EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyber-attack/2025-israel-water-systems-hack
056/430

File EL-0375CriticalOngoingCyber Attack / Hacktivism / Critical Infrastructure Attack

Israeli Water Infrastructure Cyber Attack

Also filed as Iranian Hacktivists Target Israel Water Systems · Cyber Attack on Israeli Reservoirs

Iran-linked hacktivist group CyberAv3ngers conducted a coordinated cyber attack on Israeli water infrastructure, deploying wiper malware and attempting to manipulate water levels and chemical dosing systems.

  • #hacktivism
  • #critical-infrastructure
  • #water-systems
  • #wiper-malware
  • #iran
  • #geopolitical
Notoriety9/10
Event
12 Nov 2025
Disclosed
13 Nov 2025
Target
Mekorot & Multiple Municipal Water Authorities
Actor
CyberAv3ngers
Status
Ongoing

01Summary

On November 12, 2025, multiple water treatment and distribution facilities in Israel were hit with wiper malware. The attackers claimed they could have caused physical damage by altering chlorine levels and water pressure but chose to issue a warning instead. Internal documents and SCADA screenshots were leaked online as proof of access.

02Background

Water infrastructure is a high-value symbolic and practical target in Middle East cyber conflicts. Israel has some of the world's most advanced water management systems.

03Key revelations

  1. 01Increasing willingness of hacktivists to target life-critical infrastructure.
  2. 02Persistent vulnerabilities in industrial control systems.

04Technical analysis

Attackers gained access through compromised third-party maintenance accounts and exploited unpatched ICS/SCADA systems. Wiper malware was deployed on HMIs and engineering workstations.

Attack vector
Compromised third-party credentials
Attack method
Lateral movement into ICS networks + Wiper deployment
Initial access
Third-party compromise
Lateral movement
ICS network pivoting
Exfiltration
Targeted screenshots and documents
Tool / malware
Custom wiper malware
Malware type
Wiper / Destructive

Vulnerabilities exploited

  • Weak third-party access controls
  • Legacy ICS systems

05Threat actor

CyberAv3ngers – Pro-Iran hacktivist collective known for targeting Israeli and Western critical infrastructure with destructive malware.

Aliases

  • Soldiers of Solomon

Attribution sources

  • Israeli National Cyber Directorate
  • CISA
  • BleepingComputer

06Victims and impact

Additional victims

  • Several regional water treatment plants

Countries affected

  • Israel

07Data exposed

Data types

  • SCADA Screenshots
  • Internal Operational Documents
  • Infrastructure Schematics

Notable documents

  • Leaked SCADA screenshots

08Financial damage

Emergency response costs and temporary operational restrictions.

09Timeline

  1. 2025-11-12Coordinated attacks on multiple water facilities.
  2. 2025-11-13CyberAv3ngers claims responsibility and leaks proof.

10Reaction and fallout

Public reaction

Significant public anxiety regarding water safety and national security.

Political impact

Strong condemnation from Israeli and U.S. governments.

Geopolitical consequences

Further escalation in Iran-Israel cyber shadow war.

11Legal

International investigation ongoing.

12Aftermath

Policy changes

  • Accelerated air-gapping and segmentation of critical water systems.

Security improvements

  • Emergency ICS security upgrades across Israel.

13Significance and legacy

Significance

One of the most serious attempts to disrupt critical civilian infrastructure via cyber means in 2025.

Legacy

Served as a wake-up call for global protection of water and utilities from hacktivist and nation-state threats.

14Disclosure and media

Authentication
Hacker-published screenshots and videos

Publishing organisations

  • The Times of Israel
  • BleepingComputer
  • Recorded Future

15Field notes

  1. 01The attackers claimed they could have caused chlorine overdosing but chose not to.

16Resolution

Attack contained; no physical damage to water supply reported.

17Sources

Official documents

  • Israeli National Cyber Directorate Alert

References

  1. [1]Israeli government statements
  2. [2]BleepingComputer
  3. [3]Recorded Future reports
Fact sheetEL-0375

Dates

Event
12 Nov 2025
Started
12 Nov 2025
Discovered
12 Nov 2025
Disclosed
13 Nov 2025
Ongoing
Yes

Target

Organisation
Mekorot (Israel National Water Company)
Type
Critical Infrastructure
Sector
Water & Utilities
Country
Israel
Gov. level
National

Actor

Name
CyberAv3ngers
Type
Hacktivist Group
Nation-state
Iran (linked)
Affiliation
Iran-aligned
Motivation
Geopolitical retaliation against Israel and demonstration of capability against critical infrastructure.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Critical
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.