Reporting described how digital sabotage of industrial control systems (ICS) can translate directly into physical disruption of critical infrastructure, using a Caracas blackout scenario to illustrate how attackers could manipulate modern, internet-connected controllers. The piece highlights techniques where malware can create a “split reality” by intercepting legitimate operator commands and substituting malicious instructions to destabilize grid operations, underscoring how grid modernization expands the attack surface and enables cyber effects to be synchronized with real-world operations.
Separate commentary on San Francisco’s “Waymo Freeze” argued that even without a cyber compromise, tightly coupled cyber-physical systems can fail at scale when environmental dependencies break (e.g., traffic signals and city systems impacted by a power outage). It framed the incident as an identity and resilience problem—asserting that static device identity models (e.g., PKI-based trust) do not ensure operational continuity when conditions change—highlighting the broader executive risk that safety defaults and fail-safe behaviors can still produce city-level disruption during outages or cascading infrastructure failures.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-03, the article presents a hypothetical Caracas blackout scenario to illustrate how attackers could manipulate industrial control systems, issue damaging commands, and feed operators falsified sensor data. The example is used to explain how a 'split reality' attack could delay response until physical damage occurs.
In December 2025, a local power outage in San Francisco caused a fleet of Waymo autonomous vehicles to halt in place under safety protocols, disrupting transit and obstructing emergency responders. The incident was described as an infrastructure failure rather than a cyber compromise.
In 2023, the China-linked Volt Typhoon activity was exposed, highlighting adversary efforts to position within critical infrastructure environments for potential future disruption. The disclosure underscored the strategic risk to utilities and other essential services.
In 2016, Russia's Industroyer malware was used against Ukraine's electric grid, showing that grid operations could be directly manipulated through malicious control of industrial systems. The attack is cited as a key precedent for infrastructure-focused cyber warfare.
In 2009, the Stuxnet malware demonstrated that cyber operations could cause physical damage by targeting Iranian nuclear centrifuges through industrial control systems. The incident became a landmark example of cyber-to-physical sabotage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
techxplore.com
Open sourcescworld.com
Open sourcetheconversation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.