Desk live·
ForensicPost
Ransomware/Manufacturing/File 25-0505

A Steel Producer Stopped Its Own Furnaces

A large North American steel producer halted production in May 2025 after detecting unauthorised access. In heavy industry, stopping is not a neutral act.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNorth American steel producer
ActorUnattributed
D. Kennedy10 min readConfidence: medium2 sources reviewed

A large North American steel producer halted production in May 2025 after detecting unauthorised access to its systems.

Stopping A Steel Plant Costs Something To Do

For most organisations in this database, taking systems offline is disruptive but reversible: a website goes down and comes back, an office works on paper for a week.

Heavy industry does not offer that. Furnaces, continuous casters and rolling mills have physical states that are expensive to leave and expensive to re-enter. A controlled shutdown consumes energy, generates scrap and takes time; an uncontrolled one can damage equipment. The decision to stop is measured in real money before any attacker has done anything.

Which makes the choice informative. A producer that stopped had concluded that the risk of continuing exceeded a cost it could calculate precisely — and, notably, chose to stop on detection rather than on confirmed impact.

The IT And OT Boundary Again

The recurring question in industrial incidents is whether the intrusion reached process control or stopped at the business network. Organisations frequently halt production as a precaution when they cannot yet answer it — a rational response to uncertainty about a system where the failure mode is physical.

The material we reviewed does not establish which happened here. That uncertainty is itself the finding, and it is the same one filed at 26-0318 and 26-0729: the boundary is asserted in architecture diagrams more often than it is demonstrated under investigation.

How we reported this

Compiled from published sector analysis, listed below, which describes the incident without naming the producer. We do not name it. Whether process control was affected is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware in manufacturing 2025: data security and compliance crisisKiteworks
  2. Dragos industrial ransomware analysis: Q3 2025Dragos
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary