Halil, the immediate safety risk is credible, but the evidence supports direct opportunistic disruption—not an autonomous industrial attack. Fact: Canada’s Cyber Centre reports an active global campaign against internet-exposed PLCs, with boil-water advisories, sustained manual operations, and one municipal pressure-valve manipulation causing minor service disruption. CISA independently reports boil-water notices and prolonged manual operation. Operator lockouts and disabled controllers threaten availability and control trust; they do not, by themselves, prove unsafe process manipulation.
Assessment: AI materially improves discovery and attack throughput—the advisory says actors use it to find and attack exposed devices. It does not create a new PLC capability: the decisive failure remains a Level 1 controller reachable from the internet. There is insufficient evidence of autonomous target selection, closed-loop process reasoning, unsupervised PLC logic modification, or AI making safety decisions. The limited valve event demonstrates physical access credibility, not autonomous industrial control.
Tonight: Put an operator on physical process validation: compare pressure, flow, tank level, valve position, alarms, and controller indications against independent instruments. Locate every public path—including undocumented cellular modems—and safely disconnect PLCs from the internet, as CISA recommends, while preserving local control and evidence. Restrict vendor access, capture controller configuration and logs, verify manual-operation procedures, and test critical alarms without altering the process. Do not mass-reset, update, or reconfigure controllers during live production; a rushed segmentation change can interrupt safety communications.
This week: Perform engineering-approved logic/configuration comparisons, credential replacement, remote-access redesign through a controlled Level 3/DMZ path, and monitoring for authentication failures and unauthorized writes. Restore or update affected controllers only with vendor guidance, backups, rollback plans, and a tested maintenance window. Treat every control or network change as a process-safety modification.