
An NCSC hacktivist alert lands the same way every time: a flurry of internal emails, a question from the board about whether "we are affected", and a security team that already knows the honest answer is "we are not sure, because nobody has looked from the outside recently". This piece is the version of the response that fits in two working days. Not a strategy programme. A hunt for the specific internet-facing things ideologically motivated groups actually scan for, a method for testing whether a claimed breach on a Telegram channel is real, and a single page you can put in front of a board at the end of it.
The pattern across recent NCSC and international partner warnings is consistent. Pro-Russia and ideologically motivated groups are not building bespoke industrial malware for most of what they do. They are scanning the public internet for operational technology that answers without a password, or with the factory default the vendor shipped, and then using the legitimate interface to change something.
The clearest public description of this remains the joint advisory published on 1 May 2024 by CISA, the FBI, the NSA, the EPA and international partners including the NCSC, covering pro-Russia hacktivist activity against operational technology. It documented groups manipulating human machine interfaces at water and wastewater utilities in North America and Europe, altering setpoints, disabling alarm functions and driving equipment past safe operating parameters, with at least one case producing a tank overflow. Access was largely through unauthenticated or default-credentialled remote access software, including VNC.
Read that again, because the remediation follows from it. If the route in is an exposed interface and a default login, the fix is removal of internet exposure and a credential change, not an ICS patching programme that takes nine months and a shutdown window. Most guides get this backwards and send operators off to build a vulnerability management plan when the actual finding is a panel that should never have been reachable in the first place.
Groups scanning ranges do not consult a register of designated operators. They find what answers. The maintenance contractor with a remote support tunnel into three water sites, the building management provider running HVAC controls for a council estate, the small manufacturer whose engineering team connected a gateway so a vendor could diagnose a line remotely: all of them inherit the target profile of the organisations they serve. Supply chain position matters more than sector labelling, which is a lesson the supplier blind spots exposed in the Glasgow Council incident made uncomfortably clear.
For operators of essential services, the NIS Regulations 2018 and the NCSC's Cyber Assessment Framework already require you to know your assets and manage external exposure, which is exactly what this check evidences. The Cyber Security and Resilience Bill, before Parliament at the time of writing, is expected to widen the population in scope and tighten reporting duties, particularly around managed service providers and suppliers. If you want the longer view on that, our readiness checklist for the Cyber Security and Resilience Bill covers it properly. For the next 48 hours, treat the alert as an operational task and let the compliance mapping catch up afterwards.
Work the list in this order, because it mirrors the order an opportunistic scanner finds them.
Control interfaces on the public internet. VNC answering on TCP 5900 with no authentication is the classic. Web-based HMIs on 80 and 8080 running vendor default credentials come next, followed by remote desktop services published straight to the internet. Modbus on 502, and similar industrial protocols reachable publicly, tells you a network boundary has failed somewhere upstream.
Remote access routes nobody owns any more. End-of-life VPN appliances still accepting connections years after the contract that installed them ended. Engineering jump boxes built for a commissioning phase that never got decommissioned. Vendor support tunnels and dial-home links authorised verbally in 2019. These rarely appear in a CMDB because the team that created them was not IT. The pattern is the same one we walked through in the Check Point VPN exposure checklist: the appliance is not the problem, the forgotten instance of it is.
Cheap edge devices bridging office and plant. Cellular routers, serial-to-Ethernet converters, smart building controllers. Often installed by a facilities contractor, often with a management interface published because it made support easier.
Web estate that invites defacement. Campaign microsites from a marketing push three years ago. An acquired subsidiary's domain still resolving to a server nobody patches. Staging environments answering on a live hostname. Defacement almost always lands here rather than on the main corporate site, because the main site has an owner.
Start outside in. The asset register is the wrong starting point because it contains what someone remembered to record, and shadow IT, acquired infrastructure and engineering-deployed kit are precisely the categories it never contains. Run external asset discovery against your domains, IP ranges and known subsidiaries, then look at the results from the attacker's perspective rather than reconciling them against the list you already had.
Use geographic and DNS views deliberately. A site in one country, a plant in another and a subsidiary acquired two years ago will often surface hosts nobody inside the security function has seen. That is the point of the exercise.
Run infrastructure scanning and web application scanning together, then deduplicate hard before anyone starts remediating. A response list of 400 rows describing the same TLS finding across a load-balanced estate is not a response list, it is a morale problem. You want exposures, ranked, with a route to the thing that owns them. Combined infrastructure and application scanning is useful here mainly because it lets you separate "an attacker can reach the control plane"from "an attacker can read a version banner".
Record ownership as you go, and record it in the form that matters at 2am: who can physically or logically pull the plug on this service, and how long would it take them? A named engineer with firewall access beats a department name every time.
Remove before you patch. Taking an HMI or a management panel off the public internet and putting it behind a VPN with multi-factor authentication is a change you can make today. Scheduling firmware on a live process is a change you make in a shutdown window, possibly next quarter. For the opportunistic activity described in the 2024 joint advisory, removal of exposure closes the route entirely.
Then credentials. Reused engineering and vendor logins are a faster way in than any exploit, and stealer logs routinely contain plant and SCADA portal credentials alongside the usual corporate ones. Check leaked credential and stealer log findings for your domains and for vendor domains that hold access into your environment, then rotate anything that appears with a plausible timestamp. Default vendor accounts on engineering kit get changed regardless of whether they show up in a dump.
Prepare for the noisy outcomes while you are at it. Confirm rate limiting and DDoS protection on public sites, confirm who you call at your hosting and CDN provider out of hours, and identify which domains you could actually lose control of because the registrar account belongs to an agency that no longer works with you. Run an available and lookalike domain check on your primary brands and on the names of any recently announced contract or project. If a spoof site appears, you need evidence collection with timestamps and a registrar communication route, not an abuse email into a queue.
A realistic outcome for a mid-sized operator over two days: external discovery surfaces dozens of hosts nobody listed, a handful of those expose management or control interfaces, two or three get pulled behind a VPN or firewalled the same day, and the remainder leave the exercise with a dated owner rather than a vague intention.
Claim inflation is routine. Groups recycle old dumps, combine unrelated leaks under one victim name, and describe a twenty-minute DDoS against a brochure site as a compromise of core operations. Declaring an incident on the strength of a screenshot costs you a night, a legal call and sometimes a regulator conversation you did not need to have.
Victim lists, claimed samples and coordination chatter surface on Telegram and on dark web forums long before they reach the press, and posts are deleted or edited constantly. Monitor Telegram channels and dark web sources for your brand names, domains, subsidiary names and key personnel, and capture screenshots, file hashes, channel identifiers and timestamps the moment something appears. Our practical guide to monitoring Telegram for threats covers the channel selection and collection process in more detail.
Then test the sample rather than the filename. Do the column headers match your actual data structures? Do the employee records match your directory, including people who left? Does the date range line up with a system you operate, or with a third party you happened to use in 2021? Cross-checking identities against internal versus external classification usually resolves the question inside an hour.
The line between hacktivist persona and state-linked unit has blurred, and that has consequences beyond attribution. It changes who you notify and when. It changes how your insurer reads hostile act and war exclusions in a cyber policy. And it changes your interpretation of a noisy claim, because a self-styled activist group running a DDoS against your website may be the visible half of reconnaissance that is happening slowly and quietly somewhere else. Treat a public claim as a prompt to check authentication logs on remote access, not just as a communications problem.
Politically charged announcements draw personal attention. A contract award, a public statement on a sensitive issue, a council vote: each is a plausible trigger for doxxing of named executives, council leaders and spokespeople. The material used is rarely stolen. It is a conference bio with a home town, a geotagged site photo, a LinkedIn job advert naming your control system vendor, a personal email address reused across breached consumer services.
Blanket monitoring across every employee produces noise nobody actions. Separate internal from external identities, score exposure per person, and concentrate protection where the exposure is real and the profile is raised. Our note on who to cover in executive monitoring and the mistakes that leave people exposed covers the selection criteria. Pair it with open source intelligence monitoring so the operational detail leaking through recruitment and marketing gets caught as well as the personal data.
One page. Exposures found and removed, with counts. Exposures accepted, each with a named owner and a date. Claims verified or dismissed, with the evidence that settled it. Nothing about scanner scores.
Then make it continuous, because a two-day snapshot ages badly. Weekly change reporting is the part people underestimate: a newly exposed panel should reach you as a Monday morning item from your own monitoring, not as a Telegram post. Route findings into Slack, Microsoft Teams, Jira or your ticketing system so each one carries an owner and a clock, and feed confirmed exposure events to the SIEM so detection content can reference them.
Finish with suppliers. Score the contractors who connect to your plant, ask what they expose on the internet on your behalf, and read the scope statement on any ISO 27001 certificate they send rather than the certificate number. Scope is where supplier assurance usually falls over.
The organisations that come out of an NCSC hacktivist alert well are not the ones with the largest security budget. They are the ones that can answer, within two days, what they expose to the internet and who owns each piece of it. If you want continuous visibility of that external attack surface rather than a fire drill every time an advisory lands, set up a free DarkInvader account and start from what attackers can already see.
Yes, if you supply, maintain or connect to organisations that are. Opportunistic scanning finds exposed interfaces regardless of sector designation, and maintenance contractors, building management providers and MSPs frequently hold remote access into environments that do fall in scope. The practical test is not your sector label, it is whether anything you operate is reachable from the internet and touches an operational network.
Remote access and control interfaces that answer without proper authentication. VNC on TCP 5900, web HMIs on 80 and 8080 with vendor defaults, published remote desktop, industrial protocols such as Modbus on 502, and end-of-life VPN appliances still accepting connections. Forgotten web estate, including staging sites and old campaign domains, is the usual defacement target.
Capture the post, file hashes and timestamps first, because claims get edited and deleted quickly. Then test a sample against your own data structures and employee records rather than trusting the filename or the screenshot. Recycled dumps, merged unrelated leaks and short DDoS attacks presented as full compromises are all common, so verify before you declare an incident.
Report significant incidents through the NCSC's incident reporting route at ncsc.gov.uk, and remember that operators in scope of the NIS Regulations 2018 have their own notification duties to a competent authority. Criminal activity should also go to Action Fraud, or Police Scotland in Scotland. If personal data is involved, the ICO reporting clock applies separately.
Continuously, with a weekly review of what changed. A one-off scan tells you about a single moment, and internet-facing estate changes every time a team spins up an environment or an engineer connects a gateway. Ongoing asset monitoring turns new exposure into an alert with an owner rather than a discovery you make after someone else has made it first.
Unlock full visibility of your external attack surface with DarkInvader’s continuous, real-time monitoring. Create your free account to discover unknown assets, detect emerging risks and stay ahead of potential threats before attackers can exploit them.
Create My Free Account