FBI and CISA issued guidance for critical infrastructure owners and operators on reducing risk when using third-party ICS integrators, with emphasis on least privilege, secure contracts, and monitoring remote access. The fact sheet cites a 2025 incident in which foreign cyber actors accessed a U.S. industrial automation company, searched for SCADA-related terms, and staged data for possible exfiltration from customer environments. #FBI #CISA #ICS #SCADA
Keypoints
- FBI and CISA published a fact sheet focused on reducing risks from third-party industrial control system integrators.
- The guidance stresses applying the principle of least privilege in OT environments to limit integrator access.
- Third-party integrators can introduce supply chain, data storage, and remote access risks for critical infrastructure.
- FBI analysis found that between March and April 2025, foreign cyber actors accessed a U.S. industrial automation solutions company network.
- Threat actors searched for terms such as “customers” and “SCADA” and created nine ZIP archives containing about 800 files.
- The exfiltrated material reportedly included customer SCADA information, ICS device details, and schematics that could support later disruptive attacks.
- The agencies recommend contract controls, remote access monitoring, inventories of supplied assets, and capabilities for manual operation and recovery.
MITRE Techniques
- [T1083] File and Directory Discovery – The actors searched for data related to customers and SCADA to locate valuable files inside the compromised network. (‘searched terms, including “customers” and “SCADA”’)
- [T1560.001] Archive Collected Data: Archive via Utility – The actors staged data into compressed archives for possible removal. (‘created nine .zip files consisting of approximately 800 files for presumed exfiltration’)
- [T1213] Data from Information Repositories – The actors collected customer SCADA information, ICS device details, and schematics from the company environment. (‘including customer SCADA information, ICS device details, and other schematics’)
Indicators of Compromise
- [File names / archives] Data staging artifacts – nine .zip files, approximately 800 files
- [Keywords searched] Discovery terms used by actors – “customers”, “SCADA”
- [Organizations / targets] Affected environment context – a U.S. industrial automation solutions company, power utilities, transportation entities
- [Time period] Incident window – March to April 2025
- [Contact endpoints] Reporting contacts referenced in guidance – [email protected], 1-844-Say-CISA, 1-800-CALL-FBI