Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatindustrial-control-system-vulnerabilityhacktivist-operationactively-exploited-vulnerability

Cyber Av3ngers Exploited Unitronics PLCs at Water Utilities in the U.S. and Ireland

Updated 27d agoFirst seen Apr 2, 20269 sources

A cyberattack on the Municipal Water Authority of Aliquippa in Pennsylvania exposed a broader campaign targeting Unitronics Vision Series PLCs used in water and wastewater operations. Attackers linked to the pro-Iran Cyber Av3ngers group reportedly defaced facility screens and disrupted a remote water pressure station, prompting operators to take affected equipment offline and switch to manual or backup processes; officials said drinking water quality and core service were not affected because the compromised system was isolated from the main treatment plant. Reporting also cited a separate incident at a North Texas utility, underscoring concern that internet-exposed industrial control systems are being actively targeted across the sector.

U.S. and Irish authorities later tied similar activity to exploitation of weakly secured or internet-accessible Unitronics controllers, including default or poor password practices and the vulnerability tracked as CVE-2023-6448, which was added to CISA's Known Exploited Vulnerabilities catalog. In Ireland, attackers disrupted water service to about 160 households in County Mayo after compromising a PLC at a private group water scheme. CISA warned water operators to remove PLCs from direct internet exposure, change default credentials, enforce multifactor authentication where possible, and back up device configurations as officials and experts warned that undersecured operational technology poses an ongoing risk to critical infrastructure.

Share:
Cyber Av3ngers Exploited Unitronics PLCs at Water Utilities in the U.S. and Ireland
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Dec 11, 20233y ago

Irish incident tied to Cyber Av3ngers and broader Unitronics campaign

Reporting linked the County Mayo outage to the pro-Iran Cyber Av3ngers group, which had targeted Israeli-made Unitronics devices elsewhere. The incident aligned with international concern over exploitation of Unitronics Vision Series PLCs and references to CVE-2023-6448 being added to CISA's Known Exploited Vulnerabilities catalog.

Dec 9, 20233y ago

County Mayo water outage in Ireland linked to Unitronics exploitation

A cyberattack disrupted water service for about 160 households in the Erris area of County Mayo, Ireland, after attackers exploited a vulnerability in a programmable logic controller used by a private group water scheme. Irish authorities said the incident was part of a broader global exploitation campaign rather than necessarily a targeted attack on Ireland.

Dec 4, 20233y ago

Cyber Av3ngers campaign reported across multiple U.S. states

Further reporting indicated the Cyber Av3ngers group had hacked industrial controllers in multiple U.S. states, expanding the apparent scope of the activity beyond isolated incidents. The campaign reinforced concerns about insecure internet-connected industrial control systems.

Nov 29, 20233y ago

Second U.S. utility incident disclosed amid Unitronics concerns

Reporting on CISA's warning noted a separate cyber incident affecting a North Texas utility serving about 2 million people. While no confirmed link to Unitronics PLCs was established, the disclosure marked a broader escalation of concern beyond the Aliquippa case.

CISA warns of active exploitation of Unitronics PLCs

CISA issued an alert that threat actors were actively exploiting internet-exposed Unitronics Vision Series PLCs used in water and wastewater systems. The agency cited weak password practices and direct internet exposure as likely intrusion paths and urged mitigations including changing default passwords, enabling MFA, removing PLCs from the public internet, and backing up configurations.

Nov 27, 20233y ago

U.S. officials begin assisting Aliquippa cyberattack response

Federal authorities began assisting the investigation into the Aliquippa water utility intrusion, and public officials including Rep. Chris Deluzio said they were monitoring the situation. The incident drew broader attention to cybersecurity risks facing U.S. water utilities.

Nov 25, 20233y ago

Cyber Av3ngers message appears in Aliquippa incident

Attackers displayed a message associated with the pro-Iran Cyber Av3ngers group on screens at the compromised Aliquippa facility, suggesting ideological targeting of Israeli-made technology. The affected pump system was reportedly isolated from the primary network and physically separate from the main treatment plant.

Aliquippa water authority hit via Unitronics-connected pressure station

The Municipal Water Authority of Aliquippa in Pennsylvania suffered a cyberattack affecting a remote water pressure station that used Unitronics equipment. Operators took the affected system offline and used backup/manual processes, while officials said drinking water quality and overall service were not impacted.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Threat actors
1 linked
Organizations
4 linked
National Rural Water AssociationAmerican Water Works AssociationUnitronicsMunicipal Water Authority of Aliquippa
SOURCE COVERAGE

Sources

9 references tracked. Mallory keeps watching after this page renders.

9 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cyber Av3ngers Exploited Unitronics PLCs at Water Utilities in the U.S. and Ireland | Mallory