The Containment Era is here. →Explore

Executive Summary

In September 2025, the pro-Russian hacktivist group TwoNet targeted what they believed to be a vulnerable water treatment plant, unaware it was a decoy system (honeypot) operated by cybersecurity researchers. The attackers gained access using default credentials, escalated attacks through SQL enumeration, and exploited a known XSS vulnerability (CVE-2021-26829). Within 26 hours, they created new user accounts, manipulated PLC setpoints, disabled real-time updates, and attempted to disrupt both logs and alarms via the Human Machine Interface (HMI). Their tactics included data exfiltration and process disruption, signaling a shift toward operational technology (OT) attacks targeting critical infrastructure.

This incident highlights a growing trend of hacktivist groups evolving from DDoS and defacement attacks to more sophisticated operations against OT and ICS targets. The rapid escalation and attempted sabotage observed in this breach emphasize the urgent need for robust segmentation, authentication, and real-time anomaly detection within critical infrastructure environments.

Why This Matters Now

Critical infrastructure organizations are increasingly targeted by hacktivist groups employing advanced tactics beyond traditional DDoS. The TwoNet case demonstrates how quickly attackers can pivot to disrupting industrial environments, signaling an urgent need to remedy legacy vulnerabilities, enforce network segmentation, and protect operational technology assets now.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed weak authentication, vulnerable internet-exposed HMIs, lack of network segmentation, and insufficient anomaly detection, all of which are critical for OT/ICS security compliance.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF Zero Trust controls—such as network segmentation, policy-based access, anomaly detection, and egress filtering—would have reduced the attack surface, prevented unauthorized access, and detected disruptive actions across the kill chain. Inline traffic inspection and identity-based policies could block or alert on malicious activity, limiting opportunities for both access and impact.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Prevents unauthorized access to critical HMI applications from unknown networks.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Detects anomalous account creation and suspicious privilege changes.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks or monitors unauthorized workload-to-workload and inter-service communications.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Detects and blocks suspicious inbound/outbound web access to critical service endpoints.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents unauthorized exfiltration to external destinations.

Impact (Mitigations)

Detects abnormal operations and alerts on critical unauthorized changes to industrial controls.

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • System Monitoring
  • Alarm Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

No sensitive data exposure occurred as the attack targeted a decoy system designed for research purposes.

Recommended Actions

  • Eliminate public exposure of HMI, SCADA, and OT interfaces using Zero Trust Segmentation.
  • Enforce strong, unique credentials and monitor for account creation or misuse through anomaly detection.
  • Apply east-west microsegmentation to limit intra-network movement and strictly control service communications.
  • Deploy centralized cloud firewalls and enforce egress filtering to prevent unapproved remote access and data exfiltration.
  • Continuously monitor for PLC/HMI anomalies, unusual setpoint changes, and generate rapid alerts to contain destructive actions.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image