SEV3 — ElevatedCLOSEDCyber✓ Corroborated · 3 sources20d ago

Critical ICS/SCADA Vulnerabilities Flagged in Oklahoma City — Operations Footprint at Risk

Sentinel has flagged two severity-10 cyber alerts in Oklahoma City: a critical vulnerability in the Hydro-Québec Le Circuit Électrique EV charging station backend and a separate critical flaw in OpenPLC v3, an open-source industrial control platform. Both represent potential attack vectors against operational technology (OT) and ICS/SCADA environments, which could affect facility power management, building systems, and continuity at Oklahoma City-area contact-center and knowledge-worker sites. With approximately 199,000 combined contact-center, back-office, and knowledge-worker seats across Oklahoma — anchored in Lawton and Enid — operations leaders should confirm whether any facility infrastructure dependencies on these platforms exist and review contingency planning accordingly.

Impact Summary

Sentinel has flagged two severity-10 cyber alerts in Oklahoma City: a critical vulnerability in the Hydro-Québec Le Circuit Électrique EV charging station backend and a separate critical flaw in OpenPLC v3, an open-source industrial control platform. Both represent potential attack vectors against operational technology (OT) and ICS/SCADA environments, which could affect facility power management, building systems, and continuity at Oklahoma City-area contact-center and knowledge-worker sites. With approximately 199,000 combined contact-center, back-office, and knowledge-worker seats across Oklahoma — anchored in Lawton and Enid — operations leaders should confirm whether any facility infrastructure dependencies on these platforms exist and review contingency planning accordingly.

Domain
Cyber
Region
Oklahoma, US, US
Opened By
watchkeeper
Jul 12, 2026, 04:31 AM UTC
Validated By
auto
Jul 12, 2026, 04:31 AM UTC
Event Cluster
2 events
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 13, 2026, 05:00 PM UTC

Timeline4

Incident openedby watchkeeperJul 12, 2026, 04:31 AM UTC
Declared from 2 signals. OVIX 10. News 0. BPO 2. LLM-confirmed.
Severity validatedby autoJul 12, 2026, 04:31 AM UTC
Auto-validated: SEV3 per policy.
Note addedby watchkeeperJul 12, 2026, 04:31 AM UTC
External corroboration: corroborated (3 sources via Exa). windowsnews.ai, radar.offseq.com, assurantcyber.com
Incident closedby watchkeeperJul 13, 2026, 05:00 PM UTC
Auto-closed: no new material events within 36h for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 12, 04:31 AM UTC
Why declareddeclareHybrid
Incident declaration (deterministic floor + LLM relevance gate + geo-exposure floor)v2
DECLARE when deterministicFloor AND (llm.declare OR acuteWeatherFloor OR geoExposureFloor) AND NOT aggregateTitle, and no open same-domain incident merges it. deterministicFloor = maxSeverity>=8 AND (newsScore>=1 OR bpoScore>=1 OR acuteWeatherFloor). acuteWeatherFloor = maxSeverity>=9 AND any signal is an acute severe-weather WARNING (tornado/severe-thunderstorm/flash-flood) — overrides the LLM footprint-based suppression. geoExposureFloor (agents-034) = domain in {geopolitical, financial, labor, supply_chain, travel, infrastructure, seismic, disaster, environmental, health} AND maxSeverity>=8 AND bpoScore>=3 (density_class high/very_high — a major member hub). Anchored to member exposure (geo_density), it overrides the LLM footprint suppression so any of the ten previously-blind domains can declare when genuinely material; corroboration (2+ signals OR domain news) is guaranteed by the worthAnalyzing gate. Weather + cyber are excluded (their tuned paths are unchanged). aggregateTitle (grab-bag "Multiple/Several/Various…") is refused (agents-019 §D). Asset-class deny (military/war-zone, WFM-37) suppresses earlier. cyberFloor disabled (agents-009 hotfix).
domain
cyber
regions
["Okc"]
bpo score
2
news score
0
llm declare
yes
max severity
10
signal count
2
llm rationale
Declaring true: Oklahoma carries a substantial operations footprint (~199K seats), both CVEs are severity 10 targeting ICS/SCADA-class infrastructure that could affect facility operations, and no existing open incident covers Oklahoma City specifically — nearest open incident is Tulsa, a distinct metro.
aggregate title
no
high confidence
no
geo exposure floor
no
acute weather floor
no
deterministic floor
yes
model claude-sonnet-4-6 · prompt watchkeeper-declare-2026-06
Why SEV3SEV3score 3Deterministic
Incident severity level (SEV1–SEV4) at declarationv1
Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
2
news score
0
persistent
no
max severity
10
auto validated
yes
acute weather floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic

Related Signals3

[Okc] cyber 10.0 — Hitachi Energy e-mesh EMSsentinel19d ago[Okc] cyber 10.0 — OpenPLC v3sentinel20d ago[Okc] cyber 10.0 — Hydro-Québec Le Circuit Electrique charging station backendsentinel20d ago

External Corroboration

✓ Corroborated · 3 sourcesChecked Jul 12, 2026, 04:31 AM UTC
Critical SNMP Vulnerability in Schneider Electric Easergy Relays Opens Door to Grid Disruption - Windows Newswindowsnews.aiJul 9, 2026, 04:32 PM UTCCVE-2026-54800: CWE-1188: Initialization of a Resource with an Insecure Default in Siemens CPCI85 Central Processing/Communication - Live Threat Intelligence - Threat Radar | OffSeq.comradar.offseq.comJul 9, 2026, 02:15 PM UTCSchneider Electric EasyLogic T150 and Saitel DP RTU - ASSURANT™assurantcyber.comJun 30, 2026, 12:00 PM UTC

Affected Regions

Okc