CISA Warns Hackers Are Targeting Control Systems in Oil and Gas Industry

CISA Warns Hackers Are Targeting Control Systems in Oil and Gas Industry

Federal Agencies Issue High-Priority Warning on Ongoing Cyber Threats to U.S. Energy Infrastructure

In a coordinated alert, CISA—alongside the FBI, Department of Energy, and Environmental Protection Agency—has sounded the alarm over a persistent wave of cyber activity zeroing in on control systems vital to U.S. oil and gas operations.

Target: Operational Technology in Energy Systems

Cybersecurity authorities report a troubling trend: attackers, often using basic tools, are probing and compromising industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems that support core energy and transportation operations.

While the tactics used—such as password-guessing, open-port scanning, and exploitation of misconfigured remote access—lack technical sophistication, their potential to disrupt operations or damage critical infrastructure is substantial. According to officials, the primary culprits appear to be hacktivist groups or lone actors masquerading as such, with activity dating back to at least 2022.

“Public-facing operational technology is being exploited with simple browser-based tools,” the advisory notes, highlighting how attackers scan internet-connected devices for vulnerabilities, often using widely available search engines that index exposed control systems.

Despite Basic Tactics, Stakes Remain High

Cybersecurity professionals stress that elementary attack methods can still trigger severe consequences—ranging from unauthorized system changes to full-blown outages or physical damage. As many organizations continue to suffer from weak security hygiene, the threat is amplified across sectors where downtime isn’t an option.

Five Key Actions for Immediate Defense

The alert outlines five urgent steps organizations must take to reduce risk:

  1. Remove operational technology from public internet access.
  2. Replace default login credentials with complex, unique passwords.
  3. Implement secure remote access solutions using private networks and phishing-resistant multi-factor authentication (MFA).
  4. Establish strong IT/OT network segmentation through DMZ architecture.
  5. Ensure the ability to manually operate critical systems during cyber disruptions.

Systems using factory-default settings are a top concern, especially when internet-connected. The advisory underscores the need for proper configuration of both hardware and third-party services, as lapses are often introduced during system setup or vendor deployment.

Recent Vulnerability Disclosures Add Urgency

The warning follows closely on the heels of five emergency vulnerability notices issued on April 22, 2025, covering industrial control platforms from Siemens, ABB, and Schneider Electric—underscoring the growing attack surface.

Organizations are urged to consult CISA’s online resources for further action steps, including how to assess internet exposure, bolster credentials, enable phishing-resistant MFA, and segment networks effectively.

More Articles & Posts