Halil, the delta today is scale and access pattern. This is no longer “a few weakly managed water sites”; the handoff ties CyberAv3ngers-linked activity to 30+ Minnesota water/wastewater systems and at least seven U.S. states, with exposed cellular modem paths and unprotected PLC access leading to password changes, PLC program deletion, operator lockout, and manual/offline operations. LevelBlue separately notes the Minnesota campaign affected more than 30 systems and highlights internet-facing PLCs, HMIs, cellular modems, remote access, and third-party configurations as recurring weak points. Tenable says CISA observed increased PLC targeting in water/wastewater, including password changes that lock operators out and IP changes that disconnect PLCs, with no known public-health impact reported in that advisory context.
First 24 hours — safety first: put operators physically in front of the process, not just the HMI. Verify tank levels, pump status, chemical feed, lift station state, alarms, and water-quality readings locally. If automation is untrusted, move to approved manual procedures, but do not improvise around interlocks or safety logic. A false trip can interrupt water service; a missed trip can put unsafe water or sewage overflow into the real world. If there is any uncertainty on water quality, coordinate immediately with public health officials on sampling and boil-water decision thresholds.
Cyber containment: disconnect exposed cellular modems, vendor remote access, and public-facing PLC/HMI paths from the OT side in an OT-safe sequence. Do not mass-reboot PLCs or “patch now” on an IT timeline. At Purdue Level 1/2, first preserve the process state, then isolate. Rotate compromised remote-access credentials, block inbound access to PLC management interfaces, validate firewall rules between the OT DMZ and control network, and compare PLC logic against known-good offline backups before restoring automation. Any segmentation change must be tested or reviewed by controls engineers, because breaking legitimate PLC-to-HMI or telemetry paths can create the outage you are trying to prevent.
Evidence handling: before restoring from backups, capture PLC project files if still present, controller diagnostics, HMI logs, historian events, cellular modem logs, firewall/VPN logs, remote-access records, screenshots of lockout messages, changed passwords/IP settings, and timestamps of manual switchover. State fusion centers should collect a common incident template across utilities: affected equipment, access path, ISP/cellular provider, remote vendor involved, PLC/HMI vendor, changed credentials, deleted logic, and public-health status. Share that quickly with CISA, EPA, FBI, state emergency management, and neighboring utilities so this becomes a coordinated OT containment effort, not thirty isolated small-town incidents.