Skip to content
CISA and FBI Warn of Third-Party ICS Risks for Critical Infrastructure

CISA and FBI Warn of Third-Party ICS Risks for Critical Infrastructure

First seen 24 Sep 2026, 11:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 12:55 UTC
  • CISA and FBI issued guidance on third-party ICS risks on September 24, 2026.
  • A 2025 incident involved foreign actors accessing a U.S. industrial automation company's network.
  • Operators are urged to apply the principle of least privilege to limit third-party access.

The FBI and CISA issued guidance on September 24, 2026, regarding cybersecurity risks associated with third-party industrial control system (ICS) integrators. They highlighted a 2025 incident where foreign cyber actors accessed a U.S. industrial automation company's network, potentially exfiltrating sensitive SCADA information. The agencies emphasized the importance of applying the principle of least privilege (PoLP) to limit integrators' access to critical systems. Operators are urged to assess data access, secure remote connections, and include cybersecurity requirements in contracts with integrators. The guidance aims to help critical infrastructure operators mitigate risks posed by third-party access to their systems. Failure to adopt these practices could expose operators to malicious actors who may exploit vulnerabilities to disrupt critical services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-03-01
Foreign cyber actors accessed U.S. ICS network
Malicious actors gained access to a U.S. industrial automation company's network, searching for sensitive information.
Cisa
2025-04-30
Data exfiltration attempt reported
Threat actors created nine zip files containing approximately 800 files, including SCADA information, for presumed exfiltration.
Industrialcyber.Co
2026-09-24
CISA and FBI issue guidance
The agencies warned critical infrastructure operators about third-party ICS risks and emphasized the need for PoLP.
Cisa

More articles in this cluster (3)