WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Critical OT Data Leaked on Ransomware Extortion Sites
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Critical OT Data Leaked on Ransomware Extortion Sites

Author: Jennifer Walker

Created: Tuesday, February 1, 2022 - 19:37

Categories: OT-ICS Security

Data leaks, for whatever reason, are costly. However, financial recovery costs and costs due to damaged trust and reputation are not the only ramifications. Lost data often finds its way into the hands of advanced adversaries who use it for reconnaissance efforts to learn about potential targets, including critical infrastructure organizations.

On Monday, Mandiant Threat Intelligence published analysis based on its collection of many terabytes of stolen information from ransomware data leak disclosures in 2021. According to Mandiant, the data collected impacted over 1,300 organizations from critical infrastructure and industrial production sectors, such as energy and water utilities, or manufacturing. Mandiant’s findings estimate that approximately one in seven ransomware extortion attacks leaked critical OT data. The sensitive OT documentation included, network and engineering diagrams, images of operator panels, information on third-party services, and more. For more on the findings, visit Mandiant.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) CISA Guidance – Adapting Zero Trust Principles to Operational Technology

Apr 30, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) Forescout Reports Risk to ICS/OT Environments by Exposed Remote Access Services (RDP & VNC)

Apr 30, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar