Guest Post: Why are hackers suddenly obsessed with America’s water systems?

By Stefanie Schappert

Cyberattacks on water and wastewater systems have surfaced across at least 12 US states since July 26th.

The FBI and CISA are increasingly pointing to the CyberAv3ngers, an Iranian-linked threat group backed by the Islamic Revolutionary Guard Corps (IRGC).

And while fresh attacks are being reported daily by local municipalities across the country, the bigger question isn’t where or when the next strike takes place – it’s why America’s water infrastructure has become such an attractive target in the first place.

Water is the perfect target

Water occupies a unique place in America’s critical infrastructure. Every community depends on it, and unlike many other public services, there is no alternative if the systems providing it are compromised. 

And creating uncertainty around an essential public service can be just as valuable as causing the disruption itself. 

Attackers don’t have to poison a water supply or leave an entire city without service to achieve an effect. They just have to make people wonder:

  • Is my drinking water safe?
  • Could someone shut off my town’s water?
  • How vulnerable is the infrastructure I rely on every day?

Even an unsuccessful attempt at disruption can shake public trust – and with headlines that stretch across the internet, the psychological effect can reverberate across an entire nation.

Built to be breached 

Over 50,000 drinking water and wastewater systems operate across the US, many serving small communities with limited cybersecurity resources and insecure technology. 

Many facilities still rely on internet-connected industrial control systems for remote management, creating a large and diverse attack surface.

CyberAv3ngers have found the perfect weakness in these systems: unpatchable PLC devices.

The programmable logic controller (PLC) is essentially an internet-facing computer used to automate facility operations, serving as one of the main components of SCADA systems across critical infrastructure. 

CyberAv3ngers – at first just a hacktivist group – began zeroing in on Unitronics PLC devices back in 2023, simply because its software was made in Israel.

By 2025, CyberAv3ngers had expanded to target the more commonly used Rockwell Automation PLCs, exploiting an authorization bypass vulnerability that can never be patched. 

Defenders have little recourse, while the FBI warns operators to proactively rely on defense-in-depth security measures in the absence of a permanent fix.

The water playbook evolves 

CyberAv3ngers first gained attention by defacing Israeli-made PLCs with pro-Iran messages before evolving into an IRGC-linked threat actor that developed its own strain of industrial malware, IOControl.

According to researchers, that malware has now been disseminated to at least 60 Iran-affiliated hacking groups, making threats against our water supply far less predictable. 

Instead of tracking one actor’s tactics, techniques, and procedures (TTPs), system defenders may be facing dozens of groups capable of utilizing the same underlying toolkit to modify and deploy new iterations of the malware. 

And that can leave security teams in the dark about what to look out for and how to harden systems against any one threat.   

Researchers have also documented the group’s recent use of AI tools – specifically ChatGPT – for code debugging and research, suggesting that CyberAv3ngers and its targeted malware could become even more sophisticated and stealthy as they continue to evolve. 

ABOUT THE EXPERT

Stefanie Schappert, a senior journalist at Cybernews, is an accomplished writer with an M.S. in cybersecurity, immersed in the security world since 2019.  She has a decade-plus experience in America’s #1 news market working for Fox News, Gannett, Blaze Media, Verizon Fios1, and NY1 News.  With a strong focus on national security, data breaches, trending threats, hacker groups, global issues, and women in tech, she is also a commentator for live panels, podcasts, radio, and TV. Earned the ISC2 Certified in Cybersecurity (CC) certification as part of the initial CC pilot program, participated in numerous Capture-the-Flag (CTF) competitions, and took 3rd place in Temple University’s International Social Engineering Pen Testing Competition, sponsored by Google.  Member of Women’s Society of Cyberjutsu (WSC), Upsilon Pi Epsilon (UPE) International Honor Society for Computing and Information Disciplines.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading