The strongest supported fact is the campaign pattern: CISA says actors modified PLC passwords, changed device IP addresses, locked out operators, and in some cases forced boil-water notices and sustained manual operation. CISA also attributes access to Iranian-affiliated actors targeting internet-facing Rockwell/Allen-Bradley, Schneider Electric, and Siemens PLCs. But the available reporting does not independently establish that the Georgia pressure loss was caused by an attacker rather than coincident equipment failure or loss of supervisory access. That remains an unknown causal link. (CISA advisory, CISA water-sector alert, Gizmodo)
To prove process disruption at Level 1, investigators need a synchronized timeline showing: an authenticated or network-recorded controller change; a resulting change in pump commands, VFD state, valve position, setpoints, or control logic; and then a matching pressure decline confirmed by independent field instruments, flow meters, tank levels, and electrical load. A changed PLC IP followed only by an unreachable HMI is evidence of loss of Level 2 operator visibility, not proof that the physical process changed. Conversely, breaker trips, VFD fault codes, loss of utility power, mechanical pump alarms, leaks, or a pressure decline preceding the cyber event would favor ordinary equipment failure. Preserve the PLC image and project file, controller diagnostics, historian tags, HMI alarms, engineering-workstation activity, firewall/VPN/cellular logs, and physical maintenance records before resetting anything.
The reported infostealer exposure associated credentials with 1,787 water providers. That materially widens the initial-access problem, especially for remote-access portals, vendor accounts, email, and engineering support systems—but it is exposure evidence, not proof that those credentials reached a PLC or caused pressure loss. Operators should immediately identify affected identities, reset passwords, revoke active sessions and tokens, rotate shared/vendor credentials, and review authentication from unfamiliar infrastructure. Remote OT access should require a controlled jump host and MFA rather than direct device exposure. (SpyCloud, Cryptonomist)
For safety and continuity, move affected stations to verified local or manual control under existing operating procedures; increase independent pressure, tank-level, and water-quality checks; remove direct internet reachability to PLCs; block observed hostile infrastructure; and verify a known-clean controller backup, as CISA recommends. Do not casually reboot, flash, or re-address a running controller: first confirm the fallback control path and test any segmentation change, because severing legitimate Level 1 communications can create the very loss of control we are trying to prevent. These actions are necessary regardless of whether attribution ultimately holds.