← Back

Z-Pentest and NoName057(16) Put Canadian Water Systems at the Center of Pro-Russian OT/ICS Pressure

Leer en Español
Print Share

Executive Summary

On July 23, Z-Pentest Alliance and NoName057(16) published separate messages regarding alleged access to municipal drinking water systems in Canada, as part of a sequence tagged #OpCanada and connected to the narrative that followed Operation Eastwood. Z-Pentest targeted Eau potable St-Noël in Quebec, while NoName057(16) published a post concerning Georgetown Water System in Ontario.

The activity regained visibility after Canadian media reported that Quebec and Ottawa are investigating recent cyberattacks against drinking water facilities. A summary republished by Réseau d’Information Municipale indicates that both jurisdictions are investigating recent attacks against drinking water plants, while in the United States the FBI is examining dozens of similar attacks.

The sequence is consistent with the assessment iQBlack developed through direct interviews with both actors. Z-Pentest described itself as a structure capable of operating across technical activity, propaganda, cooperation, and gray areas of affiliation, and stated that OT/ICS represents only one line within a broader operational repertoire. NoName057(16), for its part, described its activity as a broader platform for political pressure, with explicit cooperation with Z-Pentest and an information component aimed at turning public events into narrative material.

Key Judgments

  • The declared activity targets a sensitive surface: municipal drinking water systems, small communities, remote operations, and exposed OT environments.
  • The significance of the sequence lies not only in the declared access itself, but also in the subsequent cycle: publication, visual evidence, media coverage, institutional investigation, and the actor’s propagandistic response.
  • Z-Pentest and NoName057(16) frame the activity as pressure against Canada rather than as an isolated technical intrusion.
  • Publicly available information confirms an investigation and local response in at least Saint-Noël.

What Happened

According to activity declared by Z-Pentest, the actor gained access to a small municipal drinking water facility identified as Eau potable St-Noël in Canada. The publication mentioned visibility into operational variables, alerts, event history, and capabilities associated with system management. The text also included an explicit threat regarding possible changes to critical parameters, including levels, filling, and dosing.

That same day, NoName057(16) published information concerning Georgetown Water System in Halton Region, Ontario. The post described a municipal pumping station with main pumps, backup generators, monitoring, pressure, flow, and startup history. The actor claimed to have observed startup failures and alarms within the system, using the case to criticize Canada’s protection of critical infrastructure.

The Saint-Noël case received public attention. Ma Gaspésie reported that the Saint-Noël drinking water station was targeted in a cyberattack on July 23, that the incident was quickly detected by the municipal employee responsible for operating the facility, that the system was restored with support from the MRC de La Matapédia, and that the municipality stated public health and safety had not been compromised. The same report noted that an analysis would be conducted to understand the circumstances surrounding the incident.

In a recent Z-Pentest publication addressing the case, released after the media coverage, the actor adopts a mocking tone and turns the investigation period, intervention by authorities, and press coverage into material intended to reinforce its narrative of superiority, institutional slowness, and pressure against Canada.

Analytical Assessment

The case exposes a dynamic that iQBlack has been observing across the pro-Russian ecosystem: declared access to OT/ICS systems does not operate solely as a technical demonstration. It also functions as a resource for pressure, reputation, coordination, and operational propaganda.

In its interview with iQBlack, Z-Pentest stated that OT/ICS is not the entirety of its identity, but rather one of its areas of focus. It also argued that actual service disruption carries greater weight than psychological impact and that certain situations require some degree of publicity. That self-description helps place the activity involving Canadian drinking water systems in proper context: the actor is not merely seeking to display an interface, but to establish the idea that seemingly peripheral local infrastructure can become a surface for geopolitical pressure.

The coordination with NoName057(16) is also consistent with statements made by both actors. Z-Pentest said it coordinates actions with NoName057(16) and shares political solidarity with the group, while NoName stated that it has worked with Z-Pentest for a long time and that each side understands its area of responsibility. In this cycle, that relationship appears in the narrative synchronization: two publications on the same day, involving the same country, the same infrastructure category, and shared hashtags associated with Operation Eastwood, retaliation, and pressure against Canada.

The Canadian Centre for Cyber Security had already warned that non-state actors represent a growing threat to critical infrastructure and that some have adopted the practice of targeting vulnerable Internet-connected OT systems. Its assessment of water systems notes that such activity may include interface defacement, configuration changes, and manipulation of controls, with the potential to cause unintended operation, disruption, or physical damage. The same assessment states that non-state actors are very likely to continue compromising and disrupting exposed water OT systems in Canada, particularly in connection with major geopolitical events.

The primary assessment does not require accepting every detail published by the actors as verified. The relevance lies in the pattern: pro-Russian actors select water systems, publish visual or narrative evidence, connect the activity to geopolitical campaigns, and then recycle the public response as evidence of impact. NoName described this explicitly in its interview with iQBlack: it analyzes the information agenda, official statements, and political decisions, and incorporates news events into its information activities.

Analytical Closing

The activity targeting water systems in Canada shows a convergence between exposed OT environments, pro-Russian hacktivism, and operational propaganda.

The declared access represents only one part of the cycle. The other lies in how the actor turns publication, investigation, media coverage, and institutional reaction into a second layer of pressure.

In this type of operation, the affected infrastructure matters. But so does the narrative constructed after access occurs.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved