Skip to main content
QUIETLYTIC
Advisory

FBI and CISA warn ICS integrators are a path into critical infrastructure

An FBI and CISA fact sheet cites an intrusion at a US industrial automation integrator where attackers packaged about 800 files, including customer SCADA data.

Category
Advisory
Severity
High

The FBI and CISA published a joint fact sheet on 23 September warning owners of industrial control systems that the outside firms they hire to design, program and run those systems have become a route attackers can use to reach them. The agencies back the warning with a case from the FBI’s own investigations: an intrusion at a US industrial automation company whose customers include power utilities and transportation operators, in which attackers bundled roughly 800 files, including customer control-system data, apparently for removal.

The document carries no CVEs and names no malware. Its weight comes from that case. Integrators handle work ranging from control system design and installation to device support and, in some cases, running daily operations, so the access they hold can be broad.

The intrusion behind the warning

According to the FBI’s technical analysis, which the fact sheet summarises, foreign cyber actors were inside the integrator’s network between March and April 2025. The company provided system integration, engineering consulting and SCADA programming to industrial clients. While there, the intruders searched the network for terms such as “customers” and “SCADA”, then assembled nine compressed archives holding roughly 800 files. The agencies describe those archives as presumed staging for exfiltration, and list their contents as customer SCADA information, details of ICS devices, and other schematics.

Several things the fact sheet leaves open are worth stating plainly:

  • Who did it. The agencies say only that the actors were foreign. No country, group or malware family is named, and nothing here supports attributing the activity further.
  • Whether the files left the network. The wording is “presumed exfiltration”. The fact sheet does not confirm that the archives were successfully taken.
  • What happened next. No follow-on attack against any of the integrator’s customers is reported. The agencies’ concern is forward-looking: they say actors could use information like this to mount disruptive attacks on operational environments later.
  • How the attackers got in. The initial access method is not disclosed.

The integrator and its customers are not identified, and this article does not attempt to identify them.

Why an integrator is an attractive target

An integrator compromise gives an attacker two things at once. The first is knowledge: network designs, device specifications, logs and other data for many facilities, gathered in one place. The second is access. Where an integrator keeps remote connections into client ICS networks for support work, an attacker who controls the integrator’s environment may be able to move from there into the operator’s control network.

The agencies add two further risks. Equipment and software supplied by an integrator can arrive with systems and services that aren’t set up to the customer’s security requirements, and the supply chain behind that equipment is only as trustworthy as the procurement rules both parties enforce. They also flag integrators that are foreign-owned or keep data outside the United States: operational data held abroad may fall under another country’s laws, even where the integrator operates through a US subsidiary, and the fact sheet asks operators to factor the geopolitical climate into how exposed that makes them.

Questions the agencies want operators to answer

The fact sheet frames its risk assessment around four questions, and each is concrete enough to put to an integrator this week:

  1. What does the integrator hold or have access to? Designs, device specifications and logs are all valuable to an intruder, so assume anything the integrator stores could be reached through a breach of its network.
  2. Where is that data kept, and under which jurisdiction?
  3. Does the integrator hold remote access for support, and how is that connection secured and watched?
  4. Could the facility keep running, and recover, if the integrator were compromised or unavailable? The agencies recommend keeping secure offline backups of every piece of software needed to run the equipment.

What to do, in order

For operators who rely on an outside integrator, this is the sequence we would work through, drawn from the agencies’ recommendations, with our own ordering and additions:

  1. Find and close internet exposure. Ask the integrator where each device it installed or manages is hosted, and take anything reachable from the public internet off it. In our assessment this is the quickest risk reduction, and it needs no contract change.
  2. Take control of remote access. Route integrator connections through paths you can monitor and log, and move to on-demand access that your own staff must switch on for each session rather than an always-open tunnel. Review who has used the existing connections recently.
  3. Get an inventory. Request a full list of the hardware and software the integrator supplied, how each item connects to your environment, and how it is patched. CISA’s OT asset inventory guidance and its SBOM minimum elements are among the references the fact sheet points to.
  4. Rehearse manual operation. Practise running and recovering critical processes without the integrator, with the offline backups mentioned above tested rather than assumed.
  5. Rewrite the contract at renewal. The agencies list what service agreements should cover: where data is stored and how ICS data and design documents are protected, remote access terms, the integrator’s own security programme, change and patch management, hardening of deployed components such as replacing default passwords and closing unused ports, a named list of personnel with system access, and provisions for local engineering support so the integrator isn’t needed for every intervention.
  6. Apply least privilege throughout. Grant the integrator only the access its tasks require and revisit it as those tasks change.

Integrators themselves should read the case as aimed at them too. The intruders searched for customer and SCADA material by name, which is consistent with an interest in what the integrator held about its clients. In our view, segmenting client engineering files, limiting who can reach them, and watching for bulk archiving on file servers are reasonable responses on that side.

Suspected intrusions can be reported to a local FBI field office, to IC3, or to CISA’s 24/7 operations centre.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

Source: FBI Internet Crime Complaint Center (IC3)

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources

  1. CISA — Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
  2. FBI IC3 — Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators (PDF)