top of page

Water Utilities Under Attack: Exposed PLCs and Default Passwords

7 days ago
4 min read

Not every serious OT attack requires rare skill or a nation-state budget. In late 2023 and into 2024, a series of incidents at small water and wastewater systems showed how little effort it can take to reach a controller that is sitting on the public internet with its default password still in place. For small utilities with limited staff, these cases are a practical warning, and the fixes are within reach.

What happened

In November 2023, attackers began compromising a specific product line used across many small utilities: Unitronics Vision series programmable logic controllers (PLCs) and the human-machine interfaces (HMIs) built into them. The activity was tied to a persona called CyberAv3ngers, which US agencies describe as affiliated with Iran's Islamic Revolutionary Guard Corps.

The best-known case was the Municipal Water Authority of Aliquippa in Pennsylvania. On 25 November 2023, a booster station serving nearby townships was compromised. The attackers left a message on the controller's screen referencing Israeli-made equipment. The authority took the affected unit offline and switched the booster station to manual operation. Officials stated that drinking water was never at risk.

A joint advisory from CISA and partner agencies, carrying the identifier AA23-335A, documented the campaign. According to that advisory, the attackers reached the devices because they were exposed to the internet, in many cases on the default port TCP 20256, and were still using default or weak credentials. The method was not sophisticated; the devices were simply reachable and poorly protected.

Through 2024, other small US water systems reported related incidents. In Muleshoe, Texas, a water tank was made to overflow for about 45 minutes in January 2024, with neighbouring Lockney and Hale Center also seeing suspicious activity. That activity was attributed to a Russia-linked hacktivist group, the Cyber Army of Russia Reborn; the firm Mandiant reported a close operational relationship between that group and the Russian military intelligence actor it tracks as Sandworm, and in July 2024 the US Treasury sanctioned two of the group's members. As at Aliquippa, the affected systems were taken to manual operation and the water supply was not harmed.

How it worked, at a high level

Before and after comparison: internet-exposed PLC with default password versus PLC behind a firewall with secure, MFA-protected remote access
Internet-exposed controllers with default passwords were the root cause; removing exposure and changing defaults closes most of the risk.

The common thread across these incidents is simplicity:

  • The controllers were on the public internet. Devices meant to sit inside a plant network were directly reachable from anywhere.

  • Default or weak credentials were still in use. Where a device ships with a known default password and that password is never changed, anyone who finds the device can log in.

  • No real intrusion was needed. This was less a break-in than walking through an unlocked door. There is no clever exploit to describe, because none was required.

Impact

The physical consequences in these cases were limited, and no community lost safe drinking water. But the incidents were a loud signal. They showed that thousands of small utilities, often run by a handful of people without dedicated security staff, may have controllers exposed in the same way. They also drew sustained attention from federal agencies and prompted repeated warnings to the sector.

What it taught the industry

  • Internet exposure is the root problem. A controller that cannot be reached from the internet cannot be logged into from the internet. Exposure, more than any single vulnerability, is what made these attacks possible.

  • Defaults are dangerous. Default passwords are effectively public knowledge. Leaving them in place is the same as having no password.

  • Small does not mean safe. Attackers scan broadly and do not care how small a utility is. A tiny system with an exposed device is as reachable as a large one.

  • Manual fallback works. In every case, operators limited the damage by switching to manual control, echoing the lesson from the Ukraine grid attacks.

Practical defensive lessons

For a small utility with limited time and budget, a few concrete steps address most of the risk:

  1. Inventory your internet exposure. Find out whether any of your PLCs, HMIs or remote-access devices can be reached from the internet. Free external scans and your service provider can help confirm this.

  2. Remove direct internet access. Controllers should not be directly reachable from the public internet. Put them behind a firewall and a properly secured remote-access method instead.

  3. Change every default password. Replace default and shared credentials with strong, unique ones, and record them safely.

  4. Require multi-factor authentication for remote access. Any legitimate remote path into the system should use a second factor.

  5. Keep manual operation ready. Make sure staff can run key processes by hand, and practise it, so a compromised controller can be isolated without losing service.

  6. Keep firmware current. Apply vendor updates for controllers and HMIs during planned maintenance.

Key takeaways

  • In late 2023, the CyberAv3ngers persona compromised internet-exposed Unitronics Vision PLCs and HMIs, including a booster station at the Municipal Water Authority of Aliquippa, Pennsylvania.

  • The CISA advisory AA23-335A points to internet exposure, the default port TCP 20256 and default or weak passwords as the cause.

  • In 2024, further incidents hit small US water systems, including a tank overflow in Muleshoe, Texas, attributed to a Russia-linked hacktivist group.

  • No community lost safe drinking water, largely because operators switched to manual control.

  • Removing internet exposure, changing defaults and requiring multi-factor authentication address most of the risk.

How QBits Networks can help

The water-sector attacks came down to exposed devices and unchanged defaults, both of which are straightforward to find and fix. Our OT visibility snapshots and secure remote access reviews identify internet-exposed controllers and weak remote-access practices, and we can help small utilities set simple, workable policies for credentials and manual fallback. Tell us what you need through our contact page and we'll scope it with you.

bottom of page