Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In April 2019, FireEye Mandiant reported finding Triton/Trisis attack tools at a second industrial organization. The attackers had entered the organization’s corporate IT network and were conducting reconnaissance while moving toward its operational technology (OT) network. The report did not establish that they reached the OT network or compromised a safety system, and the victim’s identity and location were not disclosed.
What Mandiant reported about the second victim
Dark Reading reported on April 11, 2019, that Mandiant found custom Triton/Trisis tools while investigating an industrial organization. Mandiant described the investigation as ongoing. Its account placed the attackers in the victim’s corporate IT environment, conducting reconnaissance and advancing toward OT—not confirmed inside the victim’s safety system. Dark Reading’s report did not name the organization or give its location.
Mandiant’s Nathan Brubaker said tool overlap led the company to have “very high confidence” that the activity involved the same actor as the earlier Triton incident. That is Mandiant’s assessment as reported by Dark Reading, not an independent attribution finding. The same article reported that Brubaker declined to say whether the second organization’s safety instrumentation system had been infected.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why “another victim” does not mean a second confirmed SIS attack
The stages of an industrial intrusion matter. Access to corporate IT is not the same as access to OT; movement toward OT is not proof of entry; and access to an industrial network or engineering workstation would not, by itself, establish that safety controllers were compromised. For the second organization, the report supports corporate-network access and movement toward OT. It does not confirm the later steps or an SIS compromise.
#1 Best Overall
This distinction is consequential because Triton was designed to interact with safety systems. The 2017 incident involved Schneider Electric Triconex safety controllers. CISA’s March 24, 2022 advisory describes Triton’s capability to manipulate those controllers and explains that safety systems monitor industrial processes to help prevent hazardous conditions. Interference with safety functions could disable or alter them. The advisory explains the potential significance of the malware; it does not establish what happened at the unnamed 2019 victim.
What other reporting adds—and does not add
Dragos described early-stage activity involving roughly 12 companies across sectors including oil and gas, industrial control system vendors, and manufacturers. That figure refers to observed actor activity and targeting, not 12 confirmed Triton infections. Dragos distinguishes that activity from confirmed deployment of disruptive malware in its XENOTIME profile. Its observations provide context for the breadth of interest, but they should not be added to a tally of successful Triton attacks.
Rank #2
Later government accounts concern other incidents. In a March 24, 2022 statement, the FBI described allegations that Russian researcher Evgeny Gladkikh used Triton against a foreign natural gas refinery and later made unsuccessful attempts to target similar U.S. facilities. Those allegations are not findings about the unnamed second organization in the 2019 report. The FBI statement and the Treasury announcement provide separate legal and historical context, not confirmation of the second victim’s identity or outcome.
What is established about the incident
- Mandiant reported Triton/Trisis tools at a second industrial organization in April 2019.
- The reported foothold was in corporate IT, with reconnaissance and movement toward OT.
- The organization was not identified, and its location was not disclosed.
- The report did not confirm that its safety instrumented system (SIS) was infected.
- Mandiant’s same-actor assessment was based on tool overlap as described in the reporting.
- Wider observations of actor activity and targeting are not a count of successful Triton deployments.
Technical context: Triton and safety controllers
MITRE ATT&CK describes Triton as an attack framework built to interact with Triconex SIS controllers. Its profile includes changing a controller’s operating mode and identifies TriStation’s default UDP port 1502. These technical details help explain why investigators distinguish ordinary corporate-network access from access to safety control equipment; they do not prove that the second organization’s controllers were reached. See MITRE ATT&CK’s Triton profile, last modified May 12, 2026.
For defenders, the incident illustrates why an investigation should track each boundary crossing separately: corporate IT, OT, engineering workstations, and safety controllers. CISA’s 2022 advisory contains mitigations for the historical threat, but operational controls should be checked against current vendor guidance and the facility’s own safety and security requirements rather than treated as a universal configuration checklist.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

