CyberAv3ngers hit UK power and US water in the same window. That coordination is the story.
What happened
Iran-linked threat actors shut down a UK gas-fired peaker plant for four days. In the same operational window, they struck wastewater treatment systems across 12 US states, affecting dozens of facilities in Minnesota, Michigan, Georgia, South Dakota, New Jersey, and others.
The UK incident involved a plant with approximately 15 MW capacity. It is small relative to national grid scale, and the disruption did not affect wider power supply. The US incidents caused flooding and loss of water pressure at affected treatment facilities.
Attribution: the FBI confirmed the US incidents were conducted by CyberAv3ngers, an operational group affiliated with Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC). UK government and NCSC sources corroborated the attribution on the power plant side.
The UK incident occurred in July 2026, with the Telegraph newspaper disclosing it publicly on August 22. The US incidents began with the first Minnesota report on July 26.
The simultaneous timing is deliberate
CyberAv3ngers did not accidentally hit two allied nations at the same time. The concurrent campaigns across UK energy and US water infrastructure represent a coordinated operational plan designed to test the threshold of response. Both targets are critical infrastructure under national definitions. Neither attack reached the scale that would require a formal armed response or trigger mutual defense obligations.
That is the operating calculus. Gray-zone disruption below the threshold of armed conflict, executed simultaneously against two allied nations, creates political and attribution complexity while achieving real-world impact.
The hardware is the same
CyberAv3ngers has been targeting Unitronics Vision Series PLCs since at least the 2023 campaign against US water utilities. The same hardware appears in these incidents. The group has not needed to update its targeting approach because the exposure has not changed: internet-facing industrial controllers with default or weak credentials, accessible on standard ports.
The 2023 CISA advisory on CyberAv3ngers and Unitronics PLCs was detailed and actionable. The continued exploitation of the same hardware class three years later indicates that advisory compliance in the water sector remains incomplete.
What this means for OT security
The threat model for operational technology networks is no longer theoretical. State-affiliated actors are conducting disruptive attacks against critical infrastructure below the threshold that triggers formal escalation, and they are doing it with tactics documented years in advance.
The implication for OT operators is that internet-facing PLCs with default credentials are active targets, not hypothetical ones. Air-gapping, network segmentation, and credential hygiene on industrial controllers are not IT security practices awkwardly applied to OT. They are the baseline.
The implication for policymakers is that the current response framework treats simultaneous attacks on allied critical infrastructure as a series of individual incidents. CyberAv3ngers treated them as a single coordinated campaign. The response architecture should match the threat.
What to do
If you operate critical infrastructure in energy, water, or wastewater: inventory internet-facing PLCs, remove Unitronics Vision Series controllers from direct internet exposure, rotate any default credentials immediately, and review the CISA ICS advisories from 2023 and 2026 for specific indicators. If you cannot take affected systems offline, implement network monitoring for the specific ports and protocols documented in those advisories.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization is developing an OT security program.