logo

Was the Explosion at Freeport LNG a Result of a Russian Cyber Attack?

ID: afe1fc5a-6ef3-5431-9197-a672cb9e18e8

STIX ID: report--afe1fc5a-6ef3-5431-9197-a672cb9e18e8

Feed Name: SecurityScorecard Blog

Threat Score
45/100

Date Published: 2025-02-24

Date Updated: 2026-04-29

...
...

SecurityScorecard analyzed publicly observable data around the June 8 Freeport LNG explosion to evaluate claims of a Russian APT (XENOTIME/TRITON) attack. The investigation found external weaknesses—missing SPF records, reused/exposed credentials, outdated software, a Citrix VPN subdomain, and netflow to foreign IPs and uncommon ports—but did not find definitive ICS indicators or conclusive evidence linking the incident to a TRITON infection or Russian state actors; many flows appear consistent with third-party vendors or business operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.