logo

Mandiant: Notorious Russian hacking unit linked to breach of Texas water facility

ID: 1eb5e39a-129a-53fa-9b68-724fccc9b071

STIX ID: report--1eb5e39a-129a-53fa-9b68-724fccc9b071

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2024-04-17

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Mandiant attributes a series of disruptive attacks on water utilities and other critical infrastructure to the Russian GRU-aligned Sandworm (now tracked as APT44), linking the group to online personas such as CyberArmyofRussia_Reborn and Solntsepek; incidents cited include a Texas water-tank overflow and attacks on Ukrainian telecoms. The report elevates Sandworm to a fully capable state-backed APT conducting espionage, influence, and destructive operations against government, energy, transportation and media targets and warns of growing threats to U.S. water-sector cybersecurity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.