Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
FBI and CISA issued guidance for critical infrastructure owners and operators on reducing risk when using third-party ICS integrators, with emphasis on least privilege, secure contracts, and monitoring remote access. The fact sheet cites a 2025 incident in which foreign cyber actors accessed a U.S. industrial automation company, searched for SCADA-related terms, and staged data for possible exfiltration from customer environments. #FBI #CISA #ICS #SCADA

Keypoints

  • FBI and CISA published a fact sheet focused on reducing risks from third-party industrial control system integrators.
  • The guidance stresses applying the principle of least privilege in OT environments to limit integrator access.
  • Third-party integrators can introduce supply chain, data storage, and remote access risks for critical infrastructure.
  • FBI analysis found that between March and April 2025, foreign cyber actors accessed a U.S. industrial automation solutions company network.
  • Threat actors searched for terms such as “customers” and “SCADA” and created nine ZIP archives containing about 800 files.
  • The exfiltrated material reportedly included customer SCADA information, ICS device details, and schematics that could support later disruptive attacks.
  • The agencies recommend contract controls, remote access monitoring, inventories of supplied assets, and capabilities for manual operation and recovery.

MITRE Techniques

  • [T1083] File and Directory Discovery – The actors searched for data related to customers and SCADA to locate valuable files inside the compromised network. (‘searched terms, including “customers” and “SCADA”’)
  • [T1560.001] Archive Collected Data: Archive via Utility – The actors staged data into compressed archives for possible removal. (‘created nine .zip files consisting of approximately 800 files for presumed exfiltration’)
  • [T1213] Data from Information Repositories – The actors collected customer SCADA information, ICS device details, and schematics from the company environment. (‘including customer SCADA information, ICS device details, and other schematics’)

Indicators of Compromise

  • [File names / archives] Data staging artifacts – nine .zip files, approximately 800 files
  • [Keywords searched] Discovery terms used by actors – “customers”, “SCADA”
  • [Organizations / targets] Affected environment context – a U.S. industrial automation solutions company, power utilities, transportation entities
  • [Time period] Incident window – March to April 2025
  • [Contact endpoints] Reporting contacts referenced in guidance – [email protected], 1-844-Say-CISA, 1-800-CALL-FBI


Read more: https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators