Closing the Identity Gaps in Critical Infrastructure Security

Critical Infrastructure Under Siege: How State-Backed Actors Are Exploiting Identity Gaps

The 2021 Colonial Pipeline ransomware attack was a stark reminder of how quickly a compromised account can turn into a national crisis. The attackers exploited an inactive VPN account without multi-factor authentication, disrupting fuel supply across the U.S. East Coast and highlighting the vulnerability of critical infrastructure to cyber threats. Five years on, the lessons from Colonial Pipeline are more relevant than ever, as state-backed actors increasingly target these networks with the intention of holding access that could be used in a crisis.

Critical infrastructure is attractive to attackers because disruption creates pressure far beyond the breached organization. Today, we’re seeing a new wave of threats aimed at exploiting identity gaps within critical infrastructure networks. State-sponsored actors are looking for persistence inside these networks, not just to steal data but to hold access that could be used as leverage in times of crisis.

The initial attack path is often the same: threat actors exploit stolen credentials, unmanaged devices, compromised laptops, remote access tools, and weak access controls to gain a foothold. Zero trust has become an operational necessity for organizations delivering essential services, offering a security model that addresses these vulnerabilities by assuming all users are malicious until proven otherwise.

The identity threat facing critical infrastructure is multifaceted. As systems become increasingly interconnected, the challenge of securing them grows exponentially. CISA’s recent guidance on adapting zero-trust principles to operational technology (OT) environments acknowledges this complexity, emphasizing asset visibility, identity and access management, segmentation, monitoring, and supply chain risk as key areas for focus.

However, OT is not the only area where critical infrastructure is exposed. Essential services also depend on IT systems, cloud platforms, and SaaS applications, making them equally vulnerable to cyber threats. The Colonial Pipeline attack demonstrated that compromising business-critical systems can cause just as much damage as breaching OT.

Threat actors like Volt Typhoon are expertly exploiting these vulnerabilities, blending into normal network activity rather than triggering obvious alerts. They exploit vulnerable edge devices such as routers, firewalls, and VPN appliances using stolen administrator credentials and legitimate accounts. By leveraging “living off the land” techniques and built-in tools instead of malware, they make their activity appear routine.

Moreover, routing traffic through compromised devices makes attribution and detection even harder. The concern is not only espionage but also the possibility that persistent access could support disruption during a future geopolitical crisis. Organizations must rethink trust and focus on implementing zero-trust principles to protect against these sophisticated threats.

Implementing zero trust requires more than just multi-factor authentication (MFA). While MFA remains essential, it’s not enough if attackers can compromise a session, enroll a rogue device, exploit a trusted remote access path, or use a legitimate account from an unmanaged endpoint. Organizations must adopt a comprehensive approach to security, focusing on identity and access management, segmentation, monitoring, and supply chain risk.

In conclusion, critical infrastructure is under siege by state-backed actors who are exploiting identity gaps within these networks. It’s imperative for organizations delivering essential services to rethink trust and implement zero-trust principles to protect against these sophisticated threats. By doing so, they can ensure the security of their systems and prevent disruption during times of crisis.


Source: Bleeping Computer — 2026-07-21