The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →U.S. water and wastewater facilities have been targeted in two related campaigns: a 2023 wave against exposed Unitronics controllers and a newer campaign against internet-connected PLCs from several manufacturers. Federal agencies warn that the risk is operational, not merely cosmetic: unauthorized changes to controller logic, alarms, or displayed data can interfere with facility operations.
What did U.S. agencies report, and when?
The incidents span two phases. The first, in November 2023, involved the CyberAv3ngers persona and Unitronics PLCs and HMIs. A later campaign described by federal agencies in 2026 targets internet-connected operational technology in water and wastewater, energy, and government environments. The two phases should not be treated as one continuous count or as evidence that every listed vendor was affected in the same way.
| Date or period | Agency or dataset | What it reports |
|---|---|---|
| November 2023 activity; historical figure reported in 2026 | CISA and partner agencies | At least 75 U.S.-based Unitronics PLC devices were compromised in the historical CyberAv3ngers activity. |
| November 23, 2023–April 22, 2024 | CTIIC dataset | 29 CyberAv3ngers attacks and seven attacks attributed to a pro-Russia hacktivist. |
| April 7, 2026 | EPA, FBI, CISA, and NSA | Issued an urgent warning about ongoing Iranian-affiliated exploitation of operational technology in drinking-water and wastewater systems. |
| July 22, 2026 | CISA and partner agencies | Updated the advisory to include observed targeting of Schneider Electric and Siemens PLCs and malicious reusable code modules in Rockwell PLC programs. |
The device total and CTIIC attack count describe different measures and periods; they are not directly comparable. The 2026 advisory describes observed targeting of Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens equipment, and says other manufacturers may also be affected.
How did the intrusions work?
In the 2023 Unitronics campaign, exposed devices and compromised default credentials provided a route in. Some victims had anti-Israel messages displayed on PLC touchscreens. CTIIC reported that a few water-sector victims shut down briefly and shifted to manual operation.
#1 Best Overall
- -- PLC Type: Fully compatible with FX1S, 7 Input 5 Relay Output (24V pulse single). Have additional 4 Transistor Output: 2 for high speed pulse 100KHz & 2 for direction, can drive 2 servos or 2 steppers with pulse
- -- PLC software: Use GX Workers 2 or Developer (pls download from GX Workers 2 website, we only have Chinese version), support Command + T Ladder Diagram + SFC for programming
- -- HMI Software: YKBuilder V5.3/7.0 (Pls contact us, we will share it and the video instruction and guidelines). For HMI model: pls choose FE Serial, 280D
- -- Use the same Cable for download program from PC to PLC/HMI: Use the: mini port – USB cable, pls install HMI & PLC’s USB driver first, which we will share.
For the newer activity, CISA says the actors used foreign-based IP addresses, leased third-party infrastructure, and vendor programming software to connect to misconfigured PLCs exposed to the internet. Reported traffic included ports 44818, 2222, 102, and 502; the advisory also noted modem access on port 22. After gaining access, actors extracted project files and changed or deleted logic and Add-On Instructions. They also manipulated HMI/SCADA data and, in some cases, disabled shutdown and alarm logic.
What could be affected at a water facility?
Reported effects include wiped configuration or project files, software-based tampering with mechanical-sensor readings, disrupted HMI displays, operational interruption, and financial loss. CTIIC documented two Texas water facilities where attackers tampered with pumps and alarms. Water passed designated shutoff levels and overfilled storage tanks.
Rank #2
- Weight: 1.00lb
- Product Dimensions: 9.00 x 9.00 x 7.00 inches
- Condition: New
The practical concern is that an operator may see misleading data or lose expected alarm and shutdown behavior while equipment is running. EPA Assistant Administrator for Enforcement and Compliance Assurance Jeffrey A. Hall warned: “Cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience. A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should a utility reduce its exposure?
- Remove direct internet access to PLCs. Work with IT/OT staff or a qualified integrator to place a secure gateway and firewall between controllers and external networks. For an industrial firewall for PLC networks, verify that the design supports the facility’s PLC protocols and vendors, restricts remote access to the least privilege needed, records useful logs, fails safely, and meets the site’s environmental, lifecycle, and support requirements.
- Review logs and network activity. Compare device and network records with the indicators of compromise in CISA’s advisory, and investigate suspicious traffic on the OT ports it identifies. Treat an unfamiliar connection or unexpected programming-software session as a reason to investigate, not as proof of compromise on its own.
- Check controller and supervisory-system changes. Compare project files and ladder logic with known-good versions. Inspect Add-On Instructions, HMI/SCADA displays, shutdown behavior, and alarms for unauthorized modification or deletion.
- Apply vendor-specific secure-deployment guidance. Follow the relevant manufacturer’s instructions. For Rockwell controllers where applicable, CISA recommends placing the physical mode switch in the run position.
- Escalate suspected compromise through established channels. Activate the facility’s incident-response procedures and contact CISA, the FBI, and the PLC manufacturer using their established support channels.
- Maintain baseline controls. Keep an accurate asset inventory, apply available updates, use strong unique passwords instead of defaults, segment operational networks, and control remote access. CTIIC identified outdated software, default credentials, poor password practices, and limited update resources as recurring ICS weaknesses.
Changes to controller logic or alarm behavior can affect physical processes, so utilities should coordinate investigation and restoration with qualified operational staff rather than making ad hoc changes that could create a safety or service problem.
Quick Recap
Rank #4
- -- PLC Type: Fully compatible with FX1S, 10 Input 7 Relay Output (5V pulse single). Have additional 4 Transistor Output: 2 for high speed pulse 100KHz & 2 for direction, can drive 2 servos or 2 steppers with pulse; have 2 high speed input 100KHz X0 X1 to control encoder also
- -- PLC software: Use GX Workers 2 or Developer (pls download from GX Workers 2 website, we only have Chinese version), support Command + T Ladder Diagram + SFC for programming
- -- HMI Software: YKBuilder (Pls dowload from link or contact us, we will share it and the video instruction and guidelines), very easy to use, just create the buttun and set the address
- -- Use the same Cable for download program from PC to PLC/HMI: Use the: mini port – USB cable, pls install HMI & PLC’s USB driver first, which we shared from link
Rank #3
- -- PLC Type: Fully compatible with FX1S, 10 Transistor Input (NPN Type), 7 Relay Output. Have additional 4 Transistor Output: 2 for high speed pulse 100KHz & 2 for direction, can drive 2 servos or 2 steppers with pulse, built-in 2AD(0-10V) and 2DA(0-10V), also 2 NTC10K B3435 probe. Just read the address of AD DA NTC's will ok, 2 high speed input 100KHz X0 X1 to control encoder
- -- PLC software: Use GX Workers 2 or Developer (pls download from GX Workers 2 website, we only have Chinese version), support Command + T Ladder Diagram + SFC for programming
- -- HMI Software: YKBuilder V5.3 and Choose FE serial 380 model in HMI software. (Pls contact us, we will share it and the video instruction and guidelines), very easy to use, just create the buttun and set the address
- -- Use the same Cable for download program from PC to PLC/HMI: Use the: mini port – USB cable, pls install HMI & PLC’s USB driver first, which we will share.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

