Security1 publisher2 min readPublished
FBI traces 800 staged SCADA files to a U.S. ICS integrator's own network
Between March and April 2025 intruders searched an industrial automation firm for "customers" and "SCADA", then bundled about 800 files. FBI and CISA now want least privilege applied to integrator access.
The Watch · Security desk

What happened
- FBI technical analysis places malicious foreign cyber actors on the network of a U.S. industrial automation solutions company between March and April 2025, a firm selling system integration, engineering consulting and SCADA programming.
- Its industrial customers included power utilities and transportation entities, and while inside, the actors searched the network for terms including "customers" and "SCADA".
- The agencies want owners to run routine risk assessments against contracts that grant access to industrial systems, measuring the effect on data autonomy and process controls.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A plant that is never touched can still lose its process design, because the aggregated copy sits with the contractor, and the owner learns about it from someone else's incident response.
- decision Owners renewing integrator agreements now choose between the standing high-privilege account that makes remote support fast and per-task access that slows it down.
- constraint Adding data-residency, ownership and geopolitical questions to the assessment narrows the set of integrators a U.S. utility can hire without extra justification.
- precedent Guidance with no deadline still sets the question auditors and insurers ask after the next OT incident that starts in a vendor account.
Nine .zip archives, roughly 800 files: customer SCADA information, ICS device details and other schematics [7]. That averages about 89 files per archive [8]. The FBI describes the bundles as created "for presumed exfiltration" [7], so what the agencies document is collection and packaging on the victim's network, not confirmed transfer off it. The fact sheet identifies the intruders only as malicious foreign cyber actors and does not name the company [10].
The access these firms hold is the subject. FBI and CISA list what third-party integrators do inside ICS environments: control system design, installation, operational data analysis, device support and service, and daily operational control [4]. Each of those jobs comes with credentials. The agencies' recommendation is to size them down, and they define least privilege in OT as granting users, processes and systems "only the minimum access necessary to perform their assigned tasks, and no more" [3]. Skip it, the fact sheet says, and owners may hand actors sensitive access to pathways they can exploit to cause disruptive and destructive effects to equipment and critical functions [14].
The recommendation aims at paperwork, not products. Owners should routinely reassess contracts that involve access to industrial systems and judge the effect on their own data autonomy and process controls [11]. The same assessments should cover hardware and software supply chain vulnerabilities introduced by integrator equipment, plus the IT and OT security of those devices and their associated networks [12]. Where design work is contracted out, the obligation runs both ways: integrators and owners have to collectively enforce clear requirements for the secure procurement and handling of system components [15].
Integrators that operate and host data outside the United States get separate treatment, on the grounds that they may be subject to different data storage and management laws that do not meet the security needs of U.S. critical infrastructure entities [13]. Foreign-owned integrators also draw a geopolitical line into the risk assessment [17].
This is a fact sheet of considerations, with no binding requirement and no compliance date [16]. Its use to an asset owner is evidentiary. The next time an integrator asks for high levels of access or control over a physical process [2], there is a dated federal case to cite in which the contractor's network was the route to power utility and transportation customers' schematics [5][7].
What to watch
- Whether FBI or CISA later names the industrial automation company or attributes the March-April 2025 intrusion to a state.
- Whether the staged SCADA information and schematics turn up in a follow-on intrusion at one of that integrator's utility or transit customers.
- Whether least-privilege and data-residency language starts appearing in integrator contract renewals as an audit item.