Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-08 and was added to the RWP archive on 2026-09-07.
Data-center OT is the cooling loop and the substation — NERC already rang the load alarm
Nozomi 8 June 2026 — compromise the chillers, take the racks. NERC Level 3 Essential Action 4 May 2026 on large-load swings. Claroty's July census: 1 in 5 data-center CPS assets one hop from a risky outbound path.
Bottom line up front
CONFIRMED Nozomi, 8 June 2026 — data centers are OT: cooling, PDUs, on-site substations, generators. Knock the thermal path, the compute follows. NERC 4 May 2026 Level 3 "Essential Action" after customer-initiated large-load reductions and oscillations that play out in seconds. Claroty 29 July (750k+ CPS assets): nearly 1 in 5 one hop from systems making outbound connections; PDUs 41 percent and HVAC 32 percent highest "exposed or one hop"; 88 percent of BMS on insecure protocols; 23 percent of DC IoT with KEVs. This is not a named intrusion. Process/availability impact: ASSESSED as the design risk; not a 2026 hyperscale outage attributed here. UK CNI designation for data centers cited by Nozomi as policy backdrop.
Historical backfill of 8 June 2026 reporting; added 7 September 2026.
What happened
A sector brief, then a census. The grid noticed AI load before most SOCs noticed BACnet in the hall.
Why it mattered
Cloud IR that never walks the chiller plant is incomplete. So is utility IR that treats the campus substation as "the customer's problem."
Who / what was affected
Hyperscale, colo, enterprise DC physical plant. Not a victim list.
Technical context
Segment BMS. Patch KEVs on IoT in the hall. Monitor BACnet/Modbus. Treat vendor HVAC remote access as jump-host.
Exploitation / threat status at the time
CONFIRMED NERC alert + Claroty exposure math.
UNKNOWN a 2026 campaign that used cooling as the payload.
What defenders should have done
- Joint tabletop: IT + facilities + the serving utility.
- Inventory PDUs/HVAC like servers.
- Read Vertiv/Trane posts already in this archive as the CVE layer.
RWP assessment
Confidence: High on the exposure thesis. Do not invent a "data-center Stuxnet."
Defensive actions
- One asset list for compute and plant.
- Compensating controls on insecure BMS protocols.
- NERC large-load playbook if you are the load.
Sources
- Nozomi Networks — Data center infrastructure — overlooked cyber-physical attack surface
- Claroty Team82 — State of CPS Security: data center exposures (29 July 2026)
- NERC Level 3 Essential Action alert 4 May 2026 (large load reductions / oscillations) — NERC Level 3 Essential Action alert 4 May 2026 (large load reductions / oscillations)