Pro-Russian group TwoNet pivoted from DDoS attacks to targeting industrial systems, only to be caught in a researcher's honeypot. Their rapid 26-hour compromise of a fake water treatment facility revealed attempts to disable alarms and manipulate control systems. This incident highlights escalating threats to operational technology and the critical need for robust defenses.