🔴 [LATEST] THEGARUDAEYE TAKES DOWN PARAGUAY'S IMMIGRATION SERVER FOR 12 HOURS    ◆    🔴 [LATEST] THEGARUDAEYE DOWNS PARAGUAY FOREIGN MINISTRY OVER TRUMP’S BOARD OF PEACE    ◆    🔴 [LATEST] NONAME057(16) DDOS CAMPAIGN TARGETS GERMAN FERRY AND CITY SERVICES    ◆    🔴 [LATEST] CHAT CONTROL PROTEST: RIPPERSEC BREACH ITALIAN SCADA SYSTEM    ◆    🔴 [LATEST] ANGMAR MEDICAL BREACH & BEACON HACK EXPOSE 710GB DATA

[ SYSTEM_MENU ]

> ESTABLISH_CONNECTION

[ X_TWITTER ] [ TELEGRAM ] [ INSTAGRAM ] [ THREADS ] [ UPSCROLLED ]

CYBERASIA INTEL
Independent portal uncovering global cyber warfare operations, tracking APTs, and reporting zero-day vulnerabilities.

~/SCADA & IoTarticle

SCADA & IoT

BMS Cyberattack: Disrupt0r Hacks Quinquela Plaza SCADA

> By Haider | Aug 12, 2026 | 4 min read

A severe BMS cyberattack has exposed the critical infrastructure of QUINQUELA PLAZA in Argentina, highlighting the inherent physical risks associated with internet-connected industrial control systems. The breach, orchestrated by a threat actor operating under the alias Disrupt0r, granted deep, unauthenticated access to the facility’s Building Management System (BMS). By bypassing standard security gateways, the attacker exposed sensitive SCADA (Supervisory Control and Data Acquisition) interfaces to direct external manipulation.

According to the raw evidence released by the attacker, the compromised HMI (Human-Machine Interface) provided administrative control over essential building systems. STIB Ingeniería de Aplicación was identified as the local system integrator associated with the targeted location.

BMS Cyberattack
> TABLE_OF_CONTENTS [toggle]

Anatomy of the BMS Cyberattack and System Failures

Telemetry from the exposed SCADA dashboard indicates active interference with the building’s water heating and pressurization networks. The threat actor documented multiple critical alarms triggered during the unauthorized session, demonstrating the potential for physical equipment damage through improper operation. The speed at which this BMS cyberattack escalated from reconnaissance to active disruption underscores a growing trend of hacktivists pivoting from digital vandalism to physical sabotage.

> TARGET_INFRASTRUCTURE: QUINQUELA PLAZA BREACH

  • Target Facility: QUINQUELA PLAZA (Argentina).
  • Compromised System: Building Management System (BMS) / SCADA.
  • Threat Actor: Disrupt0r.
  • Vulnerability: Unauthenticated access to building automation interfaces.

The system’s operational data, logged consistently since its commissioning in November 2018, revealed that both primary pumps (Grupo 1) were pushed into a critical failure state (FALLA). The attacker also recorded localized warnings including “Falla Recirculadora 1 grupo 1” (Recirculation pump failure) and “Baja Presion Hidro 1/2” (Low hydraulic pressure warnings). Furthermore, temperature sensors for the six interconnected water heaters (Termos 1-6) were observed plummeting to a baseline of 0.0°C.

Security Assessment and Subsystem Exposure

Unlike standard IT data breaches or volumetric DDoS attacks, compromising a BMS poses immediate, tangible physical risks. The unauthenticated access achieved by Disrupt0r theoretically enables HVAC disruption (complete heating and cooling shutdowns), comprehensive water system manipulation, generator control, and false alarm injection.

Additional hardware and logic systems marked as accessible during the session included four hydraulic stations (Estación Hidro 0-3), the central pressurization system, internal electrical transformers, cistern monitoring mechanisms, drainage systems, and overflow controls (Preset: 5000). The sheer scope of this BMS cyberattack illustrates the danger of leaving broad operational technology networks visible to external port scanners like Shodan or Censys.

Defensive Posture & OT Mitigation Strategies

The exposure of Quinquela Plaza’s infrastructure highlights systemic vulnerabilities in how third-party integrators deploy Building Management Systems. To defend against unauthorized SCADA manipulation, facility operators must implement zero-trust architecture across all Operational Technology (OT) environments:

  • Enforce the Purdue Reference Architecture: Strict network segmentation is non-negotiable. OT and ICS networks must be entirely isolated from corporate IT environments using industrial-grade firewalls. BMS interfaces must never be exposed to the public internet or indexable by edge scanners.
  • Eradicate Vendor-Default Configurations: System integrators notoriously deploy physical infrastructure using hardcoded credentials or bypassed authentication loops to ease remote troubleshooting. Mandate comprehensive audits of all HMI panels, PLCs (Programmable Logic Controllers), and BACnet/Modbus gateways to enforce cryptographic authentication.
  • Deploy Protocol-Aware Anomaly Detection: Standard IT intrusion detection systems cannot interpret industrial commands. Deploy ICS-specific Deep Packet Inspection (DPI) capable of analyzing SCADA protocols. These systems must block erratic operational commands, such as sudden temperature threshold drops or simultaneous pump shutdowns, before they reach the physical controllers.
  • Implement Secure Remote Access (SRA): If remote administration is strictly necessary, it must traverse a hardened VPN tunnel equipped with phishing-resistant Multi-Factor Authentication (MFA), session recording, and Just-In-Time (JIT) access provisioning.
> DISCLAIMER

The information provided in this article is for educational and threat intelligence purposes only. CyberAsia does not condone, promote, or encourage any illegal activities. The claims reported herein are based on open-source intelligence published by threat actors on dark web and encrypted channels.


> subscribe_to_intel

Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.


Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing BMS Cyberattack: Disrupt0r Hacks Quinquela Plaza SCADA is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.

> share_intel.sh [ X ] [ TG ]

> ABOUT_AUTHOR: Haider

Lead Security Researcher & Malware Reverse Engineer specializing in deconstructing APT toolkits and validating underground breach claims.

> related_intel --suggest