The Municipal Water Authority of Aliquippa in Pennsylvania disclosed on 25 November 2023 that it had lost control of a booster station regulating water pressure. The compromised device was a Unitronics programmable logic controller, and the attackers renamed it and defaced its interface.
CISA and partner agencies published a joint advisory describing IRGC-affiliated actors using the persona CyberAv3ngers targeting internet-exposed Unitronics Vision series controllers and interfaces across multiple sectors including US water and wastewater systems. Reporting placed the compromised population in the dozens, with most devices using factory-default credentials.
The Vulnerability Was A Default
There is no CVE at the centre of this file. The controllers were reachable from the internet, on a well-documented port, with the password they shipped with.
The corpus files unpatched software at 23-0208 and misconfiguration at 23-0512, and this is a third category: equipment doing exactly what it was sold to do, deployed by organisations with no one whose job was to change the password. Aliquippa is a municipal water authority, not an enterprise with a security function.
Defacement Is A Message, Not A Failure Of Ambition
Renaming a controller and putting a slogan on its screen is not the most damaging thing available to someone holding a device that regulates water pressure. The corpus records that plainly.
It records equally plainly that the same access supports doing considerably more, and that the operators chose visibility over damage. That is a choice about messaging, and it can be made differently next time by the same access.
This File Is The Start Of A Sequence
The corpus records the water sector being named as a target in the May 2023 advisory at 23-0524, disrupted here in November 2023, disrupted at much greater scale across Minnesota at 26-0727, and addressed by device-level federal guidance at 26-0729.
Two and a half years separate the warning from the Minnesota incidents, with this file in between. The desk notes at 26-0729 that the later advisory names the device rather than the adversary; the reason is visible here, where the device and its default password were the whole of it.
Built on the CISA joint advisory on IRGC-affiliated exploitation of PLCs and on contemporaneous reporting of the Aliquippa incident. The attribution to IRGC-affiliated actors using the CyberAv3ngers persona is the advisory’s, recorded as its assessment. The Aliquippa booster station loss, the renaming and defacement are as reported. The count of compromised devices and the prevalence of default credentials come from the advisory and subsequent reporting and are stated as reported. No claim is made that water quality or supply safety was affected at Aliquippa — none was established. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.
- IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems FacilitiesCybersecurity and Infrastructure Security Agency
- Iranian Cyber Av3ngers Compromise Unitronics SystemsSophos