When a pump station in Aliquippa, Pennsylvania was hijacked in late 2023, operators didn’t notice until the system had already been forced into manual mode. That incident, federal agencies now warn, was a preview of far more deliberate sabotage. A joint advisory from the FBI, NSA, CISA, DOE and EPA confirms that Iranian-linked hackers are actively disrupting U.S. water and energy providers by targeting internet-exposed industrial control systems — and the tactics have grown significantly more dangerous since that Pennsylvania wake-up call.
From Vandalism to Sabotage
What began as political messaging on hacked screens in 2023 has escalated into direct manipulation of physical infrastructure.
The 2023 CyberAv3ngers campaign — linked to Iran’s Islamic Revolutionary Guard Corps — compromised Israeli-made Unitronics controllers at multiple small water utilities. Forcing a pump station into manual mode was disruptive, but operators could see it happening. The current campaign removes even that visibility. Hackers are now wiping device configurations, tampering with mechanical sensors, and — in at least one confirmed case — rewriting controller logic to disable critical safety alarms entirely, allowing systems to enter unsafe conditions without notifying operators.
Here’s what the advisory spells out:
- PLCs (programmable logic controllers) — the small computers automating physical processes like chemical dosing and pump pressure — are being directly manipulated
- HMIs (human-machine interfaces) — the operator displays showing system status — are being fed falsified data
- Targeted equipment now includes products from Rockwell Automation, Schneider Electric, and Siemens
- IRGC-affiliated actors are driving the operations, with the explicit goal of causing disruptive effects inside the U.S.
- Agencies warn that “potentially all internet-exposed” industrial control systems could be at risk
“A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust,” according to EPA Assistant Administrator Jeffrey A. Hall.
The Unlocked Front Door Problem
Too many utilities are running critical infrastructure on default passwords and open internet connections — a combination that turns negligence into a national security liability.
Think of it like the default password on your home router — the one you swore you’d change years ago, still sitting there, still working. U.S. advisories describe a “vast attack surface“ that a motivated and capable adversary can exploit, built from outdated software, unchanged default credentials, and operational technology devices connected directly to the public internet. Worth noting: not every Iranian-aligned claim holds up. California Water Service reported no evidence of unauthorized access to operational networks after the group “Handala” claimed otherwise — a useful reminder that some threat actor announcements outpace verified impact.
Federal agencies are urging operators to:
- Disconnect OT devices from the public internet
- Enforce phishing-resistant multifactor authentication
- Patch aggressively
- Implement active monitoring
The gap between that guidance and current practice at understaffed municipal utilities is precisely where your tap water’s safety — and your city’s power grid — remain exposed.





























