Iran Is Using the Exact Same Hacking Playbook on US Water Systems That It Used on Pittsburgh in 2023

0
13
Masterpineapple421, CC BY-SA 4.0/Wikimedia Commons

Federal agencies have spent months warning that cyberattacks on local water systems are becoming a larger national security issue. That warning now centers on Iran-affiliated hackers using tactics that closely mirror the 2023 breach at the Municipal Water Authority of Aliquippa near Pittsburgh. The latest alerts point to the same kind of weakly secured industrial control equipment that can be reached over the public internet.

Federal agencies say the latest attacks follow the Aliquippa pattern

The clearest federal marker came on April 7, 2026, when the EPA said a joint advisory with the FBI, CISA and NSA warned that Iran-affiliated cyber actors were exploiting vulnerabilities in water systems and other critical infrastructure. The EPA said the recent activity had already caused disruptions, including configuration wiping, tampering with software-based mechanical sensors and disruption of human machine interfaces, or HMIs. Reuters also reported that the warning covered attacks on critical infrastructure organizations in the water, energy and government sectors.

That description closely tracks what officials documented after the November 2023 incident in Aliquippa, Pennsylvania. In that case, CISA and its partner agencies said IRGC-affiliated actors using the name CyberAv3ngers were targeting publicly exposed Unitronics Vision Series programmable logic controllers through default passwords. Local officials in Aliquippa confirmed that one booster station was taken offline and that operators switched to manual control while drinking water service continued.

The scale of the current campaign appears wider than the single Pennsylvania case. AP reported that more than 30 Minnesota water systems were targeted in late July 2026, and Michigan officials later said nine systems there showed similar activity after a federal alert. The FBI has not publicly identified a culprit in those incidents, but federal agencies said in last week’s advisory that Iranian hackers have been targeting water and wastewater systems and the operational controls used in other sectors.

For western Pennsylvania readers, the comparison begins with Aliquippa, a city in Beaver County northwest of Pittsburgh. The Municipal Water Authority of Aliquippa said in November 2023 that hackers linked to CyberAv3ngers gained control of one station, prompting an immediate switch to manual operations. Reporting at the time from CBS Pittsburgh said the compromised site served local customers, while federal officials said there was no known risk to drinking water or water supply.

What remains publicly unconfirmed is whether any additional Pennsylvania water systems have been hit in the newest wave. The current federal warnings describe a national pattern, but agencies have not released a comprehensive list of affected Pennsylvania utilities tied to the 2026 activity. No statewide Pennsylvania count comparable to Minnesota’s more than 30 targeted systems or Michigan’s nine impacted systems has been publicly detailed in the reporting now available.

That means the local significance is less about a newly confirmed Pennsylvania outage and more about precedent. Aliquippa has become the case federal and industry officials repeatedly point to when explaining how an overseas hacking group can reach a small U.S. utility through exposed operational technology. The lesson from that incident was that even when water service continues, a compromise of pumps, HMIs or remote monitoring tools can force utilities into manual operation and emergency response.

Federal and independent reviews have pointed to the same underlying problem for more than two years: many water systems still rely on internet-accessible operational technology with weak authentication, outdated configurations or limited cyber staffing. The GAO said the U.S. water sector includes about 170,000 water and wastewater systems, many of which face known cybersecurity risks, and that EPA has needed a broader strategy to address them. Microsoft said in a 2024 security analysis that internet-exposed OT devices in U.S. water and wastewater systems had already been targeted by multiple nation-backed groups, including CyberAv3ngers.

The Aliquippa case showed how simple some of those intrusions can be. Federal guidance tied that 2023 attack to publicly exposed Unitronics devices and default passwords, and later federal advisories expanded the warning to other brands of programmable logic controllers. The current 2026 advisory indicates the playbook has not fundamentally changed, even if the targeted hardware has broadened beyond the Israeli-made equipment highlighted in 2023.

For residents, the practical takeaway is that a cyber incident at a water utility does not automatically mean unsafe drinking water, but it can disrupt normal plant operations and force local staff to run systems manually. In both Minnesota and Michigan, officials said utilities continued to operate safely and that no known public health impacts had been identified in the reported incidents. Federal agencies are continuing to push water systems toward basic controls such as removing devices from the public internet, changing default passwords and placing remote access behind more secure connections.

LEAVE A REPLY

Please enter your comment!
Please enter your name here