Full Breakdown
Rising Threats to Critical Infrastructure from Hacktivists and Cybercriminals
11/6/2025, 1:27:51 PM
Increased Malicious Activity Targeting Critical Infrastructure
The Canadian Centre for Cyber Security (CCCS) has issued a warning regarding a surge in malicious activities by hacktivists targeting critical infrastructure in Canada. These attacks have involved breaching internet-facing industrial control systems (ICS), leading to significant operational disruptions. Notable incidents include tampering with water pressure at a Canadian water treatment facility, manipulating an Automated Tank Gauge (ATG) at an oil and gas company, and altering temperature and humidity levels at a grain drying silo. Ryan Sherstobitoff, Chief Threat Intelligence Officer at CCCS, emphasized that these actions created unsafe environments and service interruptions, highlighting vulnerabilities in critical infrastructure.
Nature of the Threats and Their Implications
CCCS characterizes these attacks as opportunistic rather than sophisticated, suggesting that the primary goal of the hacktivists is to gain public attention and undermine the Canadian government's credibility. Sherstobitoff criticized authorities for inadequate security measures, stating that the lack of proper safeguards leaves critical infrastructure exposed. The CCCS has identified various ICS devices at risk, including Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) systems, and has recommended actionable steps for organizations to enhance their security posture.
Broader Cybersecurity Landscape
The threat landscape extends beyond hacktivists to include organized cybercriminals and state-sponsored actors. The Microsoft 2025 Digital Defense Report indicates that cybercriminals have become increasingly sophisticated, utilizing access brokerage services to facilitate attacks on critical public services. The report highlights a significant rise in attacks on telecommunications and critical infrastructure, with real-world consequences such as disrupted emergency services and delayed medical care.
Regulatory Responses and Best Practices
In response to these escalating threats, the European Union has enacted the Network and Information Systems Directive 2 (NIS2) and the Digital Operational Resilience Act (DORA). These regulations aim to enhance cybersecurity across critical sectors by establishing stringent requirements for risk management and incident reporting. Organizations are now required to adopt a risk-based approach to cybersecurity, focusing on key mitigating controls to protect against vulnerabilities.
Criticism & Opposition
Despite the proactive measures being recommended, some experts argue that existing regulations may not be sufficient to address the rapidly evolving threat landscape. The complexity of managing diverse device ecosystems, particularly in sectors like healthcare and finance, poses significant challenges. Forescout Technologies' research reveals that a substantial percentage of connected assets in these industries fall outside traditional IT, creating blind spots for security teams.
Official Statements & Responses
The CCCS has urged critical infrastructure organizations to take immediate action to inventory and secure their ICS devices. Recommendations include disconnecting devices from the internet where feasible, employing virtual private networks (VPNs) with multi-factor authentication, and enhancing monitoring practices to detect cyber intrusions promptly. Sherstobitoff stated, “Strengthening oversight across industrial environments is no longer optional.”
Verbatim Quotes
- “Hacktivists breached Canadian water, oil and gas, and agriculture facilities by tampering with industrial controls,” — Ryan Sherstobitoff, Chief Threat Intelligence Officer, CCCS
- “When infrastructure operations are disrupted, the impact extends to public health and energy reliability.” — Ryan Sherstobitoff, Chief Threat Intelligence Officer, CCCS
- “These devices are so common in the dataset because they are pervasive,” — Forescout Technologies Report
- “Attackers are pivoting to areas with maximum impact.” — Deepen Desai, EVP and Chief Security Officer, Zscaler
What's Next
As the threat landscape continues to evolve, organizations must prioritize cybersecurity measures and compliance with emerging regulations to safeguard critical infrastructure. Enhanced collaboration between government entities and private organizations will be essential in mitigating risks and ensuring the resilience of essential services.
