✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Utilities
Breach intelligence, attack campaigns, and threat reports targeting the Utilities sector.
Explore Other Sectors
Utilities Threat Reports
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.
6 months ago
Kill Chain
CISA Warns of Critical 2025 ICS Vulnerabilities in WHILL C2 and AzeoTech DAQFactory
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) publicly released advisories highlighting multiple serious vulnerabilities in two industrial control systems: the WHILL C2 Wheelchairs and AzeoTech DAQFactory software. These advisories outlined critical flaws that could permit unauthorized access, remote code execution, or control manipulation within industrial and healthcare environments if left unmitigated. Attackers exploiting these gaps could compromise patient safety with wheelchairs or disrupt automation and process monitoring within industrial facilities, directly impacting operational continuity and patient care. This disclosure underscores intensifying cybersecurity scrutiny of industrial and medical control systems, which are increasingly targeted due to digitization and legacy design shortcomings. The rapid emergence of similar threats and increased regulatory focus make swift mitigation and robust ICS security controls more vital than ever.
6 months ago
Kill Chain
ICS in Crisis: Multi-Vector Malware Campaign Hits Industrial Automation Sector in Q3 2025
In Q3 2025, a coordinated multi-vector malware campaign targeted the global industrial automation sector, exploiting both internet-borne and lateral movement vectors to infiltrate sensitive OT environments. Malicious scripts, phishing pages, and spyware were delivered through malicious emails and compromised websites, with attackers leveraging old vulnerabilities in software such as Microsoft Office Equation Editor (CVE-2017-11882) to gain persistent access. The incident impacted biometrics, engineering, and manufacturing industries, affecting up to 27.4% of ICS computers in certain regions, and enabled the delivery of ransomware, spyware, and self-propagating worms across distributed networks. This incident is notable for its breadth—over 11,000 malware families were detected—and its use of diverse channels, from web to USB to network shares. The surge in initial infection via malicious scripts and documents, especially in East Asia and South America, demonstrates attackers’ evolving tactics and the urgent need for improved segmentation, encrypted network traffic, and anomaly detection across critical OT environments.
6 months ago
Kill Chain
Mitsubishi Electric ICS Flaw in 2025 Highlights Need for Encrypted Traffic
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory detailing a critical vulnerability affecting Mitsubishi Electric Air Conditioning Systems that are widely deployed in industrial environments. The issue, cataloged as ICSA-25-177-01, centers on insufficient encryption for industrial control system (ICS) communications, exposing unencrypted traffic that could be intercepted and manipulated by malicious actors. If exploited, this vulnerability could enable attackers to intercept sensitive data or issue unauthorized commands to affected ICS devices, putting essential infrastructure operations at risk. Immediate mitigation steps were recommended for organizations to safeguard operational technology environments and prevent exploitation. This incident draws attention to the persistent risks of unencrypted or poorly protected network traffic within legacy ICS deployments. As digital transformation accelerates and threat actors increasingly target critical infrastructure, robust encrypted traffic solutions and segmentation controls are vital to ensure compliance and operational resilience.
6 months ago
Kill Chain
How Russian State-Sponsored Cyberattacks Targeted Denmark’s Critical Infrastructure and Elections in 2024
In December 2025, Danish authorities attributed two major cyberattacks in 2024 to Russian-backed groups. The first attack targeted a Danish water utility, causing significant operational disruption, and was attributed to Z-Pentest, a pro-Russian threat actor. The second involved a series of distributed denial-of-service (DDoS) attacks against Danish municipal and regional council websites on the eve of critical elections, orchestrated by NoName057(16), another threat group with ties to Russia. These incidents highlighted the vulnerabilities of critical infrastructure and democratic processes to foreign state-sponsored actors. The fallout from these attacks underscores a broader pattern of rising state-sponsored cyber operations targeting essential services and democratic institutions across Europe. Heightened geopolitical tensions and the growing sophistication of threat actors are driving urgent calls for improved cyber defenses and regulatory responses.
6 months ago
Kill Chain
Ransomware Attack Hits Romanian Water Authority: A 2024 Critical Infrastructure Wake-Up Call
In June 2024, Romania’s National Water Administration (Administrația Națională Apele Române) suffered a ransomware attack that disrupted key systems and operational processes. The attack, identified over the weekend of June 8–9, targeted core IT infrastructure, encrypting file servers and temporarily interrupting the administrative management of the country’s water resources. While water supply to the public reportedly remained unaffected, the incident led to delays in critical public and environmental services and highlighted gaps in incident response capabilities and network segmentation. Early indications suggest the attackers used a known ransomware variant, gaining access via a vulnerable remote service. This breach comes amid a surge in ransomware attacks on public utilities across Europe, emphasizing the increasing threat to operational technology and critical infrastructure. Heightened regulatory scrutiny and an evolving threat landscape put additional pressure on agencies to improve cyber resilience and visibility.
6 months ago
Kill Chain
Denmark’s Water Utility Cyberattack: Hybrid Warfare Hits Critical Infrastructure in 2025
In December 2025, Danish authorities publicly attributed a destructive cyberattack on a major water utility to Russian state-sponsored groups, primarily Z-Pentest. The attackers penetrated critical operational systems, disrupting water infrastructure and threatening essential services. Danish intelligence described the operation as part of Russia’s ongoing hybrid war strategy, which includes leveraging hacktivist proxies to create insecurity and punish countries supporting Ukraine. Simultaneously, NoName057(16) conducted a DDoS campaign targeting Danish election infrastructure, further elevating national security concerns. This incident underscores the rising threat posed by nation-state actors actively targeting vital infrastructure across Europe. The use of both destructive intrusions and disruptive tactics during sensitive political periods reflects a broader trend of cyber operations designed to undermine public trust and exploit operational technology vulnerabilities on a global scale.
6 months ago
Kill Chain
CISA Flags Critical ICS Flaws Threatening National Infrastructure in 2025
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released nine advisories covering serious vulnerabilities discovered in multiple industrial control systems (ICS) from vendors including Inductive Automation, Schneider Electric, Siemens, Mitsubishi Electric, Advantech, National Instruments, Rockwell Automation, and Axis Communications. These vulnerabilities potentially allow attackers to gain unauthorized access, move laterally, and disrupt or manipulate key operations in sectors such as energy, manufacturing, and transportation. Many of the issues arise from insecure configurations, insufficient encryption, outdated software components, and lack of segmentation between critical assets. This incident highlights the alarming persistence of security gaps across ICS environments. As operational technology (OT) converges with IT, attackers increasingly exploit these systems to launch ransomware, disrupt supply chains, or conduct cyber-physical sabotage, emphasizing the urgent need for robust controls, patching, and increased network visibility in critical infrastructure.
6 months ago
Kill Chain
Critical OS Command Injection Vulnerability Hits Mitsubishi Electric Iconics Products (2025)
In December 2025, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products disclosed a critical vulnerability (CVE-2025-11774) affecting GENESIS64, ICONICS Suite, MobileHMI, and MC Works64 software. This OS command injection flaw resides in the software keyboard (keypad) function, enabling local attackers to execute arbitrary executable files (.EXE) by tampering with configuration files. If successfully exploited, adversaries could trigger denial-of-service (DoS), information tampering, and unauthorized information disclosure or destruction on systems running these products. A fix is available for most products by upgrading to GENESIS64 v10.97.3 or higher, but MC Works64 users must migrate as no patch is planned. The incident is significant for the critical manufacturing sector, highlighting persistent risks tied to ICS software supply chains. As attackers increasingly exploit software flaws in operational technology, prompt patching and network segmentation remain vital. This vulnerability’s disclosure underscores the necessity for maintaining robust controls on critical infrastructure endpoints and monitoring for lateral movement threats.
6 months ago
Kill Chain
Schneider Electric 2025: Critical WSUS Flaw Threatens Global Industrial Networks
In December 2025, Schneider Electric disclosed a critical vulnerability—CVE-2025-59287—in its EcoStruxure Foxboro DCS Advisor, an industrial automation component used worldwide across critical manufacturing and energy sectors. The vulnerability, rooted in untrusted data deserialization within Microsoft WSUS, could allow unauthenticated remote code execution with system-level privileges if exploited, threatening core operational networks. The exposure prompted Schneider Electric and CISA to issue urgent advisories urging immediate patching via provided Microsoft updates and to isolate control networks from business operations to prevent exploitation. Despite official advisories, any systems running unpatched software remain at high risk. The incident highlights the persistent challenges in securing dependencies within operational technology (OT) environments. With critical infrastructure increasingly targeted by sophisticated threat actors leveraging software supply chain and remote execution flaws, this case underscores the importance for organizations to proactively patch, segment networks, and reinforce incident response capabilities tailored for industrial control systems.
6 months ago
Kill Chain
Inductive Automation Ignition Vulnerability Exposes Critical Infrastructure to Privilege Escalation in 2025
In December 2025, Inductive Automation disclosed a privilege escalation vulnerability (CVE-2025-13911) in its Ignition SCADA platform widely used across critical manufacturing, energy, and IT sectors. The flaw arises from inadequate controls in the Python scripting environment, enabling authenticated administrators to execute arbitrary code with SYSTEM-level privileges on affected Windows hosts. Attackers can upload malicious project files to the Ignition Gateway, potentially leading to complete host compromise if exploited. Although there are currently no reports of public exploitation, this issue underscores growing risks associated with misconfigured automation platforms and the importance of adhering to least-privilege principles. Recent trends in supply chain and ICS-targeted attacks have increased regulatory pressure on critical infrastructure operators to address privilege escalation vectors.
6 months ago
Kill Chain
Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems
In December 2025, critical vulnerabilities were disclosed in Advantech WebAccess/SCADA software (version 9.2.1), widely used across critical manufacturing, energy, and water infrastructure worldwide. Discovered by Pellera Technologies, the weaknesses included multiple instances of path traversal (CVE-2025-14850, CVE-2025-67653, CVE-2025-14848), unrestricted file upload (CVE-2025-14849), and SQL injection (CVE-2025-46268). Exploitation could enable a remote, authenticated attacker to read or modify sensitive database content, delete files, or execute arbitrary code on impacted systems, significantly increasing cyber-physical risk for operations. Advantech advised immediate upgrades to v9.2.2 to remediate these flaws. This incident underscores ongoing challenges in the security of industrial control systems amid rising cyber threats targeting critical infrastructure. With no current evidence of public exploitation, practitioners must remain vigilant due to the highly impactful nature of the vulnerabilities and their corresponding attack surface across essential industries.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports