| Critical infrastructure organizations are increasingly dependent on third-party vendors for a variety of remote services, including security and operational technologies that support essential functions. Yet the privileged access that providers rely on can also create opportunities for threat actors to infiltrate these sensitive networks. Recent incidents involving Itron and Fortinet illustrate how trusted relationships can create exposure through both compromises, affecting customer environments and compromised credentials for devices at the network perimeter. |
| In April, Itron disclosed that threat actors obtained unauthorized access to its systems. The company further identified limited unauthorized access to some customer-hosted systems; however, an investigation found no evidence that customer-facing system functionality was meaningfully impacted. Itron supplies technology that energy and water utilities use to measure resource usage and communicate with devices across their service networks. Although the company has not publicly stated how threat actors gained initial access or what information they obtained, the incident shows how a compromise of a trusted technology provider can also expose customer-managed environments across multiple critical infrastructure organizations. This exposure could also create a foothold for credential theft, lateral movement, or attempts to reach systems that support essential services. |
| In June, researchers identified a large-scale credential compromise campaign known as FortiBleed, illustrating a different form of exposure. The campaign involved credentials for more than 70,000 internet-facing Fortinet devices, potentially enabling access to customer-operated firewalls and VPN gateways. According to Fortinet , some of the exposed credentials were likely obtained during earlier incidents, while others may have been compromised through brute-force activity against devices with weak passwords and no multi-factor authentication (MFA) enabled. The company said the activity was not tied to a newly identified product vulnerability. Fortinet firewalls and virtual private network gateways often control remote access at the network perimeter. Valid credentials could therefore grant threat actors entry into customer environments and an opportunity to weaken security controls or move further into internal networks. This creates particular concern for energy and water organizations that rely on these devices for employee and vendor access. |
| Recommendations |
| Inventory third-party services, vendor accounts, remote-access pathways, and internet-facing devices with access to sensitive environments. Limit vendor and administrative access to only the systems, users, and time periods required, and periodically remove unused accounts and unnecessary privileges. Require multi-factor authentication (MFA) for remote and privileged access, where possible, and use strong, unique passwords across devices and accounts. Rotate credentials following suspected exposure and terminate active sessions when a compromise is identified. Restrict management interfaces from public internet access, segment remote-access services from sensitive business and operational technology environments, and replace unsupported devices. Review firewall, virtual private network (VPN), authentication, and vendor-access logs for unusual login attempts, configuration changes, or newly created accounts. |