Executive Summary
Between March and April 2025, foreign cyber actors infiltrated a U.S. industrial automation solutions company providing SCADA programming and system integration services to critical infrastructure entities including power utilities and transportation systems. The attackers conducted reconnaissance using search terms like 'customers' and 'SCADA,' subsequently creating nine ZIP files containing approximately 800 exfiltrated files including customer SCADA information, ICS device specifications, and operational schematics. This supply chain compromise exposed sensitive infrastructure data that could enable future disruptive attacks against operational technology environments.
This incident highlights the growing threat to critical infrastructure through third-party integrator compromises, occurring amid increased focus on ICS security following recent nation-state campaigns targeting operational technology systems and growing regulatory emphasis on supply chain risk management in critical sectors.
Why This Matters Now
Critical infrastructure faces escalating supply chain risks as nation-state actors increasingly target third-party integrators to access sensitive SCADA and ICS data, requiring immediate implementation of zero-trust principles and enhanced vendor risk management frameworks.
Attack Path Analysis
Foreign threat actors compromised a U.S. industrial automation solutions company through initial network intrusion, escalated privileges to access sensitive customer systems, moved laterally through ICS/SCADA networks, maintained command and control for reconnaissance activities, exfiltrated approximately 800 files including customer SCADA information and ICS device details in nine zip files, and created potential for future disruptive attacks against critical infrastructure operational environments.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Foreign malicious cyber actors gained initial access to U.S. industrial automation solutions company network between March-April 2025
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Valid Accounts
Remote Services: Remote Desktop Protocol
Data from Local System
Archive Collected Data: Archive via Utility
Exfiltration Over C2 Channel
Remote System Discovery
Data from Information Repositories
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Asset Management and Visibility
Control ID: ID.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
Digital Operational Resilience Act (DORA) – ICT Third-Party Risk Management
Control ID: Article 28
PCI DSS 4.0 – Third-Party Service Provider Monitoring
Control ID: 12.8.2
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical power grid infrastructure faces severe supply chain risks from compromised ICS integrators enabling lateral movement and exfiltration of SCADA systems.
Oil/Energy/Solar/Greentech
Energy sector operational technology vulnerable to third-party integrator compromise allowing threat actors to access control systems and critical infrastructure schematics.
Transportation
Transportation entities using industrial automation solutions exposed to supply chain attacks targeting SCADA programming and east-west traffic monitoring capabilities.
Government Administration
Critical infrastructure operations face zero trust segmentation failures when third-party integrators provide unauthorized access paths for foreign threat actors.
Sources
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integratorshttps://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integratorsVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- NIST Cybersecurity Supply Chain Risk Managementhttps://csrc.nist.gov/projects/supply-chain-risk-managementVerified
- Industrial Control Systems Cybersecurity Advisorieshttps://www.cisa.gov/news-events/cybersecurity-advisories?f%5B0%5D=advisory_type%3A94Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this industrial automation compromise by limiting lateral movement through ICS/SCADA networks and reducing the scope of customer data accessible to foreign threat actors.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have limited the initial compromise scope and reduced the attacker's ability to immediately access sensitive customer systems and SCADA infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies would likely have constrained privilege escalation by limiting access to customer data repositories and restricting movement between network segments containing sensitive SCADA information.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained lateral movement between network segments and reduced the attacker's reachability to customer SCADA systems and ICS device repositories.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained persistent command and control communications, reducing the attacker's ability to maintain long-term reconnaissance access across customer systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained the large-scale exfiltration by limiting outbound data transfers and reducing the volume of customer SCADA information successfully extracted.
The potential for future disruptive attacks against critical infrastructure would likely be diminished due to reduced access to comprehensive operational schematics and ICS device configurations.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems Operations
- SCADA Monitoring
- Critical Infrastructure Services
- Operational Technology Management
Estimated downtime: N/A
Estimated loss: N/A
Customer SCADA information, ICS device specifications and schematics, industrial automation system designs, and operational control data affecting power utilities and transportation entities
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between customer networks and limit third-party integrator access to only necessary systems
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts including large file transfers and zip archives
- • Enable East-West Traffic Security monitoring to detect suspicious reconnaissance activities and searches for sensitive terms like 'SCADA' and 'customers'
- • Establish Multicloud Visibility & Control to monitor third-party integrator activities and detect anomalous file access patterns across hybrid environments
- • Deploy Encrypted Traffic inspection capabilities to secure data in transit between third-party integrators and critical infrastructure systems



