the activity to any specific actor, referring only to "malicious cyber actors." ...

How has CyberAv3ngers evolved over time?

CyberAv3ngers has demonstrated a deliberate capability escalation across four documented phases:

In Phase One (2020–2022), the group operated as a propaganda persona, claiming responsibility for infrastructure disruptions in Israel that were later assessed as fabricated. DomainTools Investigations demonstrated that several claims reused imagery from earlier data leaks.

In Phase Two (October 2023–January 2024), the group compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting default passwords on internet-exposed devices. The Municipal Water Authority of Aliquippa, Pennsylvania, was the highest-profile victim.

In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices. OpenAI disclosed in October 2024 that CyberAv3ngers had used ChatGPT to assist with target reconnaissance and code debugging.

In Phase Four (March 2026 to present), the group pivoted to exploiting CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers. Actors connected to internet-facing PLCs from foreign hosting providers using the same manufacturer engineering software (Studio 5000 Logix Designer) that legitimate operators use. Once connected, they downloaded and modified controller project files and altered operator display data. The July 22 advisory update expanded the manufacturer scope to include Schneider Electric and Siemens PLCs alongside Rockwell Automation. ..."

Wednesday, August 5, 2026 - Join The Flyover



No comments: