Hacktivist tampering with internet-exposed ICS at Canadian water, oil and gas, and grain facilities
- Event Year
- 2025
- Reliability
- Confirmed
- Country
- Canada
- Industry
- Other
- Attack Type
- Untargeted Attack
Description
In October 2025, the Canadian Centre for Cyber Security confirmed three separate intrusions into internet-accessible industrial control systems at Canadian critical infrastructure facilities. At a municipal water facility, attackers altered water pressure values and degraded service to the served community. At an oil and gas company, attackers manipulated an automated tank gauge and triggered false alarms. At a grain-drying operation, attackers altered temperature and humidity settings inside a silo, creating potentially unsafe storage conditions if not caught in time.
The incidents were disclosed in CCCS advisory AL25-016, which warned that hacktivists were abusing internet-facing PLCs, RTUs, HMIs, SCADA systems, safety systems, building-management systems, and industrial IoT devices. CCCS did not name the victims, provinces, device vendors, or specific protocols. The advisory described the access pattern as opportunistic rather than technically sophisticated: the affected systems were reachable from the public internet and insufficiently protected.
No specific hacktivist group was named. CCCS stated that the activity appeared motivated by media attention and reputational damage. SecurityWeek noted that state-sponsored actors sometimes use hacktivist cover, but CCCS did not attribute the activity to a named group or state actor. The confirmed record is the process manipulation itself, not a precise attribution to a named actor.
Impact
Water pressure manipulation degraded service at a Canadian municipal water facility. An automated tank gauge at an oil and gas company generated false alarms after tampering. Temperature and humidity manipulation in a grain-drying silo created potentially unsafe conditions. No environmental release, death, product loss, or critical infrastructure outage was publicly reported.
Sources
- https://www.cyber.gc.ca/en/alerts-advisories/al25-016-internet-accessible-industrial-control-systems-ics-abused-hacktivists
- https://www.securityweek.com/canada-says-hackers-tampered-with-ics-at-water-facility-oil-and-gas-firm/
- https://therecord.media/canada-ics-hacktivists-tampering-cyber-centre-alert
- https://www.theregister.com/2025/10/30/hacktivists_canadian_ics_systems
- https://www.cbc.ca/news/politics/cyber-threat-water-energy-food-systems-9.6960580