A pro-Russian hacktivist group known as TwoNet falsely claimed responsibility for hacking a Western water treatment plant, when in reality, their attack targeted a honeypot system set up by security researchers at Forescout. The group boasted on Telegram about their supposed success, including defacing a human-machine interface (HMI) login page with a message, but Forescout confirmed that the system was a decoy designed to attract and study attackers. TwoNet's intrusion originated from an IP address registered to a German hosting provider, which had little prior association with malicious activity. The attackers gained access to the HMI using default credentials ('admin'/'admin'), highlighting the ongoing risk posed by weak authentication practices in critical infrastructure environments. After gaining access, the attacker executed SQL queries to enumerate the database schema and created a new user account under the alias "BARLATI." The group then exploited a known vulnerability, CVE-2021-26829, to alter the login page and display their defacement message. Forescout's analysis revealed that TwoNet's claims of compromising operational technology were fabricated, as the only system affected was the research honeypot. The incident underscores the ephemeral nature of hacktivist groups, with TwoNet ceasing operations by the end of September and its main Telegram handles going dark. Despite the group's short lifespan, the event serves as a warning that even unsophisticated actors can generate significant media attention and potentially influence public perception by fabricating attacks. Forescout emphasized that such groups often rebrand or join other collectives, maintaining a persistent threat to critical infrastructure. The use of honeypots by defenders remains a valuable tool for gathering intelligence on attacker tactics and motivations. The incident also highlights the importance of verifying claims of cyberattacks, especially when they involve critical infrastructure, to prevent unnecessary alarm and misinformation. Security researchers continue to monitor similar groups for signs of evolving tactics or renewed activity. The event demonstrates the ongoing cat-and-mouse dynamic between threat actors seeking notoriety and defenders leveraging deception to study and mitigate threats. Organizations are reminded to secure remote interfaces, avoid default credentials, and stay vigilant against both real and fabricated threats. The case also illustrates the role of public messaging and disinformation in modern cyber conflict, particularly among ideologically motivated groups. Finally, the exposure of TwoNet's fabricated attack provides actionable lessons for both defenders and policymakers in assessing and responding to claims of cyber incidents targeting essential services.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of Forescout's findings, researchers disclosed that TwoNet's claimed breach of a Western water utility was actually an intrusion into a honeypot and warned that even failed or misdirected operations can signal growing interest in critical-infrastructure targeting.
Forescout said key TwoNet-associated handles, including BARLATI and DarkWarios, went inactive and the group appeared to stop operating around this date. The firm noted this fits a pattern of short-lived hacktivist branding, even if operators may later rebrand or shift alliances.
TwoNet targeted what it claimed was a Western water treatment plant, but the system was actually a Forescout-operated honeypot. The attacker accessed the HMI with default credentials, ran SQL queries to enumerate the database, created a new account, and exploited CVE-2021-26829 to deface the login page.
Forescout assessed that the pro-Russian hacktivist group TwoNet evolved from an initial focus on DDoS operations to attempting intrusions against HMI and SCADA interfaces in countries it viewed as adversaries. The group also made dubious claims about selling a new crypto-locker and offering access to SCADA systems in Poland.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.