Lessons From Real ICS Attacks: Stuxnet to PIPEDREAM
What the landmark industrial control system incidents actually taught defenders: Stuxnet, Havex, BlackEnergy, Industroyer, TRISIS, PIPEDREAM and Colonial Pipeline, and the controls each one justifies.
Why Study the History
Industrial attacks are rare compared with commodity ransomware, which means the public case history is small enough to learn properly, and each case justifies specific controls. Every credible OT security programme is, in effect, a response to this list.
Stuxnet, 2010: Code Can Break Machines
Stuxnet targeted uranium enrichment centrifuges. It manipulated variable-frequency drive speeds to damage equipment while reporting normal values back to operators, and it crossed into an isolated environment via removable media.
What it taught.
Air gaps are procedural, not physical. They are bridged by USB drives, contractor laptops, and maintenance connections.
Controls it justifies. Removable media policy with kiosk scanning and port control, integrity verification of controller logic against a trusted baseline, and correlating process behaviour with independent measurements rather than trusting a single reported value.
Havex, 2013 to 2014: The Supply Chain Route
Havex was an espionage campaign against industrial targets, notable for an OPC scanning module that enumerated industrial devices, and for delivery through trojanized software downloads on legitimate vendor websites.
What it taught. Reconnaissance is a distinct and necessary phase for industrial attacks, because causing a physical effect requires knowing the environment. And the vendor download page is part of your attack surface.
Controls it justifies. Verify integrity and provenance of vendor software and firmware before installation, stage updates through a controlled internal distribution point rather than downloading directly to OT hosts, and monitor for enumeration activity such as unexpected OPC or protocol scanning.
BlackEnergy3 and KillDisk, 2015: Hostile Recovery
Attackers caused a power outage in Ukraine by using legitimate remote access and HMI control to open breakers. They then deployed KillDisk and wiped serial-to-Ethernet converter firmware, and flooded call centres, specifically to obstruct restoration. Operators restored power manually.
What it taught. This was human-operated, not automated: the adversary used the operators' own tools. Just as importantly, hindering recovery is part of the attack. Your incident response plan must assume the tools you plan to use may be degraded.
Controls it justifies. Multifactor authentication and brokered, recorded remote access; offline verified backups including device firmware and configurations; out-of-band communications for responders; and documented, practised manual operation capability.
Industroyer / CRASHOVERRIDE, 2016: Protocol-Native Attacks
Industroyer implemented native industrial protocols, including IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA, allowing it to issue legitimate-looking control commands to grid equipment. It was reusable against similar equipment rather than bespoke to one target.
What it taught. Once an adversary speaks the protocol, the malicious traffic is protocol-legitimate and has no signature. Signature-based detection cannot find it.
Controls it justifies. Baseline legitimate command patterns and alert on unexpected control commands, sources, or timing. Protocol-aware passive monitoring is the only detection approach that works here, and it must be tuned with engineering input to be useful rather than noisy.
TRISIS / TRITON, 2017: Attacking the Safety Layer
TRISIS targeted safety instrumented system controllers, attempting to modify the logic of the protective layer designed to bring the process to a safe state. It was discovered because the attack caused an unexpected process shutdown.
What it taught. This is the step-change case. Compromising the safety layer removes the last engineered barrier between a process upset and a hazardous outcome, converting a production incident into a potential loss-of-life event.
Controls it justifies. Strict segmentation of the safety zone with no inbound write path, keeping safety controllers in a non-programmable state during normal operation, alerting on any key-switch or mode change, verifying safety logic against a trusted baseline, and preserving genuine independence between the safety system and the basic process control system.
Colonial Pipeline, 2021: You Do Not Need to Touch OT
Ransomware affected IT and business systems. The operator halted pipeline operations, driven by loss of business capability and uncertainty about the extent of compromise. No industrial control system was reported compromised.
What it taught. Operational availability can be lost without any OT system being attacked. IT and OT interdependency is itself an OT risk, and the shutdown decision under uncertainty is as consequential as any technical control.
Controls it justifies. Map operational dependencies on IT systems explicitly, including billing, scheduling, and logistics. Define in advance who has authority to stop the process and on what criteria. Exercise the scenario where OT is fine but you cannot verify it.
Industroyer2 and PIPEDREAM, 2022: Capability Becomes Reusable
Industroyer2 was a refined, more targeted successor aimed at electrical substations. PIPEDREAM, also reported as INCONTROLLER, was a modular framework capable of interacting with multiple vendors' controllers and protocols, discovered before any confirmed destructive deployment.
What it taught. The trend is from bespoke, single-target tooling toward reusable cross-vendor frameworks. That lowers the effort required for future attacks and changes the threat model for many asset owners simultaneously, not one at a time.
Controls it justifies. Stop assuming obscurity or vendor diversity provides protection. Assess applicability by comparing reported capability against your actual asset inventory, protocols, and reachable access paths, then close the specific paths that capability requires.
Opportunistic Attacks on Exposed Devices, 2021 to present
A distinct and now more common pattern: internet-exposed industrial devices with default or weak credentials, compromised by low-sophistication actors. Water and wastewater utilities have been repeatedly affected, including publicly documented exploitation of internet-facing PLCs and human-machine interfaces with default passwords.
What it taught. Most real-world OT compromise is not a nation-state operation with custom malware. It is an exposed device with an unchanged default password.
Controls it justifies. Find and remove internet exposure of control devices, change default credentials at commissioning, put remote access behind a brokered and authenticated path, and inventory continuously so a newly exposed device is noticed.
The Pattern Across All of Them
Three observations recur:
1. Access usually comes through ordinary means. Phishing, vendor remote access, stolen credentials, exposed services, and removable media. The industrial sophistication appears later, in the second stage, after access is established. This is the logic of the two-stage ICS Cyber Kill Chain, and the gap between stages is the defender's best detection window.
2. Adversaries increasingly use legitimate tooling. Engineering software, valid credentials, and native protocols. Detection therefore has to rest on behavioural baselines and change monitoring, not signatures. The highest-fidelity OT alerts remain unauthorized logic downloads and controller mode changes outside an approved window.
3. Recovery is contested. Backups, firmware, and communications have all been deliberately targeted. Recovery capability must be verified offline and restore-tested, not assumed.
Turning This Into a Programme
If you want a defensible priority order derived from the case history: remove internet exposure and default credentials; broker, authenticate, and record all remote access including vendor access; harden and monitor the engineering workstation; segment the safety zone with no inbound write path; deploy passive protocol-aware monitoring tuned with engineering input; and maintain verified offline backups of logic, configuration and firmware with a practised manual operation fallback.
That list is short, unglamorous, and would have complicated or prevented most of the incidents above.
Study the Domain Properly
Incident history is examinable material in industrial security certifications, and understanding *why* each case matters is what separates recall from competence. CyberCertPrep's industrial track covers OT Security Fundamentals, ISA/IEC 62443, and CompTIA SecOT+, including OT threat intelligence, historical incidents, ATT&CK for ICS, architecture and segmentation, and safety-aligned incident response, with detailed explanations for every question.
Sources & References
Daniel Agrici
CEH, Security+, PenTest+
Daniel is the founder of CyberCertPrep. With a background in penetration testing and security consulting, he has passed 8 cybersecurity certifications and writes about exam strategies and career development.
Ready to start practicing?
72+ certifications. 126,000+ questions. 20 free per cert.