Operational Technology & Industrial Security
Fully-sourced analysis of real, documented OT/ICS incidents — and an active, in-progress build translating that research into hands-on infrastructure.
Muleshoe, Texas — A Water Facility, a Third-Party Login
On January 18, 2024, the City of Muleshoe discovered its water system's SCADA had been compromised — through a third-party vendor's remote login system, per the City Manager's own statement — causing a storage tank to overflow. Two other Texas towns were targeted around the same time.
A hacktivist persona claimed credit and was linked by Mandiant to prior Sandworm (Russian GRU-linked) activity — but Mandiant explicitly could not confirm Sandworm's direct operational involvement in this specific attack. Most public reporting collapsed that distinction anyway.
Dragos 2026: The Economics of OT Ransomware Changed
Dragos's 2026 OT Cybersecurity Year in Review (covering 2025 activity) tracked 119 ransomware groups capable of affecting operational environments — up from 80 the year before. 3,300 industrial organizations were impacted; manufacturing accounted for more than two-thirds of victims.
The single most quotable finding: average detection time industry-wide was 42 days. Organizations with real OT-specific visibility detected and contained incidents in an average of 5 days. Dragos also found that no specialized ICS malware was required — ordinary IT-side ransomware caused real OT consequences purely through interconnection, and OT devices running Windows often get misclassified as "IT only" by responders without OT expertise.
The Build, In Progress
I'm building a small, self-directed edge computing system — real physical Zigbee sensors reporting to a repurposed laptop acting as a local coordinator, designed to explore resilient, offline-capable field systems hands-on rather than just analyze them secondhand.
Honest current status: the coordinator (a repurposed laptop) and a Zigbee USB coordinator dongle are in place. Physical sensors have not yet been purchased. Planned architecture includes WireGuard for secure connectivity and, later, Zeek — a network monitoring tool I have real, hands-on experience with from prior SOC analyst work — for anomaly detection. No field deployment or range/security testing has happened yet.
I'd rather describe this honestly, mid-build, than wait until it's finished to talk about it at all.
Sources
Muleshoe, Texas
CNN, "Russia-linked hacking group suspected of carrying out cyberattack on Texas water facility" (Apr. 17, 2024) —
cnn.com
Axios, "Russia-linked hackers claim cyberattacks on U.S., French and Polish water utilities" —
axios.com
EverythingLubbock.com, official City of Muleshoe statement via City Manager Robert Sanchez —
everythinglubbock.com
Dragos 2026 OT Cybersecurity Year in Review
Dragos official press release, "Dragos 2026 OT Report Shows Surge in Threat Groups and Ransomware" (Feb. 17, 2026) —
dragos.com
Kiteworks, "Dragos 2026 Report: OT Cybersecurity Threats Evolve," quoting Dragos CEO Robert M. Lee directly —
kiteworks.com