Supply Chain Risk for Critical Infrastructure via ICS Integrators
Foreign threat actors compromised a U.S. industrial automation integrator between March and April 2025 to exfiltrate sensitive SCADA schematics and device details, creating potential pivot points into downstream critical infrastructure networks.
CISA and the FBI have issued guidance following the observation of foreign cyber actors compromising a U.S. industrial automation solutions company. Between March and April 2025, attackers gained unauthorized access to the integrator's network, which provides engineering, SCADA programming, and consulting services to power utilities and transportation entities. The threat actors conducted extensive reconnaissance, specifically searching for terms like "customers" and "SCADA," resulting in the creation of nine .zip files containing approximately 800 files for exfiltration. This incident highlights a significant supply chain vulnerability where attackers leverage the trusted access held by third-party integrators to gain intelligence on downstream operational technology (OT) environments. By exfiltrating device details and infrastructure schematics, actors aim to facilitate future disruptive or destructive attacks against the critical infrastructure systems managed by these integrators.
Attack Chain
- Initial access gained to a U.S. industrial automation solutions company network by foreign cyber actors.
- Internal reconnaissance performed to identify high-value targets, specifically searching for customer-related documentation and SCADA system information.
- Identification of sensitive files including SCADA information, ICS device details, and network schematics.
- Staging of identified data into compressed .zip archives for streamlined collection.
- Exfiltration of approximately 800 files from the integrator's environment.
- Potential future pivot activities leveraging the stolen intelligence to target the networks of power and transportation entities.
- Final objective of conducting disruptive or destructive operations within the OT environments of critical infrastructure owners and operators.
Impact
The compromise of a third-party integrator provides malicious actors with high-fidelity intelligence regarding the OT environments of critical infrastructure entities. Successful exfiltration of schematics and device configurations significantly lowers the barrier for attackers to develop targeted exploits. If attackers successfully leverage this intelligence to pivot into operational networks, the potential consequences include large-scale disruption to power grids, transportation systems, and other essential services, posing risks to both equipment and public safety.
Recommendation
Prioritized actions for critical infrastructure owners and operators:
- Review and enforce the Principle of Least Privilege (PoLP) for all third-party remote access accounts to ensure access is strictly limited to necessary OT systems.
- Audit all remote access routes into the ICS network; implement on-demand (just-in-time) access policies where the operator must proactively approve sessions rather than allowing persistent connections.
- Incorporate strict cybersecurity, patch management, and supply chain requirements into all service agreements and contracts with third-party integrators.
- Request and maintain a comprehensive inventory of all software and hardware components supplied by the integrator, including connection documentation and lifecycle update plans.
- Develop and test manual operation procedures and maintain offline, secure backups of all software required to recover systems in the event of an integrator-related compromise.
Immediate actions
Review and audit all active remote access accounts provided to third-party integrators for adherence to least privilege.