SEV3 — ElevatedCLOSEDCyber✓ Corroborated · 3 sources20d ago

Critical ICS/SCADA Vulnerabilities Flagged in Des Moines — Operations Footprint at Risk

Two Severity-10 cybersecurity alerts have been triggered in Des Moines, Iowa, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial control system (ICS/SCADA) platforms used in energy and facility management environments. Although no corroborating news coverage has surfaced, the maximum-severity ratings and the pattern alignment with similar open incidents in Colorado Springs, Omaha, and Tulsa suggest a coordinated or systemic advisory wave targeting ICS infrastructure across U.S. metro areas. Des Moines carries a meaningful operations footprint (~55,950 knowledge-worker seats, ~22,410 back-office seats, ~11,270 contact-center seats), and exploitation of energy-management or programmable-logic-controller vulnerabilities could affect facility power stability and site continuity for those hubs.

Impact Summary

Two Severity-10 cybersecurity alerts have been triggered in Des Moines, Iowa, flagging critical vulnerabilities in Hitachi Energy e-mesh EMS and OpenPLC v3 — both industrial control system (ICS/SCADA) platforms used in energy and facility management environments. Although no corroborating news coverage has surfaced, the maximum-severity ratings and the pattern alignment with similar open incidents in Colorado Springs, Omaha, and Tulsa suggest a coordinated or systemic advisory wave targeting ICS infrastructure across U.S. metro areas. Des Moines carries a meaningful operations footprint (~55,950 knowledge-worker seats, ~22,410 back-office seats, ~11,270 contact-center seats), and exploitation of energy-management or programmable-logic-controller vulnerabilities could affect facility power stability and site continuity for those hubs.

Domain
Cyber
Region
Des Moines, US, US
Opened By
watchkeeper
Jul 11, 2026, 10:30 PM UTC
Validated By
auto
Jul 11, 2026, 10:30 PM UTC
Event Cluster
2 events
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 13, 2026, 11:00 AM UTC

Timeline4

Incident openedby watchkeeperJul 11, 2026, 10:30 PM UTC
Declared from 2 signals. OVIX 10. News 0. BPO 1. LLM-confirmed.
Severity validatedby autoJul 11, 2026, 10:30 PM UTC
Auto-validated: SEV3 per policy.
Note addedby watchkeeperJul 11, 2026, 10:30 PM UTC
External corroboration: corroborated (3 sources via Exa). waterisac.org, windowsnews.ai, assurantcyber.com
Incident closedby watchkeeperJul 13, 2026, 11:00 AM UTC
Auto-closed: no new material events within 36h for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 11, 10:30 PM UTC
Why declareddeclareHybrid
Incident declaration (deterministic floor + LLM relevance gate + geo-exposure floor)v2
DECLARE when deterministicFloor AND (llm.declare OR acuteWeatherFloor OR geoExposureFloor) AND NOT aggregateTitle, and no open same-domain incident merges it. deterministicFloor = maxSeverity>=8 AND (newsScore>=1 OR bpoScore>=1 OR acuteWeatherFloor). acuteWeatherFloor = maxSeverity>=9 AND any signal is an acute severe-weather WARNING (tornado/severe-thunderstorm/flash-flood) — overrides the LLM footprint-based suppression. geoExposureFloor (agents-034) = domain in {geopolitical, financial, labor, supply_chain, travel, infrastructure, seismic, disaster, environmental, health} AND maxSeverity>=8 AND bpoScore>=3 (density_class high/very_high — a major member hub). Anchored to member exposure (geo_density), it overrides the LLM footprint suppression so any of the ten previously-blind domains can declare when genuinely material; corroboration (2+ signals OR domain news) is guaranteed by the worthAnalyzing gate. Weather + cyber are excluded (their tuned paths are unchanged). aggregateTitle (grab-bag "Multiple/Several/Various…") is refused (agents-019 §D). Asset-class deny (military/war-zone, WFM-37) suppresses earlier. cyberFloor disabled (agents-009 hotfix).
domain
cyber
regions
["Des Moines"]
bpo score
1
news score
0
llm declare
yes
max severity
10
signal count
2
llm rationale
Declaring true: Des Moines has a substantive multi-category operations footprint, the dual Sev-10 ICS/SCADA alerts match a developing pattern across peer cities with active open incidents, and the vulnerability classes (energy management systems, PLCs) carry direct facility-continuity risk — though no news confirmation yet, the signal severity and pattern warrant escalation pending validation.
aggregate title
no
high confidence
no
geo exposure floor
no
acute weather floor
no
deterministic floor
yes
model claude-sonnet-4-6 · prompt watchkeeper-declare-2026-06
Why SEV3SEV3score 3Deterministic
Incident severity level (SEV1–SEV4) at declarationv1
Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
1
news score
0
persistent
no
max severity
10
auto validated
yes
acute weather floor
no
Geo Provenance
Tiercentroid
Sourcegeo_density
Deterministic

Related Signals10

[Des Moines] cyber 10.0 — Hitachi Energy e-mesh EMSsentinel20d ago[Des Moines] cyber 10.0 — Hitachi Energy PROMOD Vsentinel20d ago[Des Moines] cyber 10.0 — Digi International PortServer TS, Digi One SP IAsentinel20d ago[Des Moines] cyber 10.0 — OpenPLC v3sentinel20d ago[Des Moines] cyber 10.0 — Hydro-Québec Le Circuit Electrique charging station backendsentinel20d ago[Des Moines] cyber 10.0 — OpenPLC v3sentinel20d ago[Des Moines] cyber 10.0 — Hydro-Québec Le Circuit Electrique charging station backendsentinel20d ago[Des Moines] cyber 10.0 — Digi International PortServer TS, Digi One SP IAsentinel20d ago[Des Moines] cyber 10.0 — OpenPLC v3sentinel21d ago[Des Moines] cyber 10.0 — Hitachi Energy e-mesh EMSsentinel21d ago

External Corroboration

✓ Corroborated · 3 sourcesChecked Jul 11, 2026, 10:30 PM UTC
(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – July 9, 2026 - WaterISACwaterisac.orgJul 9, 2026, 06:30 PM UTCCritical SNMP Vulnerability in Schneider Electric Easergy Relays Opens Door to Grid Disruption - Windows Newswindowsnews.aiJul 9, 2026, 04:32 PM UTCSchneider Electric EasyLogic T150 and Saitel DP RTU - ASSURANT™assurantcyber.comJun 30, 2026, 12:00 PM UTC

Affected Regions

Des Moines