The supplier held a map of customer operations

In a 23 September TLP:CLEAR fact sheet, FBI and CISA described foreign actors accessing a U.S. industrial automation solutions company serving the power and transportation sectors between March and April 2025.

The actors searched for terms including “customers” and “SCADA,” then created nine archive files containing about 800 files for presumed exfiltration. The material included customer SCADA information, device details, and schematics.

Keep the consequence claim precise

The agencies describe access and presumed theft of sensitive operational information. They do not confirm that the stolen material was used to disrupt a customer’s industrial process. Defenders should prepare for that possibility without reporting it as an established outcome.

An integrator can concentrate access, knowledge, and recovery dependencies

DependencyRisk if the integrator is compromisedControl objective
Remote supportA trusted connection becomes a path into customer environments.Enable access on demand, use named identities, and record every session.
Engineering filesSchematics and configurations reveal process design and defensive gaps.Minimise retained copies, encrypt them, and monitor bulk access or archive creation.
Software and updatesCustomers may accept altered packages or instructions from a trusted source.Verify signatures, hashes, provenance, and approved delivery channels.
Operational knowledgeDevice models and process context make targeting more efficient.Share only what the service requires and enforce retention limits.
Recovery supportA supplier incident can remove the expertise or files needed to restore operations.Keep tested offline copies and the ability to operate independently.

Make third-party access temporary, attributable, and reviewable

  • Inventory integrator-provided hardware, software, connectivity, cloud services, update paths, credentials, and data held outside the organisation.
  • Remove persistent remote access where the operational model permits; approve time-bounded sessions for a named person and task.
  • Route access through controlled jump infrastructure with multifactor authentication, session recording, command or file-transfer logs, and rapid revocation.
  • Apply least privilege to both the integrator and its service identities, separating engineering, maintenance, monitoring, and administrative duties.
  • Put cybersecurity, incident notification, evidence preservation, subcontractor, data-handling, and recovery requirements into the contract and test them in exercises.

Plan to operate while the trusted supplier is unavailable

  1. 1

    Map the dependency. Document which processes require the integrator, how access is granted, what information it holds, and which systems accept its updates.

  2. 2

    Build independent recovery material. Maintain offline, tested copies of controller logic, configurations, licences, installers, network diagrams, and operating procedures.

  3. 3

    Exercise access revocation. Prove that remote paths, accounts, certificates, tokens, and shared credentials can be disabled quickly without losing safe operational control.

  4. 4

    Monitor both ends of the relationship. Alert on unusual session times, new source locations, privilege changes, bulk file access, archive creation, and transfers inconsistent with the work order.

  5. 5

    Rehearse a supplier-compromise scenario. Test manual operations, alternative support, evidence collection, credential rotation, trusted-software validation, and communications with the integrator and sector authorities.

A trusted connection still needs a security boundary

Trust explains why access exists; it should not determine how much access is granted or how little it is monitored. The strongest third-party design assumes a legitimate supplier account can be stolen and makes the resulting activity narrow, observable, and reversible.