Hacktivists have breached multiple internet-accessible industrial control systems (ICS) across Canada, targeting critical infrastructure sectors including water treatment, oil and gas, and agriculture. In one incident, attackers tampered with water pressure values at a water facility, leading to degraded service for the local community. Another attack involved manipulating an Automated Tank Gauge (ATG) at an oil and gas company, which triggered false alarms, while a third incident saw the manipulation of temperature and humidity controls at a grain drying silo, creating potentially unsafe conditions. Authorities report that these attacks were opportunistic rather than highly sophisticated, with the primary aim of causing disruption, generating media attention, and undermining public trust in Canadian infrastructure.
The Canadian Centre for Cyber Security and the Royal Canadian Mounted Police have issued alerts to raise awareness about the increased threat to internet-exposed ICS and to urge organizations to strengthen their security measures. While the incidents did not result in catastrophic consequences, they highlight the risks posed by insufficiently secured ICS and the growing interest of hacktivist groups in targeting such systems. The authorities emphasize the need for improved detection and mitigation strategies to prevent similar attacks in the future and to protect critical infrastructure from both opportunistic and more advanced threat actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published alert AL25-016 warning that hacktivists have repeatedly abused exposed industrial control systems in Canada. The agency said the activity appears aimed at publicity, fear, and undermining trust, and urged organizations to reduce internet exposure and strengthen remote access and monitoring.
Canadian authorities reported three recent opportunistic intrusions involving internet-accessible industrial control systems at a water treatment facility, a Canadian oil and gas company, and an agricultural grain-drying silo. The incidents led to degraded service, false alarms, and changes to industrial controls that could have created unsafe operating conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourcecyber.gc.ca
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.