Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: Converged Threat Actors: State-Sponsored Hacktivism in OT

Claroty
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


First time meeting you. Pleasure, how are you doing? In person. In person, yeah. Yeah, no, it's good. Thanks for having me. Yeah, of course, so I know we did one of these probably about a year ago now, and I know we spent a lot of time talking about kind of the educational material that you're putting up online. Maybe bring us up to date on what you're doing and what's changed in the last few months. I know you're constantly updating some of the content you're putting out there. Yeah, yeah. I mean, that's a big, big focus for me. You know, it's all about growing awareness and education, whether it's for owners and operators, or whether it's people that want to get into the field, or people working in the field. And so, yeah, I think it's just, we can't have enough. And so, I'm always, you know, trying to do my part and contribute to their new content. I'm just about to release an updated version of my Getting Started and OTICS cybersecurity course. So, I'm really excited about that to help, you know, people get into the, primarily people getting into the field, whether they're in engineering and want to learn more about OT cyber, or it's folks from IT cyber and want to get in. So, obviously very relevant, very timely. I mean, there's a lot of IT people that are very new to managing this stuff. So, I'm sure you're getting a lot of uptick on it. A lot of, you know, really, especially the last year, the IT CISOs reaching out, or even just, you know, directors and managers that, hey, I run IT, right, for a manufacturing company. Now, all of a sudden, I'm responsible for this OT security thing. What do I do? Right? Where do I start? And it's like, oh, well, here, I can, I can help. It's just a little intimidating. Right? Right? So, I try to tell them it'll be okay. Right? And it's okay. Here's some links. Here's some, you know, videos to watch. And here's a couple of things to read and reach out if you have questions, you know, type of thing. So, as I mentioned, we're here at S4, and you gave a talk on a converged actor framework, as you call it. Pretty relevant, again, just kind of this intersection of hacktivists and kind of how the state actors are leveraging these groups. What prompted you to look at this? I mean, an increase in activity, something else? Yeah, no, well, a couple things. You know, I preach a lot about, and this was really, I think, the main theme in the presentation. It really just came down to a lot of organizing. I've been very fortunate to work in some of the world's largest control system environments. I've been in some of the smallest, right? And everything in between. And for me, there's this commonality, this big miss I see where most environments, right, the people working there, they're just not taking the time to, you know, it's like 5, 10, 15 minutes a week to sit and look at, hey, what's going on in the world, in the outside world, outside of our plan, right, that could impact us, right? If I'm watching the news and looking at incidents that are occurring, especially those incidents that are happening in environments just like mine, right? If I'm in their shoes, and we need to be asking the questions, right? Can this impact us? And if so, what do we need to do, right, today or hopefully very soon to be able to prevent it from happening to us? And I just don't see that happening in a lot of organizations. And then it really is a gut punch when, you know, I find out that they get hit six months down the road. It's like, man, if you're just paying attention to what happened, like to your biggest competitor, which you knew, right, happened, let's say, you know, like Jaguar Land Rover goes down for, you know, five weeks, right, for global manufacturing, that should be a massive lesson not for only for everybody in OT, cyber security and in operations, but just think for the manufacturers related to like automotive and what, you know, I work with a lot of like, massive large car part manufacturers. So it's just looking, taking again, that 5, 10, 15 minutes a week, just seeing what's out there. And hey, is it something we need to pay attention to? Could this impact us? There's all lessons we can always learn, you know, from really any incident, no matter what sector we're in. And yeah, let's come up with a game plan to protect ourselves in the event that, yeah, that comes our direction. I mean, it's great advice. Because I mean, if somebody in your industry gets hit that badly, even if it's an opportunistic attack, just understanding, you know, what happened, how it happened is hugely important, as I'm sure you see. Absolutely. Yeah. So it's just, yeah, it's, it just drives me crazy when you see so many environments get hit when there was no reason to. Right. So tell me a little bit about the framework. And I know you looked at a lot of different threat actor groups and what they're doing, but there's different levels in terms of, you know, effectiveness and, and speed and so forth. Talk to me a little bit about it. Yeah, the idea was, and it's, it sounds much, much more fancier than it actually is in reality. So I think, initially, it was a conversation with with Dale and wanting to do something for S4 this year. And one thing that really has caught my attention, you know, probably over the last two, three years, is as we have more evidence of state actors aligning with hacktivists. So most in particularly, we have Russia's Sandworm, right, where we have direct evidence that shows that they have, at least at certain points, directed the activities of a hacktivist group known as the Cyber Army of Russia Reborn. So when I go in talk with owners and operators or just anybody in OT or people coming into the field, right, it's, there's a lot of misconceptions of who's doing the attacking and, and, and why. And so when you get into those conversations about, oh, well, who's going to attack us, there's still especially owners and operators, there's still so many that are so set, and we're only being targeted by state actors. And we don't have anything that Russia or China or the United States wants. So if that's the case, then we don't need to do anything about OT cybersecurity, right? So it's really this awareness and education game. So first, we're trying to get over the, there are more out there than just state actors, because we have hacktivists and ransomware operators and lone wolves and script kiddies, right, that are impacting OT environments. And then I get a little bit more fascinated when you look at it, I think, I talk in my talk about, you know, growing up on, you know, James Bond, right, and being very fascinated with the spy angle. So there's that part of me, especially that 12 year old kid that watched my first James Bond movie, Roger Moore, View to a Kill. And, and just the spy aspect. So I love, you know, the research, right. And then when you learn like the attribution, you know, it's okay, we have state actors. And now again, we have them where they're lining up with hacktivists. So state actors are normally thought to be what, you know, we don't see them often, right, very low frequency type of incidents. But when they do hit, it's a high impact, very high impact, or at least the potential, right, they usually get caught some, you know, or prevented, you know, from actually pulling the trigger, right. So there's the potential for high impact, where hacktivist, we see them as high frequency, right, we see them pretty much every day, it seems now, but when they do hit, it's okay, that, you know, we didn't lose operations, we sure we had to take an hour or two to restore a system. Whoop de doo, right? It's not a big deal. Yeah. But now as we started thinking, we have state actors aligning with hacktivists, and ransomware, you know, group operators, especially, that moving into the future, are we on this path to get to where we have high frequency and high impact. And I think there's a case to be said that it could be coming to at least a degree, right. And we're not prepared for what's happening today, as far as incidents let alone being prepared for what could potentially be coming down the road. And what do you think's driving this alignment? I mean, is it just kind of fear that, you know, the Russian intelligence is reaching out, or leveraging these folks? Or is there some kind of quid pro quo will keep you out of jail kind of thing if you work for us? I mean, yeah, there's a lot. Yeah, there's definitely a lot to unpack there. So you know, Russia has always been known to turn a blind eye to, you know, cyber attackers and cyber criminals, right? Putin had a nephew or cousin that ran one of the largest kind of hacker underground collectives for so long. And their big money was child porn, right? I mean, which is like the most evil thing in the face of the planet. But here, they're allowing them to proliferate because, oh, you know, we'll just turn a blind eye, right, you know, and then they either it just goes on to cyber criminals, you know, operating out of Russia. And I remember, you know, watching attacks, you know, after the invasion in Ukraine, that Russia doesn't even care anymore, right? They're, they're just coming at you from Russian IP addresses, right? You know, it's like they just don't even try to hide. But, but yeah, I think Russia's just trying to exploit every avenue. And they've always had that relationship, especially in the IT, right, cyber realm. Yeah. And I think that's just transitioning also to the OT. Is it a bit of a death by 1000 cuts kind of thing where they slowly erode trust in services or government's ability to protect us something like that? Is that part of the motivation as well? It could be, right? I mean, of course, the Russians are always, you know, trying to angle in on and I'm not a I should say, you know, preface this by saying, I'm like, I'm not a threat analyst. You know, I don't even try to pretend to be one. I just I do read a lot of research, though. And, and whatever I can get my hands on. So, you know, the Russians are very well known for trying to take any, any angle they can kind of that psychological warfare component. And, of course, trying to get, you know, blackmail data for her, you know, on all their targets. But, but yeah, it's, it's kind of I think they're just, at this point, trying to really use every angle they can. But especially when you look at, like with cyber army of Russia reborn, it's, oh, you have this hacktivist group acting as a front, right? So you're thinking as a defender, oh, we're just being targeted by a hacktivist group, whoop de doo, I'm not going to worry about it. But really, behind the scenes, yeah, it's, it's a state actor that's, right, or government really, at the end of the day, pulling the pulling the string. And adding to that is, is there something to the fact that a lot of these attacks are very low tech or no, you know, you don't need vulnerabilities. It's just a lot of this stuff is internet facing, especially on the OT side. It's a good question. That's kind of partly where I took the this converged actor framework idea was when you look at you have, we say it's like the front stage, or the you know, and then what's happening backstage behind the curtain, like with the Wizard of Oz, or I'm a big foodie, right? So we always think of, you know, we go to a nice restaurant, we sit down, right, you have the ambience and the great service and the incredible food. But behind the scenes, right, I always think of like, Gordon Ramsay, right, yelling at the, you know, the chef, it's just complete chaos, right? But so it's what do we see in the public view, right, versus what's going on, you know, behind the scenes. And so you start to look at, you know, from two different aspects. So, so you see, okay, the attackers that are targeting us, but yeah, is it a hacktivist group getting their, their mission, right, or their kind of commands being told to do by a state actor? Also, then it gets into this, okay, well, what if the hacktivist has a target that they're going after, in particular, and they're struggling? Like, does the state actor step in and help them? And do they lend them knowledge, tools, right? I mean, oh, here's a couple of zero day exploits, right, that we have sitting on the shelf. And I think that's definitely a very real possibility, right? Others have already talked about those instances probably have already been happening. So you have like, again, the backstage where you have like state actors, or, again, we can also say just more advanced types of, you know, evil operators that are out there, and then they're working with these other groups, and they're lending them, again, that knowledge or the tools or other resources to be able to have more of an impact on a, on a target. Yeah. And again, at the end of the day, you're saying still thinking, oh, it's a hacktivist, right? Oh, whoop-dee-doo. But behind the scenes, there's a lot more going on. And I mean, at the risk of victim shaming, there's a lot of internet internet facing OT out there that's not exactly securely online. I mean, it's true. And I, I've been watching this since, since even actually slightly before Stuxnet. And so probably what 2008-2009, ever since Shodan came online. So I think that was about 2008-2009, right, looking to see what's out there. And the numbers dropped dramatically over the years. And it actually seems over the last year or so, we got to a point where I think we kind of hit the, the, the bottom of the barrel. And I've actually started to see the numbers slightly increase. So we're actually seeing we're going the wrong way. Right? So there's like, there's this number that that's still out there. And we're actually seeing a few more kind of, like, trickle, trickle in. So it's still there's, we have a lot more to do on the awareness and the education. And, and hopefully, yeah, folks don't have to find out the hard way that, you know, they have an asset that's exposed to the internet, right? And hopefully they, you know. Just to go back to the discussion of kind of thinking about these groups and in silos, for example, just, I know, in your talk, you kind of split it up state actors, activists, ransomware groups. How does that impact defenses? I mean, is that kind of, is that the prevalent way that organizations are thinking about adversaries and probably shouldn't be? Yeah, I try to take a more realistic approach. And I try not to go down the fear, uncertainty, doubt road, you know, so it's like, let's focus on what's realistic. I think there's an idea that, yes, we in the back of our head, especially in larger environments, we have to understand, sure, what a state actor is capable of, and what could happen, right? Could an attacker get in, like cause an explosion and kill people? You know, yes, we keep those types of worst case scenarios in the back of our head. But let's spend most of our time talking about, okay, what's more realistic to happen, right? State actor causing an explosion to kill people? Or is it going to be ransomware in the IT environment taking down IT, which then has an impact in the OT environment, right? So it's not as fun or sexy to talk about. But at the end of the day, that's the most realistic scenario. So it goes back to, you need to be watching what's going on out in the real world, especially with those in your sector, right? In your field and what you're doing, watching and see what's happening, ask, what's happening? Could this happen to us? And if so, what do we need to do about it? And a lot of these incidents, right? It's not a million dollar fix to address the issue. It's usually very low cost, right, to especially get started to you can have a high impact, lowering your risk. Again, if you're just paying just a little attention, and of course, more importantly, taking taking action. Yeah. And I mean, it probably should cause organizations to look at their threat modeling, too. I mean, not everybody's a state actor target, but right, right. And I said that it's kind of, I still see that, especially with leaders, or if you're working like with an IT CISO, right? The vast majority of IT CISOs that I've met with, right, they're really great in working in the IT environments. But they can't spell OT, right? And that's, and that's no fault to their own. And some are really doing a great job of getting up to speed as quickly as possible. Yeah, there are also a lot out there that aren't. Right. And so that's, it's another, it goes back to awareness and education. And hey, I got a free YouTube course that you need to watch, you know, of course, in all of your spare time, right? But it will give you an idea of the basics to help protect the environment, especially for those IT CISOs or other IT leaders that all of a sudden, oh, I'm now responsible for OT. Like what the heck is this thing? And where do I start? A lot of that. Just going back to your framework and kind of the structure of it, how would you like to see people use it? Who should be using it? How, what are the outcomes they should be looking for? So by the time I got through doing some of the additional work and the research and trying to come up with this idea of the framework, and that it really, it came, it really boiled down to get more awareness and education, right? Looking to see what's going on out there, looking to see, is this going to impact us? And if so, what can we do about that? And honestly, and I've done this with chat GPT and Gemini, and you can, you can say, hey, I work in, listen, water treatment, right? And talk about or tell me about the top five, 10 incidents that have happened in the last couple of years. Tell me what happened, right? Ask it, tell you, tell me what happened, right? Tell me, oh, how would I, you know, protect against these types of attacks in my environment? You're creating an action list. And you know what, it's like, 98 99% of the time, like, it's actually really, really quality responses, right? So you, especially for environments that they don't have all of the resources in the world, especially the small, medium sized environments, limited budgets, right? You can use free tools like that, right? To give you an idea, you don't have to pay a consultant to come in and tell you the same thing that chat GPT and Gemini, you know, is going to tell you I know that's a whole other podcast. But But yeah, so it's, but it's just paying attention to what's going on. Understanding that, that threat landscape is evolving. And it doesn't matter who you are, what sector, you are a target. Right? It's just a matter of when the attackers get to you, right? They could be in your network today. They maybe it's in six months, but they're coming. It's only just like an IT, right? We always say, like, it's not a question of if it's a question of when. Yeah. And that's the same. What's, I mean, this may be an obvious answer, but what's putting ot in control systems in the crosshairs of these groups at the moment? Is it simply connectivity? Is it just you know, what's happening? I mean, there was a big shift that we had in the landscape with colonial pipeline. Yeah. Because before colonial pipeline, it was only pretty much state actors that we worried about and talked about, because they were the ones that had the engineering knowledge. So if they got into an OT environment, they could reverse engineer the environment to have an impact on the process. Colonial pipeline showed, hey, you don't have to be a state actor to have an impact in OT, you can take down the United States largest gasoline pipeline, right by just deploying ransomware and burning IT down to the ground. Same thing essentially happened to Jaguar Land Rover, right? They had systems in IT that they needed to run operations. And so you lose IT, you lose operations. And so that's really looking at just kind of this shift in the landscape. And that at that point, it's now that's why hacktivists are out there coming after OT, right? That's why the ransomware operators that are coming, and either they're coming after OT directly, or, again, like colonial pipeline, hey, I don't even have to understand like engineering or how I have an impact. I just know, hey, if I burn down IT, or if I'm in a position where you don't pay my ransom, and I burn it down, right, you're more than likely to pay. So you have a lot more attackers coming for a lot more visibility, right? There's more money for ransomware operators. If I'm a hacktivist, right? Oh, I want to make a lot of noise, right? I want to be in the news. So there's a lot more opportunity there than that they have a lot of times now in IT. And what's your opinion in terms of disruption versus damaging attacks, for example, is there more immediate value anyway, in disrupting operations, disrupting critical services than, you know, dumping a wiper out there and destroying computers? Yeah, I think overall, they're still looking at disruption. So that's because, again, hacktivist, that's going to make noise, right? If I'm a ransomware operator, that's going to get me paid quicker. And so I can just move on to the next victim right now. So I think it's mostly about that. But we did see in Poland, right? Yeah, the state actor, right? Take out 30 substations, right? Wiped all the machines, right? Very, very, very trademark signature of the Russians, right? But and that was another one. It's a great example, though, of, hey, are you watching what's going on on the real world? Even if you're in water treatment, right? You can see what happened in Poland and the grid and say, oh, the attackers got in through weak edge devices with firewalls. Okay, we Hey, do we have those in our environment? Oh, we do. You know, are we vulnerable? Let's what can we do about it? And then default credentials, right? And that was right. That's the other one, right? Killing off IDs and RTUs inside the environment because they had default credentials, right? And so it's like, oh, do we have any of those? We don't know. Well, we need a program in place to figure out right. Yeah, whether you do or not. And that really just comes down to asking those questions if we're watching to see what's going on. So before we wrap up, I know attribution was also part of your of your presentation and your discussion. I always wonder, do victims really care? Or do they just want these guys off the network? I know if you're a military defense agency, government agency, it's a different conversation, but for the enterprise, just give me your thoughts there. Yeah, part of it. And this was one of the things I have have seen come up more than a few times as well. But that's where I started the talk off talking about, you know, me as a little kid, you know, James Bond is absolutely fascinated at 12 years old. It was also, you know, just before that, I saw war games, right. And with war games, that's when I got into computers and cybersecurity. And I've always carried that, you know, through my career. And so whenever there's and I've, I've responded to a lot of incidents, like in it, and, and in some in OT now. And when you look at from an attribution perspective, right? Does it? Does it matter if I know who it is? Right? If we're in like, hour two of an incident, and the plant is down, right? And the executives, right? They're always the two questions they're always going to ask is, when are we back up? Yeah. And who is it? You know, they want to know. It doesn't matter. No, right. We just want them off the network, right? We want to figure out how they got in, right, what they've been doing, so we can get them off and reverse everything that they've done and make sure we're safe. And we keep running, right, right. That's all that matters. But like you mentioned, now, down the road, right, from a strategic perspective, right, whether sure, at a national level, or even those companies, right, if you do, like I've been in environments, like where we work with companies like a Dragos or Mandiant, right, where you get the the kind of the feedback where, okay, it was the state actor, right? And then you can use that to get a better understanding of that adversary, why they're targeting you, right? Maybe even saw particularly what they're doing environment. And then it just goes back to, okay, how do we shift our program? And what do we need to do to prevent this from happening in the future? Alright, so last question. I mean, we've been talking about offensive capabilities throughout most of this conversation. Let's talk about defending. How do you defend against activists that, you know, the TTPs very widely, probably? I mean, even if the state actors involved, there's a bit of variance there as well. Yeah, well, there's that, you know, I always, I'm very practical. I think I always focus on the basic fundamentals. And then I literally created the acronym for basic. So BASIC. So I always talk about backup and recovery, most importantly, because I see too many environments get hit. At least you want to get back up and running, right? At least so absolutely. Then when we talk about asset management, right, which we're always talking about, right, so knowing what's in the environment, because then that helps us when we get to secure network architecture, right, things like segmentation, having the firewall between IT and OT, which you still don't see in a lot of large environments. It's crazy. Yeah, right. Incident response planning, and then continuous vulnerability management, right, all those to come place. And then my, my next big one is network security monitoring, right? Even though it's one of those, it's a struggle for a lot of those small, even some medium sized shops, right? They just don't have the resources. Yeah, exactly. They, you know, but right, if you can get to that point, that's the road that you want to be on, right? At least even just be looking at your firewall logs. Hopefully you have a firewall lock now, right? And if you don't get that, and then start looking at, you know, what traffic is allowed between IT and OT and what's being blocked. And just by doing that, you can find so many, even if you don't find a hacker in the environment, you can find so many operational issues that you can fix before it impacts the plan. A lot of basics go a long way, right? It really does. It's it's like the vast majority of the game, right? And then sure, you can do all the bells and whistles. And you can talk about a march to zero trust, you know, principles, but at the end of the day, you nail the fundamentals. And that's the vast majority of your risk, right? All right. Good to see you. Thank you so much for the time. All right. Bye bye.

TL;DR

  • State actors like Russia's Sandworm are increasingly directing hacktivist groups such as the Cyber Army of Russia Reborn, creating a convergence that combines high-frequency attacks with high-impact potential while obscuring attribution.
  • The Colonial Pipeline attack proved that adversaries don't need OT engineering expertise to disrupt critical infrastructure—compromising IT systems that operations depend on is sufficient to halt production.
  • Most OT environments remain unprepared for current threats, with many organizations failing to spend even 5-10 minutes weekly monitoring sector-specific incidents that could inform their defensive strategies.
  • Holcomb's BASIC framework (Backup/recovery, Asset management, Secure architecture, Incident response, Continuous vulnerability management) addresses the majority of OT risk through practical, low-cost fundamentals.
  • The number of internet-exposed OT assets has begun increasing again after years of decline, indicating that awareness and education efforts still have significant ground to cover in the industrial cybersecurity community.

The Converged Actor Framework

Mike Holcomb introduces his Converged Actor Framework, developed for the S4 Conference, which examines how state actors are increasingly aligning with hacktivist groups to target operational technology environments. The framework categorizes threat actors based on attack frequency and impact potential, revealing a concerning trend: state actors traditionally characterized by low-frequency, high-impact attacks are now leveraging high-frequency hacktivist groups to amplify their reach. This convergence challenges conventional threat modeling, as defenders may dismiss hacktivist activity as low-impact nuisance attacks while missing the state-sponsored coordination occurring behind the scenes. Holcomb emphasizes that Russia's Sandworm group has been directly linked to directing the Cyber Army of Russia Reborn, demonstrating how nation-states use hacktivist fronts to obscure attribution while maintaining operational control.

The Colonial Pipeline Paradigm Shift

The Colonial Pipeline ransomware attack fundamentally changed the OT threat landscape by proving that adversaries don't need deep engineering knowledge to disrupt critical infrastructure. Before this incident, the prevailing assumption was that only sophisticated state actors with specialized OT expertise posed serious threats to industrial control systems. Colonial Pipeline demonstrated that ransomware operators could cripple the United States' largest gasoline pipeline simply by compromising IT systems that operations depended on. This IT-to-OT impact model has since been replicated in incidents like the Jaguar Land Rover shutdown, where manufacturing operations ceased for five weeks due to IT system compromise. Holcomb argues this shift has democratized OT attacks, attracting ransomware operators seeking higher payouts and hacktivists pursuing greater visibility, fundamentally expanding the threat actor pool beyond traditional state-sponsored groups.

Practical Defense Through Situational Awareness

Holcomb advocates for a practical defense approach centered on continuous situational awareness rather than fear-driven worst-case scenario planning. He recommends that OT security teams dedicate just 5-10 minutes weekly to monitoring incidents in their sector, asking critical questions: Could this happen to us? What can we do to prevent it? He points to the Poland grid attack, where adversaries compromised 30 substations through weak edge devices with default credentials, as a teachable moment for all critical infrastructure sectors. Organizations can leverage free tools like ChatGPT and Gemini to analyze recent sector-specific incidents and generate actionable remediation lists. His BASIC framework—Backup and recovery, Asset management, Secure network architecture, Incident response planning, and Continuous vulnerability management—provides a foundation that addresses the vast majority of risk without requiring massive budgets. Holcomb emphasizes that most protective measures are low-cost, high-impact interventions that simply require attention and action rather than expensive technology investments.

Chapters

0:00 - Introduction and Educational Content Update
2:14 - The Converged Actor Framework Concept
5:56 - State Actors Aligning with Hacktivists
9:03 - Russia's Cyber Criminal Relationships
11:56 - Front Stage vs Backstage Threat Activity
14:04 - Internet-Exposed OT Assets Trending
15:23 - Realistic Threat Modeling for OT
20:29 - Colonial Pipeline's Impact on Threat Landscape
22:06 - Disruption vs Destructive Attacks
23:37 - Attribution: Does It Matter to Victims?
26:02 - Defending with BASIC Fundamentals

Key Quotes

6:01 "We have direct evidence that shows that they have, at least at certain points, directed the activities of a hacktivist group known as the Cyber Army of Russia Reborn."
8:26 "Are we on this path to get to where we have high frequency and high impact. And I think there's a case to be said that it could be coming to at least a degree, right. And we're not prepared for what's happening today, as far as incidents let alone being prepared for what could potentially be coming down the road."
13:10 "What if the hacktivist has a target that they're going after, in particular, and they're struggling? Like, does the state actor step in and help them? And do they lend them knowledge, tools, right? I mean, oh, here's a couple of zero day exploits, right, that we have sitting on the shelf."
15:46 "I've actually started to see the numbers slightly increase. So we're actually seeing we're going the wrong way. Right? So there's like, there's this number that that's still out there. And we're actually seeing a few more kind of, like, trickle, trickle in."
20:34 "Colonial pipeline showed, hey, you don't have to be a state actor to have an impact in OT, you can take down the United States largest gasoline pipeline, right by just deploying ransomware and burning IT down to the ground."
25:00 "Does it matter if I know who it is? Right? If we're in like, hour two of an incident, and the plant is down, right? And the executives, right? They're always the two questions they're always going to ask is, when are we back up? Yeah. And who is it? You know, they want to know. It doesn't matter."

FAQ

Why should OT defenders care about attribution if the immediate priority is removing attackers from the network?

During active incident response, attribution is secondary to containment and recovery. However, post-incident attribution provides strategic value by revealing adversary motivations, tactics, and targeting patterns that inform long-term defensive improvements. Understanding whether an attack was state-sponsored versus opportunistic ransomware helps organizations adjust their security posture and resource allocation appropriately.

How can small and medium-sized OT environments with limited budgets improve their security posture?

Holcomb recommends starting with his BASIC framework fundamentals: implement backup and recovery capabilities, establish asset inventory, deploy basic network segmentation with IT-OT firewalls, develop incident response plans, and begin continuous vulnerability management. He also suggests using free AI tools like ChatGPT to analyze sector-specific incidents and generate actionable remediation lists, eliminating the need for expensive consultants in the initial stages.

What changed in the OT threat landscape after the Colonial Pipeline attack?

Colonial Pipeline proved that attackers don't need specialized OT engineering knowledge to disrupt critical infrastructure—they can achieve operational impact by compromising IT systems that operations depend on. This realization attracted ransomware operators seeking higher payouts and hacktivists pursuing greater visibility, fundamentally expanding the threat actor pool beyond traditional state-sponsored groups with deep technical expertise.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Threat Intelligence
  • Critical Infrastructure
  • Technical Deep Dive
  • Best Practices
  • State-Sponsored Hacktivism
  • OT Threat Actor Convergence
  • Critical Infrastructure Security
  • Ransomware Impact on Operations
  • IT-OT Security Convergence
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: Converged Threat Actors: State-Sponsored Hacktivism in OT

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version