FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints

A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Photoreal editorial shot of a dimly lit industrial control room, rows of SCADA monitors showing abstract pipeline and grid schematics glowing blue and amber, on
Share

Key points

  • Between March and April 2025, foreign hackers broke into a US industrial automation company and staged nine .zip files holding roughly 800 documents, including customer SCADA information and control system schematics, according to FBI technical analysis released in a joint fact sheet with CISA.
  • The victim provided system integration and SCADA programming to power utilities and transportation operators, meaning the stolen material describes how physical systems at downstream customers are wired and controlled.
  • Attackers searched the network for terms like "customers" and "SCADA" before packaging files for exfiltration, a pattern consistent with pre-positioning for later disruptive attacks rather than immediate sabotage.
  • The FBI and CISA want critical infrastructure operators to treat third-party integrators as a supply chain risk, with contract language covering remote access, data storage and software inventories.
  • The advisory lands alongside CISA's new foundational guidance on OT asset inventories and the 2026 minimum elements for a Software Bill of Materials, both aimed at knowing what you actually run.

The FBI and CISA have gone public with a case they clearly find uncomfortable. A US company that designs and programs the control systems behind power plants and transit networks was breached last spring, and the attackers left with a targeted haul of customer blueprints.

The agencies don't name the company, the customers, or the country behind the intrusion. What they do describe is specific. Between March and April 2025, intruders sat on the network of an industrial automation solutions firm, ran keyword searches for "customers" and "SCADA," and bundled about 800 files into nine .zip archives for what investigators call "presumed exfiltration."

SCADA, short for supervisory control and data acquisition, is the software that lets an operator in a control room watch and adjust physical equipment: pumps, breakers, signals, valves. Schematics of that equipment are exactly what you'd want if you planned to interfere with it later.

Why does an integrator breach matter so much?

One integrator often holds the keys to dozens of customer sites. Third-party integrators design control systems, keep remote access afterwards for support, and sometimes run daily operations. Break the integrator and you inherit a shortcut into every utility on their client list.

That's the pattern the FBI is flagging. The stolen files included customer SCADA information, ICS (industrial control system) device details and schematics tied to power and transport clients. None of that gives an attacker a live foothold on its own. It gives them the map.

Attribution in the advisory is thin on purpose. The agencies say "malicious foreign cyber actors" and stop there. No cluster name, no vendor overlap called out. Read anything beyond the intrusion itself as medium confidence at best.

What are the FBI and CISA telling operators to do?

Apply least privilege to contractors and write it into the contract. The fact sheet pushes operators to treat integrator access as a formal risk decision rather than a handshake. The concrete asks are unglamorous and long overdue.

Area What operators should require
Data location Know where integrator-held design files and logs are stored, including whether a US subsidiary keeps data abroad
Remote access Route it through paths you can monitor, prefer on-demand approval over always-on tunnels
Hardware and software Get a full inventory of what the integrator installed and how it updates
Independence Be able to run manually if the integrator is knocked offline or compromised

Operators are also told to keep offline backups of the software needed to run equipment and to rehearse manual operations. That last point is the tell. If regulators are asking utilities to practice running plants without their integrator, they're worried about a scenario where the integrator is the problem.

We've tracked the broader ICS patching picture closely this autumn: our 17 September report on critical fixes across Schneider Electric, Siemens and Aveva shows how much unpatched surface area third-party integrators are typically working against.

Should you worry?

The interesting thing about this advisory isn't the advice, which reads like standard supply chain hygiene. It's that the FBI chose to describe a live intrusion at a named category of victim, in a sector where public case studies are rare. Pair it with CISA's push on OT asset inventories and the updated SBOM minimum elements, and Washington's direction is clear: know exactly what software you run, who touches it, and what walks out the door when a contractor gets hit. The 800 files are the argument.

© 2026 Threat Vectr