CyberAv3ngers — a hacking group affiliated with Iran’s Islamic Revolutionary Guard Corps — has a documented history of attacking water and wastewater systems in the United States and Israel using the exact same methods employed in this week’s attacks. CISA has issued multiple formal advisories about this group and these specific vulnerabilities. The pattern is established, documented, and now apparently active at a new scale.

THE DOCUMENTED TRACK RECORD
📅 NEWS EVOLUTION
2023: CyberAv3ngers attacks water facilities in Pennsylvania and elsewhere using Unitronics PLCs; CISA issues formal advisory on the group and the specific device vulnerability
Late 2023: CISA advisory expanded; group also targets Israeli water infrastructure using identical techniques
2024: CISA issues follow-up advisory confirming continued CyberAv3ngers activity against water and wastewater ICS targets; Unitronics PLCs remain primary attack vector
Feb 28, 2026: US-Iran war begins; CyberAv3ngers-style operations expected to escalate
Aug 1–2, 2026: Coordinated attack on 30+ Minnesota facilities and 6+ additional states — same PLC category, same technique, unprecedented scale
THE TECHNICAL PATTERN
CyberAv3ngers’ modus operandi is consistent across all documented incidents: they target Unitronics Vision Series programmable logic controllers — industrial devices that control water treatment processes. The attack method involves exploiting remote access capabilities, changing device passwords and IP addresses to lock out legitimate operators, and in some cases modifying operational parameters.
The consistency is significant from an attribution standpoint. The same device, the same technique, the same target sector, now at a dramatically larger scale during an active US-Iran military conflict. Professional attribution requires certainty that ONYX will not assert. But the pattern is what CISA has documented across three years of advisories.
WHY CISA KNEW AND ATTACKS HAPPENED ANYWAY
CISA issued advisories in 2023 and 2024. The attacks happened again in 2026. Why? Because advisories require implementation. A federal advisory telling water utilities to patch their Unitronics PLCs is only effective if: the utility has staff who know how to do it, the utility has budget to implement it, the utility has time to take systems offline for updates without disrupting water service, and someone is following up to verify implementation. For small rural utilities — exactly the kind targeted in Minnesota — none of these conditions are reliably met.
CISA’s budget cuts under DOGE reduced its capacity for follow-up, coordination, and implementation assistance to exactly the category of small utility most vulnerable to exactly this kind of attack. The advisory existed. The vulnerability persisted. The attack occurred.
| CONFIDENCE: HIGH | CyberAv3ngers’ track record is from CISA official advisories, published and publicly available. Unitronics PLC as the attack vector is from CISA technical documentation. Attribution to CyberAv3ngers specifically for the August 2026 attacks is not confirmed — ONYX documents the pattern without asserting attribution for this specific incident. |
| ⚖️ BIAS CHECK — WHO IS SAYING WHAT | |
| CISA | Track record of warning is documented; now explaining why warnings weren’t sufficient without budget and staff to support implementation |
| Cybersecurity Researchers | Strong pattern match between documented CyberAv3ngers TTPs and August 2026 attack methods |
| Trump Administration | Avoiding CISA/CyberAv3ngers connection to preserve political messaging about governor’s incompetence |
| Democrats | Pointing to CISA advisory history as evidence that the threat was known and the defense was defunded |
| Water Utilities Industry | Documenting the gap between receiving CISA advisories and having resources to implement them |
SOURCES
▸ CISA 2023 advisory — CyberAv3ngers and Unitronics PLCs, documented attack pattern
▸ CISA 2024 advisory — follow-up on continued ICS targeting by Iran-affiliated groups
▸ CISA — “significant increase” advisory, August 2026
▸ SecurityWeek — technical analysis of attack method consistency

