Critical Infrastructure Security
,
Governance & Risk Management
,
Operational Technology (OT)
An Intrusion Last Year May Have Provided Hackers With a Roadmap for OT Cyberattacks
U.S. authorities are warning companies that use operational technology to take care when granting online access to third-party integrators or consultants, warning that foreign hackers are actively using such connections as a vector for cyberattacks.
See Also: How to Bridge the IT-OT Divide in Building Security
“Using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues,” states a Wednesday advisory from the Cybersecurity and Infrastructure Security Agency and the FBI. “Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks,” if they do not enforce clear security requirements, the advisory adds.
The threat is not theoretical. The advisory reports that between March 2025 and April 2025, “malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services – such as system integration [and] engineering consulting,” for clients including power utilities and transportation systems. The company specialized in a kind of OT known as supervisory control and data acquisition systems. SCADA systems enable the remote operation and monitoring of industrial machinery.
According to the advisory, FBI technical analysts found evidence that the hackers searched the company network for terms including “customers” and “SCADA.” They packaged up about 800 files they found into .zip folders “for presumed exfiltration,” although the advisory doesn’t say whether the files were actually taken – and that is often difficult to determine in forensic investigations of hacks and breaches. They included “customer SCADA information, ICS device details, and other schematics,” notes the advisory, adding that hackers could use the data “to later conduct disruptive attacks” against the company’s customers “and disrupt critical services.”
A Roadmap for Downstream Attacks
The data the hackers were trying to steal was, in effect, a roadmap for cyberattacks against the downstream clients, said Patrick Gillespie, an industrial systems security specialist who is the OT Practice Director for consultants GuidePoint Security.
Typically integrators plan a system out end-to-end, said Gillespie, and their files will contain three types of diagrams of their clients’ site: “Architectural, electrical, and network.”
“If you’re going to install a conveyor belt, you need to know how big the building is,” and what shape it is, Gillespie explained, “You need electrical diagrams: How are the sensors and the OT assets going to get power? And then of course we are sending [those assets] network traffic, so you need switches and routers and all that fun stuff.”
Taken together, those three types of diagrams provide a complete blueprint for the attacker, said Gillespie, adding that the hacked company would also likely have details of the make, model and software version of all the OT equipment they’d installed.
That kind of careful, advanced reconnaissance, hacking an integrator to lay the groundwork for downstream attacks against multiple critical power and transportation utilities, is the hallmark of “an extremely sophisticated actor, likely nation-state based,” said Michael Garcia, former associate policy chief at CISA, until June.
“If this was just a criminal, they would just have locked it up, encrypted the data, and asked for money,” added Garcia, who is now policy director for the Operational Technology Cybersecurity Coalition, a trade association representing OT device manufacturers, security vendors and other businesses in the sector.
The tone of the advisory suggested the agencies did not believe there was an active, ongoing campaign, he said. “The advisory says they are aware that this is a tactic that an adversary is using, and so they want folks to make sure that they have appropriate safeguards in place. I think the language would have been more escalatory, much more alarming if there was an active threat.”
Garcia said he did not know what accounted for the timing of the advisory, 18 months after the cyberattack on the integrator, but added it was unclear when the agencies had learned of the attack, or what other factors, like additional FBI operations, might have been in play.
“We don’t know what we don’t know,” he said.
“This is a very positive thing,” Garcia continued, “really doubling down” on information sharing. The new FBI cyber strategy calls for more communication and transparency from the agency. But Garcia noted, “The FBI and CISA push out a lot of these alerts already … and I’ll be curious to see if we actually see more of them” as a result of the strategy.
The mitigations the advisory recommends are pretty “basic, foundational” security measures, said GuidePoint Security’s Gillespie, such as least privilege, the principle that those working on the network should only have the access and authorities to do their jobs and nothing more.
OT asset owners needed to review their support contracts with integrators, because they might be able to implement the recommendations within existing contracts, Gillespie said.
“They need to figure out: Is this something I’m already paying for? Like an asset inventory, or changing default passwords. If these basics are a part of my support contract already, then the integrator shouldn’t be charging again.”
But he added there were circumstances where some of the recommendations would need to be scoped: “If it’s a customer-owned remote access tool that’s monitored by the customer, then that will typically be a different project” for the integrator, he said.
Click Here For The Original Source.
