Critical Infrastructure Is More Than Oil and Gas

Published March 26, 2025

While oil and gas may be top of mind when it comes to critical infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA) categorizes 16 sectors as critical infrastructure. As StateScoop describes, these “systems and networks are considered so vital to the United States that any disruption to their operations would have crippling effects on national security, economics, public health and safety.” Within that definition are systems such as healthcare and water and wastewater facilities, all of which are at the risk of cybersecurity vulnerabilities and cybercriminals.

Medusa and Salt Typhoon

The most recent case of threatening cyber activity in critical infrastructure comes from Medusa. Several U.S. federal organizations issued an advisory concerning the ransomware gang, which was first flagged in 2021. The advisory warns that Medusa has infiltrated over 300 critical infrastructure organizations across the globe. Its targets have consisted of a range of critical infrastructure entities from the medical, education, insurance, tech, and manufacturing fields among others.

Medusa certainly isn’t the only concerning group. There have been other prominent threat actors such as Salt Typhoon, which gained attention for taking advantage of vulnerabilities including outdated systems and lack of preventative measures like suspicious activity detectors.

The Quiet Intrusions That Look Like Normal Traffic

Not every threat to critical infrastructure announces itself with a ransom note. Reporting on the threat group known as Volt Typhoon described access to a United States electric grid network that went undetected for roughly 300 days. An intrusion that lasts that long is quiet by design. The attacker spends those months learning the environment and waiting, and any disruption would come later.

Volt Typhoon reflects a broader pattern in critical infrastructure intrusions. Rather than deploying obvious malware, attackers use common, legitimate tools already present on the network to get past defenses. The approach is often called living off the land, and its whole purpose is to look like routine administrative activity. When the traffic resembles the work your own team does every day, alarms simply do not fire.

That makes the activity considerably harder to detect, and the difficulty falls hardest on operators with limited resources and limited monitoring. Federal advisories have described adversary interest in locating operational technology and in establishing a lasting presence on those networks. Operators can start with a direct check of their own environment. Confirm whether anyone would notice a legitimate tool being used at an hour when no one should be using it.

Where Attackers Get In and How Often It Happens

The entry point is often smaller than the consequence. CISA flagged a vulnerability in the Lantronix XPort, a device used globally across manufacturing, energy and other critical infrastructure industries. The XPort enables remote connectivity, which means the vulnerability could let an attacker reach the device configuration interface. From there, an intruder can work outward through the layers of connected systems.

The results reach real communities. The city of Abilene, Texas confirmed it experienced a cyberattack that caused a shutdown of systems for a period of time. Research from the security company Semperis puts that experience in context across the utility sector.

  • 62% of water and power operators in the United States and the United Kingdom were targeted by cyberattacks in the past year
  • Of those targeted, 80% were targeted multiple times
  • More than half of those affected experienced permanent damage from system infiltration
  • 59% of those surveyed were impacted by attacks backed by nation states

Remote access is the common thread. CISA worked with the FBI, the NSA and other partners on a guide to securing remote access software. The agencies note that this software provides broad capability to maintain and improve information technology, operational technology and industrial control system services. That same breadth is exactly what makes it attractive to criminals.

Protecting Critical Infrastructure Across the Board

Overall, these threats to critical infrastructure impact so many operators and communities. As David Jones reports for Cybersecurity Dive, “State and local communities are facing a rise in cyber threats from nation-state-linked and criminal threat groups, which in many cases are looking to undermine confidence in public institutions, according to a report by the Multi-State Information Sharing and Analysis Center.”

At the end of 2024, officials in Rhode Island were forced to deal with a cyberattack that affected a site controlling food and healthcare services for residents in need. That’s just one example of the other critical networks requiring protection. In order to block such occurrences from taking place and from threat actors like those listed above from taking advantage, strategic cybersecurity measures must be put in place. These strategies must also cover all potential bases. Integrating a mix of monitoring and zero-trust frameworks is and will continue to be essential.

Sources

  • “Critical infrastructure relies on ‘whole-of-state’ information sharing, says report” – Sophia Fox-Sowell, StateScoop

https://statescoop.com/critical-infrastructure-relies-on-whole-of-state-information-sharing-says-report/

  • “Over 300 Critical Infrastructure Organizations Hit by Medusa Ransomware Attacks” – Alicia Hope, CPO Magazine

https://www.cpomagazine.com/cyber-security/over-300-critical-infrastructure-organizations-hit-by-medusa-ransomware-attacks/

  • “Salt Typhoon: A Wake-up Call for Critical Infrastructure” – Gabrielle Hempel, Dark Reading

https://www.darkreading.com/cyberattacks-data-breaches/salt-typhoon-wake-up-call-critical-infrastructure

  • “‘Living off the land’ a major cyber threat to critical infrastructure, report finds” – Chris Teale, Route Fifty

https://www.route-fifty.com/cybersecurity/2025/04/living-land-major-cyber-threat-critical-infrastructure-report-finds/404733/

  • “Lantronix Device Used in Critical Infrastructure Exposes Systems to Remote Hacking” – Eduard Kovacs, Security Week

https://www.securityweek.com/lantronix-device-used-in-critical-infrastructure-exposes-systems-to-remote-hacking/

  • “Cyberattack disrupts Texas city’s systems” – SC Media

https://www.scworld.com/brief/cyberattack-disrupts-texas-citys-systems

  • “CISA and Partners Release Joint Guide to Securing Remote Access Software” – CISA

https://www.cisa.gov/news-events/alerts/2023/06/06/cisa-and-partners-release-joint-guide-securing-remote-access-software

  • “Critical infrastructure at state, local levels at heightened risk of cyberattacks” – David Jones, Cybersecurity Dive

https://www.cybersecuritydive.com/news/critical-infrastructure-state-local-cyber/741273/

Author: <a href="https://dynics.com/author/dynics-team/" target="_self">Dynics Team</a>

Author: Dynics Team

The Dynics engineering group designs and builds industrial computing hardware and OT cybersecurity systems for the plant floor. Its engineers hold more than 75 years of combined experience, and its plant-floor deployments go back more than 30 years. More than 75% of staff work in product development, design, assembly, and service. Dynics designs, fabricates, and assembles its panel PCs, monitors, rackmount chassis, and security appliances at a 37,500 square foot facility in Ann Arbor, Michigan.

Related Posts

You Might Also Like...