FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #11
FBI WARNS

An official IC3 public service announcement dated 2026-07-30 names malicious cyber actors targeting internet-facing programmable logic controllers in the water and wastewater sector.

LOW CONFIDENCEPublished 2026-08-15
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

An official IC3 public service announcement published 2026-07-30 is titled to name malicious cyber actors targeting internet-facing programmable logic controllers in the water and wastewater sector. We harvested only that advisory's title, link and publication date, so we cannot describe how the targeting works, who was affected, where, or what any operator should expect to see. Nothing in our harvested material describes any phone call, email, text or invoice sent to consumers or utility staff, so treat any message that claims to be about this advisory as unconfirmed. If someone contacts you claiming your water utility's systems are compromised and asks you to pay, log in, or grant remote access, hang up and call the utility back on the number printed on your own bill. LIVEFRAUD ALERTS is an independent consumer awareness desk and is not affiliated with any government agency or utility; this alert rests on one official advisory record and will be updated only if further rows are harvested.
THE RULE
Low actionable risk to consumers as harvested: an official advisory title names a targeting activity, but we hold no detail on method, reach or any contact made to individuals.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. 2 OF 3 — ONE MODEL DISSENTED. READ WHY.

The card names a count. Here are the seats behind it, with what each one said.

GOOGLEgemini-flash-latest · MODERATE
Raised no objection; read the evidence as holds.
GROQopenai/gpt-oss-120b · MODERATE
The recommendation to treat any message about the advisory as unconfirmed could cause readers to dismiss legitimate communications from their utility, potentially delaying real incident response.
OPENROUTERopenrouter/free · LOW
The evidence only provides the advisory’s title; the finding restates that title, which is permissible and does not overstate the source.

Reviewed by 3 independent models; all found the finding carried by the evidence.

▼ Protocol & challenge record
Objection (high): Selective omission that flips the risk picture. The harvested title reads '... Programmable Logic Controllers, Causing Operational Disruptions.' The draft silently drops the 'Causing Operational Disruptions' clause — the single most consumer-relevant assertion available — and then states in the risk line 'Low actionable risk to consumers as harvested.' The one row we hold says an official body asserted operational disruption of water/wastewater control systems. Either carry that clause (and adjust the risk line to acknowledge that the source itself asserts service-affecting impact, while noting we hold no scale or geography) or explain the omission. As written, the alert under-reports the source and mischaracterises it as low-consequence.
Not resolved — preserved on the record.
Objection (high): Overclaim in the verb 'names'. The claim line — 'names malicious cyber actors targeting internet-facing programmable logic controllers' — reads to an ordinary reader as attribution, i.e. that the advisory identifies specific threat actors or a group. The title uses the generic boilerplate phrase 'malicious cyber actors' and names nobody. The finding's contorted repair ('is titled to name malicious cyber actors') does not fix the claim line and is barely parseable. Use 'describes' / 'warns of unnamed malicious cyber actors' and state explicitly that no actor, group or country is identified in the harvested material.
Resolved: Partially addressed only. The finding hedges to 'is titled to name', but the claim line still says 'names'. Requires an edit to the claim line: 'warns of unnamed malicious cyber actors' plus an explicit unknown that no actor is identified.
Objection (medium): Audience/advice mismatch, and an invented scenario. The audience callout addresses the water and wastewater SECTOR (operators), while the only advice given is consumer anti-scam advice about phone calls, payment demands and remote access — a scenario the draft itself concedes has zero support in the harvested row. IC3 PSAs of this type are operator-facing. Building a consumer scam script around an OT/ICS advisory is scope creep by the desk: it manufactures the impression that impersonation calls tied to this advisory are circulating. If the advice stays, it must be labelled unambiguously as generic standing hygiene, not as a response to this advisory.
Resolved: Partially addressed. The limitation sentence 'Nothing in our harvested material describes any phone call, email, text or invoice...' does disclose the gap, and the advice is framed conditionally ('If someone contacts you...'). Remaining defect is the operator-facing callout sitting on top of consumer-facing advice, which is unresolved.
Objection (medium): The single most useful action is missing. We hold exactly one thing of value — the primary-source URL (https://ic3.gov/PSA/2026/PSA260730.pdf). The finding never tells the reader to go read it, yet devotes two sentences to a hypothetical phone call. For a title-only harvest, 'read the source, we cannot summarise it' is the honest and highest-value directive.
Not resolved — preserved on the record.
Objection (medium): Provenance and existence of the document are unverified. The row supplies title, URL and a date; nothing indicates the URL was fetched, resolved, or that the title string is verbatim IC3 wording rather than a feed/aggregator summary. The 'official' label appears to be a pipeline classification, not an independent verification. The domain is plausibly IC3 (ic3.gov, no www) and the PSA260730 filename is internally consistent with a 2026-07-30 date, but consistency is not confirmation. Calling it 'An official IC3 public service announcement' asserts more provenance than a single unfetched metadata row establishes.
Resolved: Partially addressed. The evidence block and confidence_reasons state that only title, URL and date were harvested and that no body text is held, which fairly warns the reader. The residual issue is the unqualified word 'official' in the claim line.
Objection (low): Date currency / timestamp artefact. The publication value is 2026-07-30T23:00:00+00:00 — a 23:00 UTC stamp on a US government release is the signature of a date-only field being normalised with a timezone offset. It can indicate an off-by-one day. Separately, the Desk must confirm this date is not in the future relative to the harvest run; a future-dated 'official' row is a feed-integrity red flag, not a scoop.
Resolved: Not addressed; no timestamp or currency caveat appears anywhere in the draft.
Objection (low): Internal inconsistency in the targeting rule. A share directive to 'utility' handles was dropped under §11 Rule 2 on the ground that naming a group implies that group is targeted — yet 'ATTENTION: WATER AND WASTEWATER SECTOR' is retained. Here the retention is defensible because the source title itself names the sector, but the reasoning should be stated, otherwise the rule looks applied arbitrarily.
Resolved: Addressed in part by targeting_dropped, which records the reasoning for the dropped directive; it does not explain why the sector callout survives the same rule.
Objection (low): Attribution narrowness. Advisories of this kind are frequently joint issuances (FBI/IC3 with CISA, EPA, WaterISAC). Nothing harvested tells us whether this one is sole or joint, so 'An official IC3 public service announcement' should be presented as what the URL indicates rather than as a settled fact about authorship.
Not resolved — preserved on the record.
Preserved dissent
ON THE RECORDI would not publish this as drafted. Two defects are substantive, not stylistic. First, the draft quietly deletes 'Causing Operational Disruptions' from the one title it holds and then tells readers the risk is low. That is the desk deciding to report less than its single source says, in the direction that makes the story calmer. If the only evidence we have asserts operational disruption to water systems, the alert must say so and must not carry a 'low actionable risk' line without directly reconciling the two.
ON THE RECORDSecond, 'names malicious cyber actors' will be read as attribution. The advisory names nobody; 'malicious cyber actors' is generic government boilerplate. Publishing a claim line that implies an actor has been identified, then walking it back with the unreadable phrase 'is titled to name', is an overclaim dressed as a hedge.
ON THE RECORDThird, and more broadly: from a title, a link and a date on an operator-facing ICS advisory, this desk has produced a consumer scam script about phone calls and payment demands that it simultaneously admits no source supports. That is manufacturing a fraud angle to justify an alert. The defensible output from a title-only row is a pointer — 'IC3 published this advisory on this date; we hold only the title; read it here' — or no alert at all. I record that I regard the current shape as scope creep, and I regard the omission in OBJ-1 as the more serious of the two, because it changes the reader's sense of consequence rather than merely of certainty.

The sources

Official sourceMalicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions2026-07-30
An official IC3 public service announcement published 2026-07-30 is titled to name malicious cyber actors targeting internet-facing programmable logic controllers in the water and wastewater sector.
Authority: official. Retrieved 2026-08-15.
Limitation: Only the title, URL and publication date were harvested; the document body was not, so no statement about impact, technique, geography or number of affected entities can be drawn from this row.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/n3-34hQ

Approved by ihubglobalhq on 2026-08-17, after review of the alert and its sources.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.