CyberAv3ngers compromised a Unitronics PLC/HMI at the Municipal Water Authority of Aliquippa, Pennsylvania, in November 2023, disrupting equipment used to monitor and regulate water pressure and defacing the controller. The utility took the affected system offline and switched to manual operations; officials reported no known risk to drinking water or the water supply. Microsoft subsequently attributed the attack to the Iranian Islamic Revolutionary Guard Corps-affiliated group it tracks as Storm-0784. The attackers apparently selected the Israeli-manufactured equipment because of its origin. Similar attacks targeted Unitronics devices internationally, while Microsoft also observed pro-Russian actors targeting poorly secured water-sector systems.
CISA assessed that weak passwords and direct internet exposure likely enabled access, but neither its initial reporting nor Microsoft’s analysis conclusively established the precise compromise mechanism. CISA warned that actors were probing TCP port 20256 and using PCOM/TCP-specific scripts to identify Unitronics controllers. Unitronics issued a patch addressing the default-password vulnerability CVE-2023-6448; the reporting does not establish that this vulnerability was the attack vector. Operators should remove PLCs from direct internet access, replace default credentials, require MFA for remote access, deploy firewall/VPN controls, segment OT networks, and update PLC/HMI firmware. Backing up controller logic and configurations and preparing manual-operation and recovery procedures can limit disruption if a controller is compromised.

See the actors and campaigns active against you right now.
13 events from the most recent confirmed update back to the earliest known activity.
A CISA advisory described additional water-sector attacks involving pro-Russian actors targeting internet-exposed OT systems with weak passwords.
Pro-Russian hacktivists targeted U.S. water and wastewater systems in early 2024. The attacks involved internet-exposed operational technology systems protected by weak passwords.
Other Unitronics systems were reportedly attacked internationally around the November 2023 Aliquippa incident. Compromised devices displayed a message declaring Israeli-made equipment a CyberAv3ngers target.
A late-November attack on Pennsylvania’s Municipal Water Authority of Aliquippa compromised a Unitronics PLC-HMI and caused a pressure-regulation pump outage. The device displayed CyberAv3ngers branding, and the group claimed responsibility.
Microsoft used internet-device search engines, geographic information, and metadata including the PLC name “Raccoon Primary PLC” to identify a system it assessed was likely the Aliquippa victim. The identification was contextual rather than a conclusively confirmed forensic finding.
The U.S. Department of the Treasury sanctioned officials in the IRGC Cyber-Electronic Command in connection with the Aliquippa attack.
Unitronics issued a patch requiring users to address the default-password issue associated with CVE-2023-6448.
Following the incidents, the Unitronics default-password configuration issue was assigned CVE-2023-6448. The references do not conclusively establish the precise compromise mechanism in the Aliquippa attack.
Full Pint Beer reported on X that its brewery control system suffered a cyberattack. Restoration efforts involved Brewmation and backups, extending the reported impact beyond public infrastructure.
CISA updated its guidance to advise installing the latest Unitronics PLC/HMI versions and referenced Unitronics Cybersecurity Advisory 2023-001.
A joint cybersecurity advisory described IRGC-affiliated actors exploiting PLCs across multiple sectors, including U.S. water and wastewater facilities. Microsoft reports that CISA attributed the Aliquippa attack to IRGC-affiliated CyberAv3ngers.
CISA warned of active exploitation of Unitronics PLCs in the water sector and assessed that weak passwords and internet exposure likely enabled access. The alert urged operators to replace default credentials, restrict remote access, and remove direct internet exposure.
The affected water authority took the compromised system offline and switched to manual operations. The utility and CISA stated that there was no known risk to the drinking water or water supply.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourcesecurityweek.com
Open sourcecisa.gov
Open sourceincibe.es
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.