# America's Water Systems Are Running on Default Passwords — And Someone Just Proved It


The advisory from CISA reads like a fire alarm pulled for the third time in two years. Protect your operational technology. Segment your networks. Change default credentials. Assume you're a target.


For most of the 50,000-plus community water systems across the United States, those instructions land in an inbox managed by the same person who also fixes the parking lot lights.


That's the real story behind the agency's latest push to harden water sector OT after a wave of coordinated attacks on programmable logic controllers — the embedded computers that physically move valves, adjust chemical dosing, and control pump stations. This isn't a software vulnerability with a patch Tuesday. It's a structural crisis dressed up as a cybersecurity advisory.


## What Actually Happened to Those PLCs


The most concrete trigger for CISA's renewed urgency was a campaign by CyberAv3ngers, an Iranian Islamic Revolutionary Guard Corps-linked threat group, that hit water utilities across multiple U.S. states in late 2023. The targets weren't random — attackers specifically hunted Unitronics Vision Series PLCs, a popular and affordable line of industrial controllers that ship with a default password of 1111 and, in many deployments, a web interface reachable straight from the public internet.


Municipal Water Authority of Aliquippa, Pennsylvania became the public face of the campaign when attackers defaced the HMI (human-machine interface) screen on a booster station controller. The image: a red banner declaring "You have been hacked." The station immediately switched to manual operation. No water was contaminated. But the point had been made.


What separated Aliquippa from a genuine disaster wasn't sophisticated defense — it was luck and the fact that most water utilities run their most sensitive processes through redundant manual controls that predate digital integration entirely. That safety net is not a strategy.


## The OT Attack Surface Nobody Wants to Fund


Industrial control systems in water utilities occupy a peculiar security limbo. They're too critical to ignore and too expensive to replace on a timeline that matches modern threat actors. A SCADA system controlling chemical dosing at a municipal plant might be running Windows XP on hardware purchased during the Bush administration, connected to a corporate network through a flat architecture with no segmentation because the engineer who designed it in 2003 never imagined someone would try to poison a suburb from a keyboard in Tehran.


CISA's advisory hits the expected marks: network segmentation, multi-factor authentication on remote access, replacing default credentials, monitoring for anomalous PLC commands. All correct. All things that have been on the checklist since at least the 2021 Oldsmar incident, where an attacker briefly cranked the sodium hydroxide setpoint at a Florida water treatment plant to 111 times normal levels before an operator caught it on screen.


The Oldsmar attack happened via TeamViewer. The attacker had valid credentials — probably harvested from a data breach — and the plant had no alerting for out-of-range chemical commands. Five years later, the same attack surface exists at hundreds of utilities.


## Small Systems, Big Exposure


The EPA's own estimates suggest the majority of U.S. water systems serve fewer than 10,000 people. These are small municipalities, rural water districts, and cooperatives operating on tax revenue that barely covers pipe replacement. Their "cybersecurity team" is often a single IT generalist or an outsourced managed service provider focused on email and payroll, not SCADA.


CISA knows this. The advisory specifically acknowledges that many targeted systems "may not have dedicated cybersecurity staff." What it doesn't fully reckon with is that awareness campaigns alone can't solve a resource problem. Telling a 3-person water authority to implement network segmentation across legacy OT infrastructure is like telling someone to renovate their kitchen with instructions but no budget.


The EPA attempted to fix this through mandatory cybersecurity assessments in 2023 — a rule requiring water systems to include cyber reviews as part of existing sanitary surveys. A coalition of states promptly sued, and the agency withdrew the rule. The voluntary framework has remained voluntary.


## What This Coordinated Pattern Actually Signals


The shift worth watching isn't the attacks themselves — it's the coordination. CyberAv3ngers didn't stumble into Unitronics PLCs. They built tooling to scan for them, exploit default credentials at scale, and hit multiple utilities in sequence. That's reconnaissance and targeting infrastructure, not opportunism.


This mirrors the playbook the Volt Typhoon (PRC-nexus) group used against U.S. critical infrastructure: establish persistent access across many targets, stay quiet, and hold the capability in reserve. Water is a soft target that delivers outsized psychological impact. An attacker who can credibly threaten a city's drinking water supply — even without following through — has leverage.


The PLCs being targeted are also a signal. Unitronics makes affordable, capable equipment. It's the brand small utilities actually buy. Targeting it isn't random; it's a deliberate choice to go where the defenses are thinnest.


---


## HackWire Analysis


CISA's water sector advisories are becoming a ritual without consequence — and that rhythm itself should alarm anyone paying attention. The same warnings, the same mitigations, the same sector-specific guidance, issued after each fresh incident. The underlying problem isn't that utilities don't know what to do. Many do. The problem is that the resources to do it don't exist at the community level, and federal mandates keep getting killed in court before they can change that.


What's missing from most coverage of this advisory is a direct comparison to what happened after Colonial Pipeline in 2021. That attack prompted TSA security directives with real teeth — mandatory incident reporting, specific cybersecurity measures, designated cybersecurity coordinators at pipeline operators. The water sector got... a voluntary framework. The reason is political economy: pipeline operators are large private companies that can absorb compliance costs. Water utilities are public entities whose rate increases require city council votes.


The other undercovered risk is the supply chain angle. Unitronics is an Israeli company whose PLCs are distributed globally. When IRGC-linked actors specifically target that vendor's equipment in U.S. water systems, there's an obvious geopolitical dimension the advisory doesn't name directly. These aren't random target selections — they reflect intelligence about where specific hardware is deployed at scale.


Defenders in this space have a narrow set of practical moves: internet-facing PLCs should be behind VPNs with MFA, full stop; chemical setpoint commands should have alerting for out-of-range values; and incident response plans need to explicitly cover "switch to manual" procedures before an attack, not after. But the larger fix requires funding mechanisms — likely federal grants specifically for OT security upgrades at small utilities — that aren't in the current advisory.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)