The Group Behind This Week’s Water Attacks Has Done This Before. Here’s Their Full Track Record.

CyberAv3ngers — a hacking group affiliated with Iran’s Islamic Revolutionary Guard Corps — has a documented history of attacking water and wastewater systems in the United States and Israel using the exact same methods employed in this week’s attacks. CISA has issued multiple formal advisories about this group and these specific vulnerabilities. The pattern is established, documented, and now apparently active at a new scale.

THE DOCUMENTED TRACK RECORD

📅 NEWS EVOLUTION

2023: CyberAv3ngers attacks water facilities in Pennsylvania and elsewhere using Unitronics PLCs; CISA issues formal advisory on the group and the specific device vulnerability

Late 2023: CISA advisory expanded; group also targets Israeli water infrastructure using identical techniques

2024: CISA issues follow-up advisory confirming continued CyberAv3ngers activity against water and wastewater ICS targets; Unitronics PLCs remain primary attack vector

Feb 28, 2026: US-Iran war begins; CyberAv3ngers-style operations expected to escalate

Aug 1–2, 2026: Coordinated attack on 30+ Minnesota facilities and 6+ additional states — same PLC category, same technique, unprecedented scale

THE TECHNICAL PATTERN

CyberAv3ngers’ modus operandi is consistent across all documented incidents: they target Unitronics Vision Series programmable logic controllers — industrial devices that control water treatment processes. The attack method involves exploiting remote access capabilities, changing device passwords and IP addresses to lock out legitimate operators, and in some cases modifying operational parameters.

The consistency is significant from an attribution standpoint. The same device, the same technique, the same target sector, now at a dramatically larger scale during an active US-Iran military conflict. Professional attribution requires certainty that ONYX will not assert. But the pattern is what CISA has documented across three years of advisories.

WHY CISA KNEW AND ATTACKS HAPPENED ANYWAY

CISA issued advisories in 2023 and 2024. The attacks happened again in 2026. Why? Because advisories require implementation. A federal advisory telling water utilities to patch their Unitronics PLCs is only effective if: the utility has staff who know how to do it, the utility has budget to implement it, the utility has time to take systems offline for updates without disrupting water service, and someone is following up to verify implementation. For small rural utilities — exactly the kind targeted in Minnesota — none of these conditions are reliably met.

CISA’s budget cuts under DOGE reduced its capacity for follow-up, coordination, and implementation assistance to exactly the category of small utility most vulnerable to exactly this kind of attack. The advisory existed. The vulnerability persisted. The attack occurred.

CONFIDENCE:
HIGH
CyberAv3ngers’ track record is from CISA official advisories, published and publicly available. Unitronics PLC as the attack vector is from CISA technical documentation. Attribution to CyberAv3ngers specifically for the August 2026 attacks is not confirmed — ONYX documents the pattern without asserting attribution for this specific incident.
⚖️  BIAS CHECK — WHO IS SAYING WHAT
CISATrack record of warning is documented; now explaining why warnings weren’t sufficient without budget and staff to support implementation
Cybersecurity ResearchersStrong pattern match between documented CyberAv3ngers TTPs and August 2026 attack methods
Trump AdministrationAvoiding CISA/CyberAv3ngers connection to preserve political messaging about governor’s incompetence
DemocratsPointing to CISA advisory history as evidence that the threat was known and the defense was defunded
Water Utilities IndustryDocumenting the gap between receiving CISA advisories and having resources to implement them

SOURCES

▸  CISA 2023 advisory — CyberAv3ngers and Unitronics PLCs, documented attack pattern

▸  CISA 2024 advisory — follow-up on continued ICS targeting by Iran-affiliated groups

▸  CISA — “significant increase” advisory, August 2026

▸  SecurityWeek — technical analysis of attack method consistency

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top