Executive brief
This advisory addresses security risks that critical infrastructure operators face when granting third-party industrial control system (ICS) integrators access to sensitive operational networks and data. Attackers can compromise integrator networks to gain access to customer infrastructure, steal operational designs and device configurations, and conduct disruptive attacks against power utilities, transportation systems, and other critical services. The guidance emphasizes implementing the principle of least privilege and conducting thorough risk assessments before engaging third-party integrators to reduce exposure to supply chain compromises and insider threats.
Technical details
This advisory highlights supply chain and third-party access risks in industrial control system (ICS) environments rather than a specific software vulnerability. The FBI and CISA documented a March–April 2025 incident where threat actors compromised a U.S. industrial automation company offering SCADA programming and system integration services, exfiltrating approximately 800 files including customer SCADA designs, ICS device details, and operational schematics. The root risk is the lack of application of the principle of least privilege (PoLP) and insufficient contractual security controls when critical infrastructure operators grant integrators broad network access for system design, installation, operational analysis, device support, and daily operational control. Attack vectors include direct network compromise of integrators (network vector), supply chain introduction of insecure components (supply chain vector), and misuse of legitimate remote access credentials. Preconditions include the integrator having remote access capabilities and storage of sensitive customer data; no authentication or technical exploit is required—malicious actors simply need to compromise the integrator's network to pivot into customer environments. Attackers can exfiltrate operational designs, device specifications, network logs, and customer lists to enable follow-on disruptive or destructive attacks. Mitigation includes implementing PoLP in contracts, requiring data residency restrictions, maintaining offline backups, and conducting regular risk assessments of integrator relationships.
Affected products
- Third-party ICS integrators and industrial automation solutions companies all
Timeline
- 2026-09-23: advisory: FBI and CISA published guidance on risks when working with third-party ICS integrators
- 2025-03: exploited: Foreign threat actors compromised a U.S. industrial automation company and exfiltrated customer SCADA information and ICS device details