Was the Explosion at Freeport LNG a Result of a Russian Cyber Attack?
ID: afe1fc5a-6ef3-5431-9197-a672cb9e18e8
STIX ID: report--afe1fc5a-6ef3-5431-9197-a672cb9e18e8
Feed Name: SecurityScorecard Blog
SecurityScorecard analyzed publicly observable data around the June 8 Freeport LNG explosion to evaluate claims of a Russian APT (XENOTIME/TRITON) attack. The investigation found external weaknesses—missing SPF records, reused/exposed credentials, outdated software, a Citrix VPN subdomain, and netflow to foreign IPs and uncommon ports—but did not find definitive ICS indicators or conclusive evidence linking the incident to a TRITON infection or Russian state actors; many flows appear consistent with third-party vendors or business operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
