A hacking group tied to Iran’s Islamic Revolutionary Guard Corps quietly compromised critical infrastructure across the United States — oil and gas operations, water utilities, and other industrial sites — using a surprisingly simple playbook: targeting devices that shipped with default passwords nobody ever bothered to change.
The group calls itself CyberAv3ngers. U.S. federal agencies and intelligence partners have now laid out in stark detail just how far the group penetrated, and the picture isn’t reassuring for anyone responsible for keeping American infrastructure running.
According to a joint advisory issued by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and partner agencies from Israel, Canada, Australia, and the United Kingdom, the CyberAv3ngers targeted programmable logic controllers and other operational technology devices manufactured by Israeli company Unitronics, as well as equipment from other vendors. The advisory, first reported on by Slashdot, details a campaign stretching back to at least late 2023 that hit infrastructure in multiple U.S. states and several other countries.
The attackers didn’t need sophisticated zero-day exploits. They didn’t deploy novel malware engineered in a state-sponsored lab. They walked through the front door — scanning the internet for Unitronics Vision and Samba series PLCs still running factory-default credentials. That’s it.
And it worked.
The Municipal Water Authority of Aliquippa, Pennsylvania, was one of the first confirmed victims. In November 2023, the group gained access to a Unitronics PLC controlling a booster station that regulates water pressure. The compromised device displayed an anti-Israel message, making the intrusion immediately visible. But the implications ran deeper than vandalism. The attackers had access to equipment that could, in theory, manipulate physical processes — pumps, valves, chemical dosing systems — in ways that could endanger public health.
That incident triggered alarm bells across the federal government. CISA issued an initial alert in December 2023 urging water and wastewater utilities to immediately change default passwords on Unitronics PLCs and disconnect them from the public internet. Many operators apparently didn’t listen — or didn’t move fast enough.
The expanded advisory reveals CyberAv3ngers went well beyond water systems. The group compromised devices at oil and gas facilities, though U.S. officials have not publicly identified the specific companies or sites affected. The advisory also notes intrusions at targets in Israel, where the political motivation is most obvious, and in other allied nations. The pattern was consistent: find internet-exposed industrial controllers, try default credentials, get in.
CyberAv3ngers has been linked by the U.S. Treasury Department to the IRGC’s Cyber-Electronic Command (IRGC-CEC). In February 2024, Treasury’s Office of Foreign Assets Control sanctioned six individuals allegedly associated with the group. The State Department’s Rewards for Justice program simultaneously offered up to $10 million for information leading to the identification or location of the hackers. That bounty remains active.
What makes this campaign particularly unsettling isn’t the sophistication of the attack. It’s the lack of sophistication required. Industrial control systems — the computers that operate physical machinery in water treatment plants, oil refineries, gas pipelines, and power stations — have long been the soft underbelly of American infrastructure. Many were designed decades ago, before cybersecurity was a serious consideration. They were meant to sit on isolated networks. They weren’t supposed to be connected to the internet at all.
But they are. Thousands of them.
Shodan, a search engine that indexes internet-connected devices, routinely reveals thousands of exposed industrial controllers across the United States. Researchers at Censys and other threat intelligence firms have documented the problem extensively. The devices are easy to find. And when they still carry factory-default passwords — “1111” was one common Unitronics default — they’re trivially easy to compromise.
The federal government has been warning about this for years. CISA’s advisories on operational technology security date back to its earliest days. The agency has published guidance, offered free assessments, and dispatched teams to help small utilities harden their systems. But many of these organizations — particularly small municipal water systems — operate on shoestring budgets with minimal IT staff. Changing a default password sounds simple. In practice, it requires someone to know the password needs changing, understand how to access the device’s configuration, and ensure the change doesn’t disrupt operations. For a rural water district with two employees, that’s not always straightforward.
The oil and gas sector presents a different set of challenges. Larger companies generally have more resources for cybersecurity, but the sector’s sprawling supply chain means countless smaller contractors, field operators, and remote sites may run outdated equipment with minimal oversight. A single compromised PLC at a remote pumping station could, under the wrong circumstances, cause physical damage or environmental contamination.
So far, U.S. officials have characterized the CyberAv3ngers intrusions as disruptive rather than destructive. The attackers defaced screens, knocked systems offline, and demonstrated access — but they did not, according to public disclosures, manipulate processes in ways that caused physical harm. Whether that restraint was intentional or reflected limited technical capability remains an open question among intelligence analysts.
Robert M. Lee, CEO of industrial cybersecurity firm Dragos, has repeatedly warned that the line between espionage, disruption, and destruction in operational technology environments is thinner than most people realize. An attacker who can access a PLC can potentially reprogram it. And reprogramming a controller that governs a chemical feed pump or a pressure relief valve can have consequences measured not in data breaches but in human casualties.
The CyberAv3ngers campaign also highlights an uncomfortable geopolitical reality. Iran has steadily built its cyber capabilities over the past decade, moving from website defacements and crude DDoS attacks to operations targeting industrial infrastructure. The 2012 Shamoon attack on Saudi Aramco — attributed to Iranian actors — destroyed data on tens of thousands of computers. Since then, Iranian groups have targeted banks, government agencies, and now the physical systems that underpin daily life.
The IRGC connection is significant. Unlike freelance hackers or loosely affiliated hacktivist collectives, the IRGC is a military organization with a clear chain of command, strategic objectives, and state resources. CyberAv3ngers’ operations appear designed to serve both propaganda and strategic purposes: demonstrating the ability to reach inside adversaries’ critical infrastructure while signaling that escalation is possible if geopolitical tensions worsen.
And tensions have worsened. The October 7, 2023, Hamas attack on Israel and the subsequent war in Gaza intensified cyber operations across the Middle East. CyberAv3ngers’ campaign against Unitronics devices — an Israeli manufacturer — began in that exact timeframe. The group explicitly referenced the conflict in messages left on compromised devices. But the collateral damage extended far beyond Israel, hitting American towns that most people couldn’t find on a map.
Congress has taken notice, though action has been slow. The bipartisan Cyber Incident Reporting for Critical Infrastructure Act, signed into law in 2022, requires critical infrastructure operators to report significant cyber incidents to CISA. But the rulemaking process to implement those requirements has dragged on. Meanwhile, proposed legislation to establish minimum cybersecurity standards for water systems has faced pushback from industry groups and small utility operators who argue they can’t afford the compliance costs.
The Environmental Protection Agency attempted in 2023 to include cybersecurity assessments in routine sanitary surveys of water systems. A legal challenge from Republican attorneys general and water utility trade groups forced the agency to withdraw the rule. That left the water sector without any enforceable federal cybersecurity requirements — a gap that CyberAv3ngers exploited with precision.
Anne Neuberger, the Biden administration’s deputy national security adviser for cyber and emerging technologies, described the situation bluntly in a 2024 briefing: the United States cannot rely on voluntary measures alone to protect critical infrastructure from state-sponsored cyber threats. The current administration has yet to articulate a clear alternative approach.
The private sector has responded with a mix of urgency and frustration. Unitronics issued guidance urging customers to change default passwords and restrict internet access to its PLCs. Industrial cybersecurity vendors including Dragos, Claroty, and Nozomi Networks have published detailed analyses of the CyberAv3ngers’ tactics, techniques, and procedures. But vendors can only do so much when the fundamental problem is that operators leave devices exposed and unpatched.
There’s a broader pattern here that extends beyond any single threat actor. The Volt Typhoon campaign attributed to China targeted similar infrastructure — water, energy, transportation — using different methods but with the same underlying objective: pre-positioning for potential disruption during a future conflict. Russia’s Sandworm group has repeatedly attacked Ukrainian power grids. The message from multiple nation-states is consistent: critical infrastructure is a legitimate target, and the West’s defenses are inadequate.
For the operators running America’s 150,000-plus public water systems, the approximately 900,000 oil and gas wells, and the vast network of pipelines, refineries, and processing plants that keep the economy functioning, the CyberAv3ngers campaign is a warning shot. The next group may not stop at defacing a screen.
The technical fix is straightforward, even if implementation is hard: change default passwords, segment networks so industrial controllers aren’t directly exposed to the internet, monitor for unauthorized access, and patch known vulnerabilities. Every one of these steps has been recommended in federal guidance for years. Every one remains widely ignored.
That’s the real story. Not that Iranian hackers breached American infrastructure. But that they did it using techniques a moderately skilled teenager could replicate — and that much of the nation’s critical infrastructure remains just as vulnerable today as it was before the first intrusion was discovered.


WebProNews is an iEntry Publication