Ransomware at a Gas Compression Facility: The CISA Alert That Mapped OT Risk
On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.
