Resources / Perspective
What the attacks on U.S. water systems exploited
On the last weekend of July, water utilities in at least a dozen states lost remote control of wells, treatment plants, and lift stations in a coordinated wave of intrusions. In Braham, Minnesota, population around 1,700, well and treatment controls were down for about two hours. Plymouth lost the cellular equipment connecting its water towers and lift stations. Maple Plain declared a local emergency. Clayton County Water Authority in Georgia, which serves 300,000 people, was hit the same weekend, and Michigan reported nine affected systems. The FBI and EPA issued a joint public service announcement on July 30. Federal officials have not publicly attributed the wave to any specific actor, but the technique matches a campaign that six federal agencies have been documenting since April, and that campaign is attributed to Iranian-affiliated actors.
The record of these attacks now spans almost three years, and the most useful fact in it is one the headlines skip: none of the intrusions required a novel technique. Every one of them walked through a door that was already documented, in public, often for years. That changes what the right response looks like, and it is worth walking through the record to see why.
Three years, four federal advisories
In late November 2023, the Municipal Water Authority of Aliquippa, Pennsylvania found a message on the screen of the controller running one of its booster stations: “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is CyberAv3ngers legal target.” The station was switched to manual operation and water kept flowing. CISA, the FBI, NSA, EPA, and Israel’s National Cyber Directorate published a joint advisory, AA23-335A, attributing the activity to cyber actors affiliated with Iran’s Islamic Revolutionary Guard Corps operating under the CyberAv3ngers persona. The method required no exploit: the actors scanned for Unitronics Vision series controllers exposed to the internet on their default TCP port, 20256, and logged in with default passwords that had never been changed after installation. Similar compromises were confirmed at water systems across multiple U.S. states, and a small utility in County Mayo, Ireland reportedly lost water service for two days from the same campaign.
In February 2024, the U.S. Treasury sanctioned six officials of the IRGC Cyber-Electronic Command over the campaign, and the State Department offered a reward of up to $10 million for information on them. Later that year, researchers at Claroty documented a custom malware platform they named IOCONTROL, built by the same actors to run on embedded devices from multiple vendors: PLCs, HMIs, IP cameras, and fuel management systems. The group had moved from trying default passwords to building custom OT tooling.
In March 2026, CISA confirmed attackers were exploiting CVE-2021-22681, an authentication bypass in Rockwell Automation Logix controllers, and added it to the Known Exploited Vulnerabilities catalog. The vulnerability was disclosed in February 2021. It scores 9.8 out of 10, and there is no vendor patch; the published mitigations are architectural, starting with taking the controller off the internet. On April 7, six agencies (FBI, CISA, NSA, EPA, the Department of Energy, and U.S. Cyber Command) published AA26-097A, documenting Iranian-affiliated actors using it against controllers exposed to the internet at water, energy, and government facilities: downloading PLC project files, modifying logic, and manipulating operator displays, with operational disruption and financial loss at multiple U.S. organizations. The July 22 update extended the observed activity to Schneider Electric and Siemens controllers and documented exfiltration of project files, the control logic that describes how a plant runs.
Four days later came the July 26 wave. Whoever ran it, the doors it used were the ones the advisories had spent three years describing.
Every door was already documented
Across the whole record the entry points repeat: default passwords on controllers open to the internet, a vulnerability whose mitigations had been published five years earlier, cellular modems wiring remote sites straight to the public internet, and devices nobody at the utility knew were reachable from outside. Internet scans find thousands of exposed Rockwell devices in the U.S. alone. The targeting follows from that: these actors scan for whatever answers, so the victim list is whoever answered the scan, which is how a town of 1,700 ended up hit the same weekend as a system serving 300,000.
The gap between the advisory and the utility
Most commentary on these incidents ends with the standard checklist: disconnect PLCs from the internet, change default credentials, put remote access behind a gateway with multifactor authentication, set the physical key switch to run mode, keep offline backups of controller logic. That advice is correct, and it has appeared in substantially the same form in every federal advisory since 2023. EPA’s May 2024 enforcement alert reported that more than 70% of the community water systems it had inspected had violations of the Safe Drinking Water Act section 1433 requirements, the risk assessments and emergency response plans that have been federal law since 2018.
A small system runs on a handful of licensed operators who also fix mains, read meters, and answer the phone, so an advisory arrives as unassigned work for people who are already at capacity. Each line of the checklist is a task against a specific device: find every controller, establish whether it is reachable from the internet, change its credentials, verify the key switch, back up its logic, and then check all of it again next quarter, because this state drifts. A modem gets reconnected because manual rounds are tedious in January. A contractor sets a password back to something convenient. The difference between a utility that is exposed and one that is not usually comes down to whether that work was owned by a named person, finished by a date, recorded, and verified again, and whether anyone can prove it afterward.
Where Ithil fits
Ithil is an operations platform. It runs the work that advisories, integrators, and security tooling generate for a utility, and keeps the proof that the work happened.
When an advisory names specific hardware, the first question is “do we have any?” A current asset register answers it in minutes, by make, model, firmware, and site, instead of by a week of opening cabinets. Each mitigation becomes a work order against a specific asset, with an assignee, a due date, and completion evidence attached. Recurring inspections verify the state on a schedule, so the reconnected modem surfaces in the next round instead of in the next incident. And because work orders and inspections in Ithil are event sourced and hash chained, the record of what was done, by whom, and when is append-only: it can be handed to a state primacy agency, an insurer, or a city council as proof rather than recollection. After the July incidents, the utilities in the best position were the ones that could answer, from records, which mitigations were in place on which devices and when they were last checked.
Start with the advisories
If you operate a water or wastewater system, the place to start costs nothing: read AA26-097A and its July update, check your controllers against the device families it names, and enroll in CISA’s free vulnerability scanning for water systems and in WaterISAC’s advisories. Those steps are worth taking whatever software you run. If the part your utility is missing is the execution, turning that guidance into owned, scheduled, provable work, talk to us. That is the problem Ithil was built for.
