SCADA & IoT
~/ › SCADA & IoT › article
#OpUSA: Z-Pentest Alliance Claims Breach of Nokota Gas Processing Facility in North Dakota
> By Haider | Aug 04, 2026 | 4 min read
⚠️ THREAT INTELLIGENCE ADVISORY:
Pro-Russian hacktivist collective Z-Pentest Alliance has announced a critical breach of industrial infrastructure in the United States. Operating under the #OpUSA campaign banner, the group claims to have compromised the operational technology (OT) systems of Nokota Gas Processing, a facility located in North Dakota.

> TABLE_OF_CONTENTS [toggle]
System Compromise and Manipulation
According to the threat actors’ dispatch, they successfully infiltrated the facility’s supervisory control and data acquisition (SCADA) systems. The attackers stated they switched the JT-bypass controller into manual mode and forced the output to 100 percent. They claim to have gained full visibility and control over critical telemetry, including temperatures, flow rates, and valve operations.
Alarmingly, the attackers claim to have enabled fire and gas protection bypasses. They specifically noted that “gas analyzers no longer decide anything”, indicating a severe compromise of the facility’s automated safety logic.
Forced Failures and Emergency States
The hacktivist group detailed specific mechanical overrides executed during the breach. They forced multiple Emergency Shutdown Valves (ESDV) into a “Fail Open” state. These valves include the Inlet, Scavenger Tower, Condy, K200, and Bullets systems.
In addition, the attackers claim to have thrown Compressor K-200 into an emergency state while maintaining full control over its start status and associated sensors. As a result of these manipulations, the facility’s system was reportedly flooded with emergency alarms and messages, rendering automated protection systems practically disabled.
The group also escalated their access by adding their own contact address to the corporate directory, positioning themselves alongside legitimate operators and engineers.
Implications for Critical Infrastructure
This incident highlights the escalating threat of ideologically motivated attacks against critical national infrastructure (CNI). The ability to remotely manipulate physical gas processing valves and bypass safety systems poses a severe physical safety risk. Industrial operators are strongly urged to immediately segment OT networks from the public internet, audit all remote access points, and enforce strict multi-factor authentication (MFA) across all administrative interfaces.
Strategic Threat Landscape & Operational Technology (OT) Vulnerabilities
The escalation of this specific cyber incident reflects a broader, systemic shift in the global threat landscape regarding the targeting of Operational Technology (OT) and critical infrastructure. Threat intelligence analysts continuously observe that the tactics, techniques, and procedures (TTPs) deployed here represent a severe escalation in cyber-physical risks.
In recent months, the rapid digitization of industrial environments—often referred to as Industry 4.0—has inadvertently expanded the attack surface of once-isolated SCADA systems and Industrial Control Systems (ICS). The convergence of IT and OT networks has allowed threat actors to pivot from compromised corporate environments directly into environments controlling physical processes, power grids, and manufacturing lines.
Furthermore, the exploitation of unpatched IoT devices, exposed HMIs (Human-Machine Interfaces), and legacy protocols lacking native encryption has become a preferred vector for both financially motivated syndicates and state-aligned disruption teams. These intrusions are often designed to inflict maximum operational downtime and societal impact.
Defensive Evolution & The Purdue Enterprise Reference Architecture
From a defensive standpoint, applying traditional IT security models to OT environments is fundamentally flawed. Organizations must urgently adopt and strictly enforce the Purdue Enterprise Reference Architecture (PERA), ensuring rigorous network segmentation and the implementation of industrial DMZs.
To combat this evolving threat matrix, the deployment of passive, ICS-specific Deep Packet Inspection (DPI) is critical for identifying anomalous lateral movement without disrupting fragile legacy equipment. Proactive threat hunting, continuous vulnerability management, and strict access controls are the most effective strategies for maintaining organizational resilience against cyber-physical adversaries.
Get CyberAsia threat intelligence updates by email. Unsubscribe anytime. Privacy Policy.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
>
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing #OpUSA: Z-Pentest Alliance Claims Breach of Nokota Gas Processing Facility in North Dakota is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
SCADA & IoT
SCADA & IoT
BMS Cyberattack: Disrupt0r Hacks Quinquela Plaza SCADA
> read
SCADA & IoT