
Shieldworkz Featured in CRVScience
Shieldworkz Threat Intelligence Cited in CRVScience Deep-Dive on Two Decades of ICS Exploitation
Shieldworkz original threat intelligence has been cited as a source in a major research feature published on CRVScience, authored by Bryan White. Titled "Two Decades of Cyber Conflict: The Journey from Web Disruption to ICS Exploitation," the piece traces the evolution of cyberwarfare from the 2007 Estonian denial-of-service attacks to the precise, architecturally aware ICS intrusions defining the threat landscape today, drawing directly on Shieldworkz research into the 2026 multistate campaign against U.S. water and wastewater systems.
The Shieldworkz report in question, "Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology," published August 3, 2026, documented a coordinated intrusion campaign that began July 26, 2026 and expanded to affect water and wastewater facilities across at least seven U.S. states, including Minnesota and Michigan. The CRVScience feature draws on this and related reporting to illustrate how Iranian-affiliated actors have evolved their tradecraft against critical infrastructure.

Shieldworkz Threat Intelligence Cited in CRVScience Deep-Dive on Two Decades of ICS Exploitation
Shieldworkz original threat intelligence has been cited as a source in a major research feature published on CRVScience, authored by Bryan White. Titled "Two Decades of Cyber Conflict: The Journey from Web Disruption to ICS Exploitation," the piece traces the evolution of cyberwarfare from the 2007 Estonian denial-of-service attacks to the precise, architecturally aware ICS intrusions defining the threat landscape today, drawing directly on Shieldworkz research into the 2026 multistate campaign against U.S. water and wastewater systems.
The Shieldworkz report in question, "Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology," published August 3, 2026, documented a coordinated intrusion campaign that began July 26, 2026 and expanded to affect water and wastewater facilities across at least seven U.S. states, including Minnesota and Michigan. The CRVScience feature draws on this and related reporting to illustrate how Iranian-affiliated actors have evolved their tradecraft against critical infrastructure.


Why this coverage matters
CRVScience research places Shieldworkz findings within a two-decade historical arc, from Estonia's 2007 DDoS campaign, which established cyberspace as a domain of state-level coercion, through the legal frameworks of the Tallinn Manual, to the present-day exploitation of programmable logic controllers (PLCs) governing physical processes. The piece cites Shieldworkz analysis of the 2026 multistate water sector campaign as a case study in how this evolution plays out in practice.
Shieldworkz original reporting, referenced in the feature, documented several core findings:
Direct exploitation of internet-facing PLCs, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers, alongside CompactLogix and Micro850 devices
A consistent attacker methodology: exploiting exposed EtherNet/IP sessions on TCP port 44818, resetting administrative passwords, altering IP configurations, and uploading tampered ladder logic
Operational consequences including simultaneous loss of view and loss of control for plant operators, forcing multiple municipalities into emergency manual operations
A medium-confidence attribution assessment pointing to CyberAv3ngers, an IRGC-Cyber Electronic Command-affiliated group, based on tactical alignment with the group's 2023 campaign against Unitronics PLCs at the Aliquippa, Pennsylvania water authority

Why this coverage matters
CRVScience research places Shieldworkz findings within a two-decade historical arc, from Estonia's 2007 DDoS campaign, which established cyberspace as a domain of state-level coercion, through the legal frameworks of the Tallinn Manual, to the present-day exploitation of programmable logic controllers (PLCs) governing physical processes. The piece cites Shieldworkz analysis of the 2026 multistate water sector campaign as a case study in how this evolution plays out in practice.
Shieldworkz original reporting, referenced in the feature, documented several core findings:
Direct exploitation of internet-facing PLCs, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers, alongside CompactLogix and Micro850 devices
A consistent attacker methodology: exploiting exposed EtherNet/IP sessions on TCP port 44818, resetting administrative passwords, altering IP configurations, and uploading tampered ladder logic
Operational consequences including simultaneous loss of view and loss of control for plant operators, forcing multiple municipalities into emergency manual operations
A medium-confidence attribution assessment pointing to CyberAv3ngers, an IRGC-Cyber Electronic Command-affiliated group, based on tactical alignment with the group's 2023 campaign against Unitronics PLCs at the Aliquippa, Pennsylvania water authority
Shieldworkz perspective
At Shieldworkz, our threat intelligence exists to give defenders an accurate, evidence-based picture of what's actually happening on exposed networks, not speculation. Seeing our multistate campaign analysis cited in a piece of this depth is a validation of that approach: research grounded in confirmed forensic facts, clearly separated from analytical hypothesis, and mapped against frameworks like MITRE ATT&CK for ICS that defenders can act on directly.
The throughline CRVScience draws, from Estonia's 2007 DDoS campaign to today's PLC-level intrusions, matches what we've observed directly: attackers don't need sophistication when operators haven't closed the basics. The highest-leverage defensive actions available to critical infrastructure operators today remain straightforward:
Eliminating internet-facing exposure of PLCs, RTUs, and HMIs
Rotating default and weak administrative credentials
Enforcing genuine network segmentation aligned with the Purdue Model
Why This Recognition Matters
CRVScience broader argument, that architectural decay, IT/OT convergence, and the erosion of the Purdue Enterprise Reference Architecture are handing attackers an asymmetric advantage, is directly substantiated by the operational details Shieldworkz documented in its multistate campaign analysis. The research feature notes that the vulnerability exploited was not a sophisticated zero-day but rather a fundamental architectural failure: PLCs designed for closed, trusted networks left exposed to public scanning tools like Shodan and Censys.
Key takeaways from the coverage
Shieldworkz multistate water sector campaign report is cited as a primary source in CRVScience research on the evolution of ICS threats.
The 2026 campaign affected water and wastewater facilities across at least seven U.S. states, targeting Rockwell Allen-Bradley PLCs via exposed EtherNet/IP sessions.
Attribution points with medium confidence to CyberAv3ngers, an IRGC-affiliated group with a documented history of targeting water infrastructure.
The incident illustrates CRVScience broader argument that architectural decay, not novel exploits, is the primary driver of modern ICS compromise.
Both the Shieldworkz report and the CRVScience feature converge on the same remediation priorities: eliminating internet exposure, enforcing MFA, and rebuilding Purdue Model segmentation.

Shieldworkz perspective
At Shieldworkz, our threat intelligence exists to give defenders an accurate, evidence-based picture of what's actually happening on exposed networks, not speculation. Seeing our multistate campaign analysis cited in a piece of this depth is a validation of that approach: research grounded in confirmed forensic facts, clearly separated from analytical hypothesis, and mapped against frameworks like MITRE ATT&CK for ICS that defenders can act on directly.
The throughline CRVScience draws, from Estonia's 2007 DDoS campaign to today's PLC-level intrusions, matches what we've observed directly: attackers don't need sophistication when operators haven't closed the basics. The highest-leverage defensive actions available to critical infrastructure operators today remain straightforward:
Eliminating internet-facing exposure of PLCs, RTUs, and HMIs
Rotating default and weak administrative credentials
Enforcing genuine network segmentation aligned with the Purdue Model
Why This Recognition Matters
CRVScience broader argument, that architectural decay, IT/OT convergence, and the erosion of the Purdue Enterprise Reference Architecture are handing attackers an asymmetric advantage, is directly substantiated by the operational details Shieldworkz documented in its multistate campaign analysis. The research feature notes that the vulnerability exploited was not a sophisticated zero-day but rather a fundamental architectural failure: PLCs designed for closed, trusted networks left exposed to public scanning tools like Shodan and Censys.
Key takeaways from the coverage
Shieldworkz multistate water sector campaign report is cited as a primary source in CRVScience research on the evolution of ICS threats.
The 2026 campaign affected water and wastewater facilities across at least seven U.S. states, targeting Rockwell Allen-Bradley PLCs via exposed EtherNet/IP sessions.
Attribution points with medium confidence to CyberAv3ngers, an IRGC-affiliated group with a documented history of targeting water infrastructure.
The incident illustrates CRVScience broader argument that architectural decay, not novel exploits, is the primary driver of modern ICS compromise.
Both the Shieldworkz report and the CRVScience feature converge on the same remediation priorities: eliminating internet exposure, enforcing MFA, and rebuilding Purdue Model segmentation.


About Shieldworkz
Shieldworkz helps organisations secure Operational Technology (OT), IoT and Cyber-Physical Systems (CPS) across industrial and national infrastructure. Our threat research team blends sector-aware telemetry, hunt-driven detection, and hands-on incident response to find hidden exposure and build resilient recovery paths.

About Shieldworkz
Shieldworkz helps organisations secure Operational Technology (OT), IoT and Cyber-Physical Systems (CPS) across industrial and national infrastructure. Our threat research team blends sector-aware telemetry, hunt-driven detection, and hands-on incident response to find hidden exposure and build resilient recovery paths.
Visit our website: https://shieldworkz.com
For press inquiries and expert interviews, contact: info@shieldworkz.com
Stay ahead of tomorrow’s threats with Shieldworkz, your partner in proactive OT cybersecurity.
Learn More & Resources
Visit our website: https://shieldworkz.com
For press inquiries and expert interviews, contact: info@shieldworkz.com
Stay ahead of tomorrow’s threats with Shieldworkz, your partner in proactive OT cybersecurity.
Learn More & Resources
Read the news article

