Government and industry reporting warns that operational technology and industrial control systems remain dangerously exposed through weak remote access, poor segmentation, and internet-facing devices, giving both state-backed and criminal actors paths into critical infrastructure. A joint CISA/NSA advisory said adversaries routinely exploit legacy OT environments, public system information, and insecure remote connections to move from reconnaissance to manipulation of physical processes, while a separate CISA/FBI alert tied Chinese state-sponsored intrusions to U.S. natural gas pipeline operators and said the actors stole SCADA and ICS information to build capabilities for future disruption. Recent exposure research also found 6,300 internet-reachable industrial-control and building-automation devices near U.S. data centers, including BACnet, Fox/Niagara, Modbus, and Vertiv/Liebert systems that could affect cooling and power operations.
The threat has already translated into real-world disruptive activity and increasingly specialized tooling. Dragos reported FrostyGoop, a Golang-based ICS malware that communicates over Modbus TCP and was likely used to disrupt heating services in Lviv, Ukraine, after attackers apparently entered through an internet-facing router and traversed poorly segmented networks. Other cited incidents and assessments include Israel’s thwarted attempt against water facilities, persistent Russian probing of U.S. power infrastructure, and leaked-document analysis describing a Russian capability designed to attack rail and petrochemical control systems through telecommunications access. Across the reporting, the common defensive priorities were to eliminate direct public exposure, harden and inventory remote access, enforce MFA, replace default credentials, patch supported systems, restrict engineering tools, and closely monitor OT network and protocol activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
48 events from the most recent confirmed update back to the earliest known activity.
Between June 14 and July 14, 2026, Flare conducted passive discovery of internet-facing OCPP endpoints and identified 1,000 distinct endpoints across 56 countries. It found that 720 accepted connections without transport-layer encryption.
The UK Department of Science, Innovation and Technology announced a regular program of joint exercises with the Irish government for crisis rehearsal. The move was presented as part of improving resilience for undersea infrastructure incidents.
The Russian vessel Yantar neared British waters as part of a GUGI operation to map critical undersea infrastructure. After patrol aircraft were dispatched, the crew shone lasers into the eyes of Royal Air Force pilots.
During the Cyber Security Agency’s 10th anniversary dinner, K. Shanmugam publicly called out the Chinese-linked threat actor UNC3886. The move marked Singapore’s first public attribution of a cyber incident to a named APT group.
OCPP 2.1 followed the earlier 2.0.1 security improvements for EV charging communications. Later measurement found sightings of 2.0.1 and 2.1 were still rare among exposed endpoints.
About 116,000 records linked to a common charging application from an Indian energy management provider were posted on a deep web forum. Upstream later traced the records to software used by charging point operators across eight countries and territories.
Dragos first reported FrostyGoop to Dragos WorldView subscribers in late May 2024. It also deployed FrostyGoop indicators of compromise in its platform for threat hunting.
Dragos discovered FrostyGoop in April 2024 and described it as the ninth known ICS malware. The malware is written in Golang for Windows and communicates directly with industrial devices over Modbus TCP.
At Pwn2Own Automotive 2024 in Tokyo, Synacktiv compromised three chargers and a Tesla modem. The team defeated an Autel MaxiCharger through a Bluetooth authentication bypass and chained stack overflows into arbitrary code execution.
Volt Typhoon breached Singtel in 2024, according to the RUSI article. Reports suggested the intrusion may have been a precursor to broader campaigns against U.S. telecommunications targets.
Dragos assessed that FrostyGoop was likely used in a disruptive attack against a district energy company in Lviv, Ukraine. Malicious Modbus commands to ENCO controllers caused inaccurate measurements and system malfunctions that led to a two-day loss of heating.
Researcher Anurag Sen found an unprotected Shell Recharge cloud database containing nearly a terabyte of charging-network logging data. Exposed records included names, email addresses, phone numbers, station locations, and one executive’s home address.
The article reports a 30 percent increase in Russian incursions into British waters from 2023. This rise was cited as part of growing concern over threats to British undersea infrastructure.
ChargePrint research presented at the NDSS Symposium fingerprinted 27,439 internet-connected charging stations worldwide. The work found that roughly 92 percent carried at least one vulnerability.
A researcher found an open TeamViewer remote-access session on an Electrify America charger in Kettleman City and navigated its Windows operating system from the touchscreen. The case illustrated weak remote-access exposure in charging infrastructure.
An Electrify America station in California displayed a political meme instead of its normal interface. The event was cited as an example of EV charger compromise or tampering.
Both cables connecting Shetland were cut, disrupting communications and transport links for residents. The incident was later cited in discussions of UK undersea infrastructure vulnerability.
NSA and CISA issued a joint cybersecurity advisory warning that traditional OT/ICS security approaches do not adequately address current threats. The advisory described common intrusion stages and recommended mitigations for critical infrastructure operators.
Council-operated EV chargers on the Isle of Wight in England were redirected to display pornographic websites. The incident was later cited as an example of real-world EV charging infrastructure abuse.
CISA and the FBI published a joint advisory on the Chinese gas pipeline intrusion campaign spanning 2011 to 2013. The advisory said 23 U.S. natural gas pipeline operators were affected, including 13 confirmed compromises.
At a municipally owned water treatment plant in Oldsmar, Florida, someone reportedly altered sodium hydroxide settings from 100 PPM to 11,100 PPM via remote access. Plant personnel detected and reversed the change before any known harm occurred.
Taiwan’s Ministry of Justice Investigation Bureau publicly disclosed the first two waves of supply-chain-style attacks affecting Taiwan. TeamT5 said at least three distinct China-nexus groups were involved across the broader 2020 operations.
TeamT5 tracked a July 2020 operation on PTT involving posts about scandals intended to discredit the Taiwanese government or military. The activity was linked by TeamT5 and another source to a Chinese APT group.
Yigal Unna said Israel had thwarted a synchronized cyberattack on industrial computers supporting water facilities the previous month. He said the attack targeted civilian infrastructure and could have caused damage if it had not been stopped.
Several Taiwan energy-related companies were hit by a ransomware attack that TeamT5 attributed to a well-organized Chinese adversary group. The incident was cited as a sign of China-linked actors expanding beyond traditional espionage.
Israel’s National Cyber Directorate issued a statement about attempted breaches of water pumping stations and treatment plants. It urged companies in the water sector to take defensive measures.
OCPP 2.0.1 added certificate-based security for EV charging communications. Later research noted that adoption of this more secure version remained rare among observed internet-facing endpoints.
Russian hackers continued probing the U.S. power grid and other critical infrastructure in 2018. WIRED framed this as evidence that cyber-induced utility disruption had become a real-world threat beyond the Ukraine blackouts.
Russia unleashed NotPetya through the hacked supply chain of a Ukrainian accounting software provider. Disguised as ransomware, it functioned as destructive wiper malware and spread globally within hours.
Another power outage in Kyiv was caused by malware known as Industroyer or CrashOverride. The malware included modular industrial-protocol capabilities and a wiper component.
Guccifer 2.0 claimed to have hacked the Democratic National Committee and passed emails to WikiLeaks. The activity was described as widely believed to be linked to the Kremlin.
A cyberattack cut power to about half of the residents of Ivano-Frankivsk, Ukraine. Attackers used BlackEnergy-enabled access to obtain SCADA credentials, open breakers, deploy a wiper, brick remote controls, and launch a telephone denial-of-service attack.
OCPP 1.6 was released without built-in public-key encryption. Later reporting cited this design choice as a contributor to persistent exposure in EV charging infrastructure.
The New York Times reported that Snake malware had infiltrated the Ukraine Prime Minister’s Office and several remote embassies. The report highlighted cyber activity accompanying the Crimea crisis.
During the 2014 Crimea operation, attackers seized telecommunications networks and the region’s only internet exchange, causing an information blackout. They also used mobile network access to identify protesters and tamper with parliamentarians’ phones.
CISA received reports about targeted attacks directed at multiple oil and natural gas pipeline sites. The reporting marked an early government awareness point in the broader Chinese intrusion campaign.
CISA and the FBI provided incident response and remediation support to a number of pipeline-sector victims. This support continued across 2012 and 2013 as the campaign unfolded.
From December 9, 2011 through at least February 29, 2012, oil and natural gas organizations received highly tailored spearphishing emails targeting employees. The campaign also involved related social engineering activity.
A Chinese state-sponsored spearphishing and intrusion campaign targeting U.S. oil and natural gas pipeline companies began in late December 2011. The activity was later assessed as intended to develop capabilities to hold pipeline infrastructure at risk.
USUTIL2 notified USUTIL1 that a USUTIL1 employee had visited with a Mariposa-infected laptop. USUTIL1 had not detected the infection through its antivirus, IDS, or firewalls before the notification.
Spanish authorities arrested three suspects in Spain in connection with the Mariposa botnet case. The arrests followed the earlier takedown of the botnet's infrastructure.
Authorities took down the 12.7 million-node Mariposa zombie network. ICS-CERT later noted that residual malware still remained on infected systems despite the disruption of primary command-and-control infrastructure.
Defence Intelligence announced the discovery of the Mariposa botnet. The investigation involved Spanish authorities, the FBI, Panda Security, and Defence Intelligence.
Kyrgyzstan experienced DDoS attacks while deliberating whether to renew a lease for a U.S. air base. The attacks were described as appearing linked to the Russian Business Network.
The Georgia cyberattacks intensified as Russian troops invaded South Ossetia. The activity expanded to financial institutions, businesses, education, Western media, and included defacements and spam campaigns.
DDoS attacks began targeting Georgian news and government websites. The campaign later expanded alongside the Russia-Georgia conflict.
Estonia suffered debilitating DDoS attacks against government and financial services websites after the relocation of a Soviet war memorial. Targets included the president, parliament, police, political parties, and major media outlets.
GCN reported that the Oldsmar water treatment incident was actually an employee error rather than a hack. The later reporting said statements from the city manager indicated this explanation had been known from the outset.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
smallwarsjournal.com
Open sourcecybersecuritynews.com
Open sourceflare.io
Open sourceteamt5.org
Open sourcewired.com
Open sourceus-cert.gov
Open sourcehub.dragos.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.