Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In April 2019, FireEye Mandiant reported finding Triton/Trisis attack tools at a second industrial organization. The attackers had entered the organization’s corporate IT network and were conducting reconnaissance while moving toward its operational technology (OT) network. The report did not establish that they reached the OT network or compromised a safety system, and the victim’s identity and location were not disclosed.

What Mandiant reported about the second victim

Dark Reading reported on April 11, 2019, that Mandiant found custom Triton/Trisis tools while investigating an industrial organization. Mandiant described the investigation as ongoing. Its account placed the attackers in the victim’s corporate IT environment, conducting reconnaissance and advancing toward OT—not confirmed inside the victim’s safety system. Dark Reading’s report did not name the organization or give its location.

Mandiant’s Nathan Brubaker said tool overlap led the company to have “very high confidence” that the activity involved the same actor as the earlier Triton incident. That is Mandiant’s assessment as reported by Dark Reading, not an independent attribution finding. The same article reported that Brubaker declined to say whether the second organization’s safety instrumentation system had been infected.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why “another victim” does not mean a second confirmed SIS attack

The stages of an industrial intrusion matter. Access to corporate IT is not the same as access to OT; movement toward OT is not proof of entry; and access to an industrial network or engineering workstation would not, by itself, establish that safety controllers were compromised. For the second organization, the report supports corporate-network access and movement toward OT. It does not confirm the later steps or an SIS compromise.

This distinction is consequential because Triton was designed to interact with safety systems. The 2017 incident involved Schneider Electric Triconex safety controllers. CISA’s March 24, 2022 advisory describes Triton’s capability to manipulate those controllers and explains that safety systems monitor industrial processes to help prevent hazardous conditions. Interference with safety functions could disable or alter them. The advisory explains the potential significance of the malware; it does not establish what happened at the unnamed 2019 victim.

What other reporting adds—and does not add

Dragos described early-stage activity involving roughly 12 companies across sectors including oil and gas, industrial control system vendors, and manufacturers. That figure refers to observed actor activity and targeting, not 12 confirmed Triton infections. Dragos distinguishes that activity from confirmed deployment of disruptive malware in its XENOTIME profile. Its observations provide context for the breadth of interest, but they should not be added to a tally of successful Triton attacks.

Later government accounts concern other incidents. In a March 24, 2022 statement, the FBI described allegations that Russian researcher Evgeny Gladkikh used Triton against a foreign natural gas refinery and later made unsuccessful attempts to target similar U.S. facilities. Those allegations are not findings about the unnamed second organization in the 2019 report. The FBI statement and the Treasury announcement provide separate legal and historical context, not confirmation of the second victim’s identity or outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is established about the incident

  • Mandiant reported Triton/Trisis tools at a second industrial organization in April 2019.
  • The reported foothold was in corporate IT, with reconnaissance and movement toward OT.
  • The organization was not identified, and its location was not disclosed.
  • The report did not confirm that its safety instrumented system (SIS) was infected.
  • Mandiant’s same-actor assessment was based on tool overlap as described in the reporting.
  • Wider observations of actor activity and targeting are not a count of successful Triton deployments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Technical context: Triton and safety controllers

MITRE ATT&CK describes Triton as an attack framework built to interact with Triconex SIS controllers. Its profile includes changing a controller’s operating mode and identifies TriStation’s default UDP port 1502. These technical details help explain why investigators distinguish ordinary corporate-network access from access to safety control equipment; they do not prove that the second organization’s controllers were reached. See MITRE ATT&CK’s Triton profile, last modified May 12, 2026.

For defenders, the incident illustrates why an investigation should track each boundary crossing separately: corporate IT, OT, engineering workstations, and safety controllers. CISA’s 2022 advisory contains mitigations for the historical threat, but operational controls should be checked against current vendor guidance and the facility’s own safety and security requirements rather than treated as a universal configuration checklist.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.