Waterfall OT Cyber Threat Report 2025

Waterfall OT Cyber Threat Report 2025
Waterfall’s OT Cyber Threat Report 2025 shows that physical-consequence OT attacks continued to rise in impact, with a 146% increase in affected sites and 76 incidents in 2024. The report highlights growing nation-state activity, persistent ransomware pressure, and new ICS-capable malware such as FrostyGoop, IOControl, and Fuxnet, with #Sandworm #VoltTyphoon #SaltTyphoon #FrostyGoop #IOControl #Fuxnet #CrowdStrike #Halliburton #Keytronic #StoliGroupUSA.

Keypoints

  • Annual OT cyber threat reports typically begin with key takeaways, followed by methodology, macro trends, incident breakdowns, threat actor analysis, affected regions and industries, attack techniques, costs, case studies, and defensive guidance.
  • These reports usually explain how incidents were selected, what counts as a qualifying event, and why public reporting likely understates real-world activity.
  • They then summarize the scale of attacks, the most affected sectors, the most impacted geographies, and whether effects were direct on OT or indirect through IT disruptions.
  • In this report, 2024 saw 76 attacks with physical consequences, a 5% increase from 2023’s 72 incidents.
  • The number of sites impacted rose 146% year over year, from 412 sites in 2023 to 1,015 in 2024, showing that many incidents affected multiple locations.
  • Ransomware remained the dominant attack type, accounting for 87% of identifiable attacks in 2024.
  • Nation-state attacks with physical consequences tripled year over year, reflecting a sharper shift toward geopolitically motivated operations.
  • Transportation was the single largest affected sector, making up 37% of attacks, while transportation plus discrete manufacturing accounted for 69% of all incidents.
  • North America’s water and wastewater sector saw a notable increase in threat activity, including seven consequential attacks and near misses, most tied to nation-state activity.
  • The USA and Germany experienced the largest number of incidents, with Japan, the UK, and Canada also heavily affected.
  • Nearly 90% of physical consequences came indirectly, often because IT systems were disrupted and OT operations depended on them or were shut down as a precaution.
  • The report identifies eight attack pathways: direct OT attacks, poor segmentation, IT pivoting, supply chain compromise, malicious insiders, abundance-of-caution shutdowns, IT dependencies, and third-party outages.
  • The most common indirect causes were precautionary shutdowns and dependence on IT systems, underscoring weak IT/OT separation.
  • Incident disclosure rules from the SEC and other regulators may be suppressing public reporting detail and affecting apparent incident trends.
  • In June 2024, the SEC accepted a $2.1 million penalty from R. R. Donnelley & Sons for disclosure violations, reinforcing the compliance pressure on public companies.
  • The report argues that stronger IT security alone will not solve OT risk because safety-critical OT requires robustness beyond what typical IT environments can provide.
  • It recommends making IT-to-OT pivoting physically impossible through stronger segmentation and hardened remote access controls.
  • Halliburton’s reported costs reached $35 million, while Keytronic reported more than $17 million in losses after a May 2024 incident.
  • The CrowdStrike software failure, though not malicious, affected about 8.5 million devices and caused major outages across airlines, ports, manufacturing, and mining, with estimated costs of $5 billion to $10 billion.
  • Navigation disruption remained a serious physical threat: GPS jamming and spoofing affected flights in Europe, contributed to a fatal Azerbaijan Airlines crash, and showed how satellite-navigation interference can create safety risks.
  • Near-miss cases, especially Sandworm-linked activity against water utilities, showed that grey-zone campaigns are becoming more common and are increasingly probing OT defenses without always causing full outages.
  • Volt Typhoon and Salt Typhoon stood out as major Chinese campaigns, with Volt Typhoon using “living off the land” techniques and Salt Typhoon penetrating telecom networks across dozens of countries.
  • The report says 2024 produced three new ICS-capable malware families, a sharp increase compared with the small number seen over the previous 14 years.
  • FrostyGoop, IOControl, and Fuxnet demonstrated destructive or disruptive capability against heating systems, fuel pumps, and sensor gateways.
  • Defensive guidance in 2024 emphasized hardware-enforced remote access, stronger OT security principles, and a shift from abstract likelihood language to the more practical concept of credible threats.
  • The recurring takeaway is that OT risk is worsening in scale, sophistication, and reach, and security programs must prioritize safety-critical resilience over traditional IT-centric assumptions.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github