I have spent two decades in this industry. The attacks described in this advisory are not sophisticated. They are exploiting the same gaps I keep finding across the region.
On December 9, 2025, CISA, the FBI, NSA, and international partners issued a joint advisory on pro-Russia hacktivist groups conducting opportunistic attacks against critical infrastructure globally.
When I read it, I did not see a warning about a distant threat.
I saw a description of vulnerabilities my team and I have documented across water utilities, power generation facilities, petrochemical plants, and smart city infrastructure throughout the Gulf over the past two years.
- The targets in the advisory: water and wastewater systems, food and agriculture, and energy sectors.
- The methods: exposed VNC connections, brute force password attacks, and unmonitored remote access.
No zero-day exploits. No advanced persistent threat tradecraft. Just basic reconnaissance against systems that should never have been internet-reachable in the first place.
The advisory states these attacks have already caused “physical damage” in some cases.
For Critical National Infrastructure (CNI) operators across Saudi Arabia, the UAE, Qatar, and the wider GCC, this is not a warning about American infrastructure. It is a mirror.
Why I Am Writing About This Now
I have had three conversations this week with CISOs and OT security leaders in the Gulf about this advisory.
The reaction was consistent. Not surprise. Recognition.
One told me: “We know we have exposed assets. We just have not had the mandate to fix them.”
Another said: “Our vendor access controls exist on paper. But I cannot tell you right now how many active remote sessions are connected to our OT environment.”
A third was more direct: “If these hacktivists scanned our perimeter tomorrow, they would find us.”
That honesty is rare. And it is exactly where progress begins.
But it also tells me something about the state of OT security across the region. The gaps are known. The policies exist. The execution is where we are failing.
What I Keep Finding Across the Gulf

Over the past two years, my team and I have assessed OT security posture across manufacturing, oil and gas, utilities, and food and beverage operations in Saudi Arabia, the UAE, and the wider GCC.
The patterns are consistent. And they map directly to the attack vectors described in this CISA advisory.
Internet exposure that should not exist.
In one recent assessment, we found over 40 exposed ICS components across a single client’s regional operations. Ninety percent lacked basic access controls. SCADA interfaces were discoverable through Shodan. HMIs were accessible without VPN. Engineering workstations were reachable from contractor networks.
The client had passed their last compliance audit. Their documentation was excellent. Their exposure was invisible to them until we showed them what an attacker would see.
Vendor access that never expires.
At a petrochemical facility last year, we found TeamViewer sessions to PLCs that had been active continuously for over 11 months. The original project had completed. The vendor had moved on. But the access remained.
No one owned it. No one monitored it. No one knew it was there until we asked.
This is the exact attack vector the hacktivists in the advisory are exploiting. They do not need sophisticated tools. They need an open door that no one is watching.
Authentication treated as optional.
I cannot count how many times I have heard “we need MFA exceptions for executives” or “the vendor cannot work with our authentication requirements.”
Every exception is a decision to accept risk. The problem is that these decisions are rarely documented, rarely reviewed, and rarely owned by someone accountable for the consequences.
The Oldsmar water treatment attack in the United States succeeded because of exactly these conditions. An attacker accessed a water treatment system through a remote connection with no MFA and changed chemical levels to dangerous concentrations. The only reason it did not cause harm was because an operator noticed the mouse moving on his screen.
That is not security. That is luck.
Visibility gaps between IT and OT.
In most organizations I assess, the SOC is instrumented for IT traffic but blind to industrial protocols. They would catch a phishing email. They would miss an attacker connecting directly to a SCADA system via VNC.
When I ask “can you see remote connections to your OT environment in real time?” the answer is usually silence.
Governance that exists on paper only.
I have reviewed countless policy documents aligned to NCA OTCC-1 or IEC 62443. Segmentation diagrams that look correct. Asset inventories marked as comprehensive.
Then I walk the plant floor. I find flat networks. Shared VLANs between IT and OT. Controls that were defined in a document but never enforced in hardware.
The hacktivists in this advisory did not break sophisticated defenses. They walked through doors that were left open.
Why This Matters More Here

I have worked across critical infrastructure in Europe, Asia, and the Middle East. The Gulf is different.
National visibility is immediate.
When a desalination plant in the UAE or a power distribution network in Saudi Arabia experiences disruption, it becomes a national trust issue within hours. There is no quiet recovery period. The public expectation is zero tolerance for service interruption.
I have seen what happens when an incident becomes public before an organization is ready to communicate. The reputational damage compounds faster than the technical recovery.
Interdependence amplifies blast radius.
Water, power, and transport infrastructure in the GCC are tightly coupled. A failure in one sector cascades faster than in more fragmented markets. A water treatment disruption during peak summer demand is not an inconvenience. It is a crisis that touches every citizen.
Mega-project timelines compress governance.
Vision 2030 and similar national transformation programs drive aggressive deployment schedules. New facilities come online rapidly. I support that ambition.
But speed without validation creates the exact exposure patterns these hacktivist groups exploit. Vendor access left active after commissioning. Remote connections never decommissioned. Authentication bypassed because “we need to meet the deadline.”
I have sat in meetings where security concerns were acknowledged and then deprioritized because the launch date was fixed. The risk does not disappear. It accumulates.
Geopolitical targeting is not theoretical.
The Middle East sits at the intersection of global energy security and regional power competition. Iranian state-sponsored groups have targeted Gulf infrastructure for years. Russian-aligned hacktivists see value in disrupting Western-allied nations. Chinese APTs have conducted long-dwell campaigns across the region’s energy sector.
I have reviewed incident reports from regional operators that never made headlines. The targeting is real. The intrusions are happening. The question is whether organizations are detecting them.
What the Advisory Actually Revealed

The hacktivist groups identified include Z-Pentest, Cyber Army of Russia Reborn (CARR), NoName057(16), and Sector16.
Let me be clear about what these groups are and are not.
They are not sophisticated nation-state actors. They lack the resources and tradecraft of groups like Sandworm or Volt Typhoon.
And yet they are succeeding.
Their playbook is straightforward. They scan for internet-exposed OT devices with open VNC ports. They brute force credentials using commodity tools. They gain access to SCADA systems and HMIs. They manipulate control settings or deface interfaces to generate media attention.
Z-Pentest, which formed in September 2024, specializes specifically in OT intrusion operations. Unlike other groups focused on DDoS, they claim OT access to generate headlines for pro-Russia messaging.
The advisory notes some attacks have resulted in physical impact. Not data theft. Actual operational consequences.
This is what concerns me most. These are not advanced attackers. They are persistent opportunists scanning for low-hanging fruit. And they are finding it.
The Larger Signal I Noticed This Week

The CISA hacktivist advisory was not the only relevant finding.
Amazon’s threat intelligence team released details on a years-long GRU campaign (Sandworm) targeting energy and cloud infrastructure across North America, Europe, and the Middle East.
The notable finding: starting in 2025, these sophisticated attackers have shifted away from zero-day exploitation toward targeting misconfigured network edge devices.
I have been tracking this evolution for months. When advanced adversaries stop investing in expensive vulnerability research and start hunting for misconfigurations, it tells us something important.
They are not working harder because they do not need to.
Exposed management interfaces, weak authentication, and poor segmentation provide easier paths than zero-days ever did.
For Middle East Critical National Infrastructure (CNI) operators, this means the threat landscape has shifted. The most likely initial access vector is not a sophisticated exploit. It is a misconfigured firewall, an orphaned VPN connection, or a forgotten vendor account.
That is actually good news. Because these are problems we can fix without waiting for new technology or additional budget.
They require discipline, not innovation.
What NCA OTCC-1 and Regional Regulations Already Require

I want to be direct about something.
Saudi Arabia’s NCA OTCC-1:2022 framework explicitly addresses the controls that would prevent these attacks.
Access control requirements mandate strong authentication for remote connections. Network security controls require segmentation between IT and OT environments. Asset management requirements demand current inventories of all connected devices. Monitoring requirements specify detection capabilities for unauthorized access attempts.
The UAE’s DESC regulations impose similar requirements for critical sector operators.
These are not optional guidance. They are regulatory mandates.
The question I keep asking clients is whether they are implementing these as living operational controls or treating them as compliance documentation that sits in a folder between audits.
I have seen organizations pass OTCC-1 assessments with documented policies that do not reflect operational reality. The segmentation exists on a diagram. The authentication policy is signed. But the controls are not enforced.
The gap between passing an assessment and preventing the attacks described in this advisory is the gap between paper resilience and plant resilience.
One produces certificates. The other produces safety.
Five Actions I Am Recommending to Clients This Month

Based on this advisory and what I am seeing across the region, here is what I am telling every Critical National Infrastructure (CNI) client right now.
1. Commission an external exposure scan.
Do not rely on internal assessments alone. Engage a third party to scan your OT perimeter the way an attacker would. See what Shodan and Censys reveal.
I have done this exercise with clients who were confident they had no exposure. They were wrong. The external view is always different from the internal assumption.
2. Audit all remote access to OT.
Every VPN tunnel. Every VNC session. Every jump server. Every vendor connection. Document who owns each one. Verify whether it should still be active. Decommission everything that cannot be justified.
In my experience, at least 30 percent of active remote access to OT environments should not exist. It is left over from completed projects, forgotten integrations, or convenience decisions that were never reviewed.
3. Enforce MFA without exception.
No executive exemptions. No vendor exemptions. No “temporary” bypasses that become permanent.
I understand the operational arguments. I have heard them all. But every exception is a door left open. If the access path reaches OT, it requires strong authentication. Full stop.
4. Integrate OT visibility into your SOC.
If your security operations cannot see VNC connections to your SCADA systems, you are blind to exactly the attack vector described in this advisory.
Protocol-aware monitoring is not optional for Critical National Infrastructure (CNI). You need to know what normal looks like before you can detect what is abnormal.
5. Brief your leadership in operational terms.
Do not present this as a technical briefing about hacktivists. Present it as an operational risk briefing about remote access governance.
Frame the question: “How many active remote connections to our OT environment can we verify are legitimate right now?”
If the answer is “we do not know,” that is your starting point.
The Board Question That Would Change Everything

If I could give every Critical National Infrastructure (CNI) board in the Gulf one question to ask after reading this advisory, it would be this:
What percentage of our OT assets are reachable from the internet, and who is accountable for reducing that number to zero?
Not “we believe” or “we are confident.”
A verified number. A named owner. A timeline for closure.
That single metric, tracked monthly at the board level, would do more to prevent these attacks than any technology investment I could recommend.
Because the attackers are not sophisticated. They are simply persistent against organizations that have not closed the most basic gaps.
The Uncomfortable Truth I Keep Coming Back To

The mitigations in the CISA advisory are not complex.
Reduce exposure. Implement strong authentication. Monitor remote access. Maintain asset visibility.
These have been industry consensus for over a decade. They are embedded in NCA OTCC-1. They are fundamental to IEC 62443.
The fact that a 2025 joint advisory from five agencies still needs to state them tells me that the problem is not awareness.
It is execution.
Somewhere between the policy document and the plant floor, these controls are not being enforced.
I see the same pattern repeatedly. Smart people. Good intentions. Solid policies. And a gap between what is documented and what is operational.
In the Gulf, the stakes are higher. The visibility is greater. The tolerance for disruption is lower.
The question for every Critical National Infrastructure (CNI) leader is not whether you have the right policies.
It is whether those policies survive contact with your vendors, your contractors, your commissioning timelines, and your operational pressures.
A Question for This Community
I have been having these conversations with CISOs and OT security leaders across the Gulf this week. The consistent theme is not that organizations lack policies. It is that policies are not validated under real conditions.
The organizations making progress are not the ones with the most sophisticated detection tools. They are the ones running monthly exposure audits, enforcing vendor access time limits, and testing their segmentation with adversarial assumptions.
So here is my question:
When was the last time your organization verified its OT exposure posture against the specific attack vectors in this advisory?
If the answer is “we have not,” that is not a failure. It is a starting point.
The hacktivists are scanning. The question is whether you find the gaps before they do.
I would welcome the conversation. DM me if you are working through this challenge. I am always interested in comparing notes with leaders who are taking this seriously.
The CISA advisory is available at
cisa.gov
under advisory AA25-343a. The Amazon GRU campaign findings were published December 16, 2025.