logo

Pipeline Attacks highlight Third Party Threat to Critical Infrastructure

ID: bc361a56-a7f0-50f6-9a5e-cb534dc65d44

STIX ID: report--bc361a56-a7f0-50f6-9a5e-cb534dc65d44

Feed Name: Security Ledger

Threat Score
60/100

Date Published: 2018-04-04

Date Updated: 2026-05-05

Author: Elizabeth Montalbano

...
...

Multiple U.S. pipeline companies experienced disruptions to third-party EDI data systems supplied by a vendor unit of Energy Services Group, interrupting document and transaction flows but not reportedly impacting SCADA or pipeline operations. Security experts characterize the incidents as likely financially motivated (possible ransom or transactional-data theft), emphasize the risk of third-party access as an attack vector, and recommend stronger third-party security controls such as audits, contracts requiring security practices, multifactor authentication, restricted remote access, and vendor vetting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.