The Containment Era is here. →Explore

Industry Category

Industrial Automation

Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.

213 threat reports
Page 18 of 18

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Industrial Automation Threat Reports

Showing 205213 / 213 reports
How BlackSuit Ransomware Hit a Global Equipment Manufacturer in 2024
Impact· high

How BlackSuit Ransomware Hit a Global Equipment Manufacturer in 2024

In early 2024, a global equipment manufacturer experienced a significant ransomware attack carried out by the threat actor Ignoble Scorpius, leveraging the BlackSuit ransomware. The attack began with a sophisticated vishing campaign targeting an employee, leading to credential compromise and lateral movement within the company’s network. Attackers bypassed multiple defenses, ultimately deploying the ransomware to encrypt critical business systems and disrupt operations worldwide. The incident required rapid response, threat intelligence analysis, and comprehensive remediation to restore services and protect sensitive data. This incident highlights the growing danger of human-centric social engineering combined with advanced ransomware—a tactic increasingly adopted by organized threat actors. With the resurgence of targeted and blended attacks, organizations face urgent pressure to strengthen security controls and resilience against such evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
Impact· high

Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave

In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
China-Linked PlugX and Bookworm Malware Strike Asian Telecoms in Advanced Attack
Impact· low

China-Linked PlugX and Bookworm Malware Strike Asian Telecoms in Advanced Attack

In mid-2025, a coordinated advanced persistent threat (APT) campaign linked to China targeted telecommunications and manufacturing entities across Central and South Asia. Attackers leveraged new PlugX and Bookworm malware variants, utilizing DLL side-loading techniques via legitimate applications to achieve persistence and evade detection. The intrusions allowed the threat actors to perform extensive reconnaissance, deploy additional payloads, and exfiltrate sensitive operational data from ASEAN and Asian telecom networks, demonstrating a high degree of stealth and sophistication in lateral movement. This incident underscores a growing uptick in nation-state cyber activity against Asian critical infrastructure, highlighting emerging malware evolution and increasingly covert lateral movement. With similar TTPs proliferating, organizations must elevate east-west traffic security and anomaly detection to stay ahead.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security
Impact· medium

ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security

In Q2 2025, industrial automation systems worldwide experienced significant and persistent threats, with 20.5% of ICS (Industrial Control Systems) computers encountering malicious objects, despite a slight quarterly decrease. Attackers leveraged a multi-stage campaign, beginning with phishing emails and malicious documents to gain access, and subsequently deploying next-stage malware such as spyware, ransomware, and cryptominers. Regions like Africa and sectors such as biometrics were among the most targeted, while common initial infection sources included malicious internet resources, infected emails, and removable media devices. Multiple sophisticated malware families (over 10,000 variants) exploited ICS security gaps to enable lateral movement, persistent access, and data exfiltration, impacting operational resilience and increasing risk of service disruption for critical industries. This incident underscores the continued evolution of ICS-targeting malware and the increasing sophistication of attack vectors in the operational technology sector. The upward trend in email-based infiltration and malicious cloud links, coupled with persistent use of multi-stage payloads, highlights the urgent need for robust, layered security, Zero Trust policies, and compliance alignment to protect critical infrastructure environments against both commodity and targeted threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations
Impact· medium

Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations

In September 2025, a critical vulnerability (CVE-2025-5086, CVSS 9.0) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management software was found to be actively exploited in the wild. Threat actors leveraged this flaw to gain unauthorized access, bypassing authentication and executing arbitrary code on exposed systems. The breach impacted several manufacturing sector organizations globally, leading to disruptions in operational technology, potential data compromise, and urgent incident response actions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog and issuing public guidance for immediate patching and mitigation. This incident is significant as adversaries continue to target vulnerable OT/IoT platforms central to manufacturing operations. The increased frequency of high-severity vulnerabilities in critical infrastructure software, combined with rapid weaponization by threat actors, is driving regulatory scrutiny and highlighting the urgent need for robust vulnerability management and zero trust controls across industrial environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing
Impact· medium

Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing

In early 2024, Bridgestone Americas, a leading tire manufacturer, experienced a cyberattack that impacted several of its North American manufacturing plants. The incident led to operational disruptions, with reports confirming at least one plant in Quebec suspending activity. Bridgestone acted promptly, implementing its established cyber incident response protocols and containing the breach while launching a forensic investigation to determine the incident's scope. According to statements from company officials and local authorities, no employee or customer data was reported compromised, and business operations have largely returned to normal as of the latest updates. This attack highlights how IT/OT convergence in manufacturing continues to expose critical infrastructure to cyber threats, even in the absence of clear threat actor attribution or significant data loss. The event underscores the rising necessity for robust east-west security controls and rapid response capabilities within industrial environments facing increasing cyber risk.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
U.S. Indicts Ukrainian Ransomware Operator Behind Hundreds of Global Attacks
Impact· high

U.S. Indicts Ukrainian Ransomware Operator Behind Hundreds of Global Attacks

In June 2024, the U.S. Department of Justice indicted Volodymyr Tymoshchuk, a Ukrainian national linked to the development and deployment of the Nefilim, LockerGoga, and MegaCortex ransomware variants. Operating under aliases such as 'deadforz' and 'farnetwork,' Tymoshchuk and his co-conspirators targeted organizations—including healthcare, industrial, and blue-chip companies—across the U.S., Europe, and Australia from at least 2018 onward. Over 250 U.S. and hundreds of global victims experienced encrypted systems, data theft, and significant operational disruption, resulting in tens of millions of dollars in damages attributed to ransom payments, mitigation, and recovery costs. This indictment underscores increasing law enforcement cooperation and heightened government focus on disrupting ransomware-as-a-service ecosystems. The ongoing campaign and associated public rewards for information highlight how ransomware actors continue evolving tactics, targeting high-revenue organizations and leveraging affiliate networks to scale global extortion operations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
Impact· high

Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024

In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Exploits for Dassault DELMIA Apriso RCE (CVE-2025-5086) Target Manufacturing Operations
Impact· medium

Exploits for Dassault DELMIA Apriso RCE (CVE-2025-5086) Target Manufacturing Operations

In June 2025, Dassault Systèmes disclosed a critical deserialization vulnerability (CVE-2025-5086) in its DELMIA Apriso Manufacturing Operation Management system, affecting releases from 2020 through 2025. Attackers exploited this remote code execution flaw via crafted SOAP requests containing malicious serialized data, enabling them to upload and execute arbitrary Windows executables on vulnerable servers. The exploit activity, orchestrated through automated scanners—some associated with the Project Discovery framework—originated from multiple geographies and targeted the core manufacturing process integration point, posing risks to operational uptime and potential lateral movement within enterprise environments. This incident underscores the growing threat targeting industrial control applications and critical infrastructure through software supply chain vulnerabilities. Exploiting deserialization bugs in widely deployed operational technology platforms has become a preferred method for threat actors, highlighting the urgent need for timely patching, application-layer anomaly detection, and zero trust segmentation within manufacturing and industrial settings.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports