What happened

CISA and the FBI published a joint advisory telling critical infrastructure operators to take care when granting online access to third-party integrators and consultants. Released on Wednesday, it says foreign hackers are actively using those connections as a route into operational technology environments.

The case is not hypothetical. Between March and April 2025, malicious foreign actors gained access to the network of a US industrial automation solutions company that provided system integration and engineering consulting for clients including power utilities and transportation systems. The company specialised in supervisory control and data acquisition systems.

FBI technical analysts found that the intruders searched the company network for terms including customers and SCADA, then packaged roughly 800 files into zip archives for what the advisory calls presumed exfiltration. The material included customer SCADA information, ICS device details and other schematics, which the advisory says could be used to plan later disruptive attacks on those customers.

Patrick Gillespie, OT practice director at GuidePoint Security, described the stolen files as a roadmap. Integrators typically hold architectural, electrical and network diagrams of a client site, plus the make, model and software version of installed equipment. Read together, those show how a facility is built, powered and networked. Michael Garcia, a former associate policy chief at CISA, said the patience of the operation points to a sophisticated, likely state-linked actor, since a criminal would simply have encrypted the data and asked for money. He added that the tone of the advisory suggests the agencies did not believe they were responding to an active campaign.

The recommended mitigations are foundational: least privilege for anyone working on the network, asset inventories and replacing default passwords. Gillespie suggested operators check whether items like inventories or password management are already covered by their support contract.

Why this is a GRC story

Third-party risk stops being abstract here. The integrator is the door, and the harm lands on the client. The questions are practical: what access is granted, who approves it, how it is logged, and how quickly it can be withdrawn.

Least privilege belongs in the contract. The recommendation is technical, but enforcing it across an external team is a procurement and oversight problem. If the access scope is not written down and testable, nobody can evidence it later.

You cannot assess what you have not inventoried. The stolen files were valuable because they named which equipment was installed and where. An incomplete asset register is not just an audit finding, it decides how much an attacker learns.

The reporting gap matters. The intrusion happened in 2025 and the advisory arrived about 18 months later, which shows how hard it is for a client to learn a supplier was breached. Supplier assurance should say what an integrator owes you when it finds out.

What to watch

Watch whether CISA and the FBI follow this advisory with more detail, and whether OT support contracts start carrying explicit access logging, notification and least-privilege obligations. Watch also whether other regulators adopt the same framing.

The practical takeaway is a short exercise: pull the list of integrators with remote access to your environment, confirm each connection is named, time-bound and logged, and check what the contract obliges them to tell you after an incident.

Attribution: Analysis based on DataBreachToday and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News