Manufacturing & Industrial Operations

The email lands at Level 4. The consequence shows up on Level 1.

Nobody phishes a PLC. They phish a buyer, a controls engineer or a maintenance planner, and the ladder logic is downstream of that. This page is about putting a list of DNS-verified, currently-live phishing hostnames where it does the most good in a plant: the mail path, the enterprise resolver, the DMZ, and the one file you can carry across an air gap without opening a hole in it.

390,000+Live phishing hostnames, each DNS-verified as resolving
04:30 UTCWhen the rebuilt database lands, ahead of first shift in most plants
One fileCSV or JSON — reviewable, hashable, transferable one-way
Sub-50msAPI response when you do query, at 10 requests per second
Procurement & AP mailboxes
IT/OT DMZ resolvers
Shared shop-floor stations
PLM and CAD repositories
Supplier and logistics portals
Integrator remote access
Home / Use Cases / Manufacturing
Initial access

Phishing is the first move in an OT incident, not an office inconvenience

Every plant-floor disruption that made the trade press started somewhere much more boring than the plant floor.

Walk the sequence backwards from any production outage caused by an intruder and the last few steps are always industrial — a domain controller in the plant DMZ, a jump host with cached credentials, an engineering workstation that had a direct path to the control network because somebody needed it to have one during commissioning and nobody revoked it afterwards. Keep walking backwards and the industrial part runs out. What you find at the origin is somebody in finance opening a remittance advice, or a controls engineer authenticating to what looked like the vendor's licence portal, or a maintenance planner clicking a tracking link for a part that genuinely was overdue.

Where the money goes

OT tooling watches the wrong end of the sequence

Plants buy passive monitors that fingerprint Modbus and EtherNet/IP traffic, unidirectional gateways and asset inventory appliances that listen rather than scan. All of it is worth having, and none of it touches the point of entry, because the point of entry was not on the control network. It sat two or three segments and one trust relationship away, in an environment that looks like any other office. Control-network tooling meets the intruder at the boundary, which is late.

The map everyone uses

Purdue makes the distance visible

Levels 0 through 2 are instruments, controllers and operator stations. Level 3 is site operations — historians, batch management, the MES. Level 3.5 is the DMZ where IT and OT meet under supervision. Levels 4 and 5 are enterprise IT and the corporate WAN. Phishing is a Level 4 and Level 5 phenomenon almost without exception, and the entire architecture of segmentation exists to keep it there.

Why the seams exist

The porosity is documented nowhere and nobody is to blame

A shared Active Directory forest. A historian replicating upward through a hole in the firewall. An engineering laptop that lives on the corporate domain during the week and gets carried down to the line on Saturday. Each of those was justified at the time by an engineer who needed a line running before the shift ended, and the accumulated residue of twenty years of those decisions is the real network, not the one on the diagram.

What a list changes

It moves the odds on the first step, not the last

A known-bad domain list does nothing about a flaw in a protocol converter and will not save a site where an adversary already has persistence. What it removes is a large, cheap, high-volume category of opening move — the commodity credential-harvesting page reached from a link — from the set of things that can succeed against your buyers, your engineers and your shift supervisors. A control network that never receives the intruder is worth considerably more than one that detects them quickly.

Segmentation is a boundary, not an immune system. Purdue Level 3.5 assumes the threat arrives at the boundary and gets stopped there. Blocking the hostname at Level 4 means it never travels far enough to test that assumption.
The engineering laptop is the seam. A machine that authenticates to the corporate domain and also carries project files onto the line is, functionally, a bridge with a person on it. Whatever protects the corporate side is protecting the control side too, whether the architecture diagram admits it or not.
Resolver enforcement is protocol-agnostic. It does not matter whether the click came from Outlook, a PDF, a QR code printed on a work order or a chat message. If the hostname does not resolve, none of those paths complete.
Plant-floor reality

What the shop floor actually is, and what that forces a control to look like

Most security products assume every device has an owner, an agent and a patch window. A plant is none of those things.

Before deciding how to deploy anything into a manufacturing environment, write down what that environment genuinely is rather than what a datasheet assumes. The left column below is what a controls engineer will tell you over coffee; the right is the constraint that falls out of it. Every row on the right is a design requirement, and any tool that cannot satisfy all six ends up deployed on the enterprise side only, with the plant network quietly dropped from scope and nobody wanting to say so out loud in the steering meeting.

What the plant floor actually is

Operator stations sit under one shared login that three shifts use and nobody rotates
Half the machines run an operating system whose vendor stopped shipping patches years ago
An agent that consumes CPU unpredictably is a genuine safety and throughput concern
Changes go through a management-of-change process with a scheduled window, not a push
Outbound internet from the control network is either absent or deliberately one-way
Integrators and OEM support staff hold access that predates the current security team

What that forces the control to look like

Enforcement must work without knowing who is at the keyboard — network layer, not identity layer
No installation on the asset itself; the control lives on the path, not on the machine
Zero runtime footprint on the station, because a resolver lookup costs it nothing at all
Updates must be schedulable, reviewable and reversible to a previous known-good file
Intelligence must arrive as data you carry in, not a service you are obliged to call out to
Protection must be independent of account hygiene, because those accounts are not yours
The shared-login problem has no identity answer. When the badge on the station reads LINE3-OP and four people use it, conditional access, risk scoring and user-behaviour analytics all degrade into noise. A destination-based block is one of the very few controls whose effectiveness does not depend on knowing who did the clicking.
Drawings and process IP

The RFQ that wants your CAD files is a lure with a business case

Engineering-focused phishing does not look like phishing. It looks like work. A request for quotation arrives from a name that sounds like a tier-one integrator, references a programme that is plausibly public, and asks the recipient to sign in to a portal to pull the drawing pack and upload a response. The recipient is an application engineer whose job is literally to answer requests like this, under a deadline, several times a week.

  • They are not careless. Engineering staff are asked, as a job function, to open unsolicited attachments and follow links from strangers.
  • The portal step is normal. Large drawing packs genuinely do sit behind logins, which is exactly why the pretext works.
  • One credential is enough. A single sign-on password opens the mailbox, the PLM and the remote-access portal together.
Anatomy of an engineering lure
The pretext: a request to quote on a sub-assembly, referencing a real programme name lifted from a press release or a careers listing.
The friction: the drawing pack is "too large for email", so it sits behind a portal login. This is the entire trick, and it is indistinguishable from normal practice.
The harvest: a cloned sign-on page for the recipient's own identity provider, not the sender's. One password, and the intruder has the mailbox, the PLM and the VPN.
The break point: the hostname behind the portal link. Verified as live phishing infrastructure, it fails to resolve and the sequence ends before the engineer reads a word of the page.

What the credential actually opens

A PLM login is not a mailbox. It is indexed access to the product structure: assembly trees, revision history, tolerances, approved supplier lists, the heat-treatment step that took four years to get right. Teamcenter, Windchill and their smaller equivalents are built to make that material easy to traverse for anyone with legitimate access — which is precisely the property an intruder inherits on arrival.

Why nobody notices for months

The theft is quiet in a way ransomware is not. No line goes down, no note appears, and the first external signal is often a competitor bidding suspiciously well on a part you thought was hard to make. That delay is why credential phishing against engineering staff is a favourite of well-resourced actors, and why it is systematically under-reported — many manufacturers never establish that it happened at all.

Blunt is fine here

A drawing-theft campaign still needs somewhere for the engineer to type the password, and that somewhere is a hostname. If it is already on the list, the sign-in page never renders and the campaign fails at its cheapest point. Pair it with the patterns on our email security and brand protection pages if the same actors are cloning your own supplier portal.

Procurement fraud

Accounts payable is where a manufacturer actually loses money

The dramatic scenario is a stopped line. The common scenario is a payment run. Manufacturers hold long, stable supplier relationships with predictable invoicing cadences, high individual invoice values, and an approval process involving several people who each assume one of the others verified something. That combination is what fraudsters mean when they talk about a good target.

  • Nothing is forged. The mature version of this attack sends from the supplier's real address, inside the real thread, quoting the real purchase order.
  • Patience is the tell. The attacker reads the correspondence for weeks before altering remittance details on an invoice that was already due.
  • Volume still favours you. Look-alike hostnames remain the majority of attempts, and those are exactly what a verified list removes.
Where the checks belong
  • The inbound mail path, before a buyer sees the link — hostnames extracted at the gateway and checked server-side
  • Supplier onboarding, at the moment a new vendor domain is entered into the ERP master record
  • The monthly vendor-master sweep, batched and logged as a control with a date attached to it
  • Your own supplier portal's submission fields, wherever an external party can paste a URL a colleague will later click
  • The enterprise resolver, so a click that got past the mail path still reaches nothing at all
Upstream

You cannot filter the fraudulent invoice, so filter what precedes it

Once a genuine supplier mailbox is under someone else's control, the resulting message is technically indistinguishable from correspondence you have received for years. The place a blocklist earns its keep is one step earlier: reducing the chance that the supplier's credentials were harvested in the first place, and catching the impatient variants that still route through a hostname one character away from the real one, or the supplier's name parked as a subdomain of something registered last week.

Cheap and repeatable

Sweep the vendor master every month

The domains you already transact with are a finite list, usually a few thousand entries pulled straight out of the ERP. Running it through the /batch endpoint, a hundred domains per request at one lookup each, tells you whether any hostname you do business with sits on a verified phishing list today. Twenty minutes, repeatable, and it occasionally produces a very awkward and very valuable phone call. The supply chain and accounting pages go further into the finance-side workflow.

The key stays on the server. Your API key is the username you chose at registration, and every integration described here is a back-end call — never a fetch from a page that reaches a browser.
What you are actually loading

A file, not a subscription to somebody else's opinion

The shape of the data matters more than the marketing around it, particularly where a security team has to defend every byte crossing a boundary.

390,000+Hostnames with a verified active A record, checked through rotating proxy infrastructure
24 hoursFull rebuild cycle, with the daily build landing at 04:30 UTC
0.98 / 0.0Confidence on a confirmed match versus no match — nothing in between to interpret
3 columnsDomain, category and DNS status in CSV, or the same fields as JSON

The verification standard is the part that matters for a plant, because it changes what the file costs you operationally. Every entry has been confirmed to resolve. Domains that stop resolving fall out of the next build rather than accumulating forever, so the list stays a picture of what is live rather than a growing archive of everything ever reported. That is the difference between a blocklist your DMZ resolver parses in a second each morning and a multi-megabyte historical dump that grows without bound and slows every lookup on the site.

The changelog is the artefact reviewers want

A daily record of domains added and removed ships alongside the feed, which lets a nightly update be expressed as a diff rather than a wholesale replacement. The change record you file then says "412 hostnames added, 380 removed" instead of "list replaced". Reviewers can read the first sentence; a full-file swap is opaque and invites the entirely reasonable objection that nobody knows what changed.

No thresholds means no arguments

Confidence is 0.98 for a confirmed match and 0.0 for no match, with nothing between them. There is no scoring model to explain to an auditor and no debate about where the line should sit. For a plant security team obliged to justify every automated action to an operations manager, a control with no tuning knobs is a feature rather than a shortcoming.

The response contract is deliberately flat

is_phishing is a boolean. category reads phishing/malware. dns_status reads resolves. last_checked carries a date. Four fields, no interpretation required, and nothing that changes shape between releases in a way that breaks a script somebody wrote two years ago and has not looked at since.

BIND RPZ Firewall external list DMZ resolver Mail gateway SIEM enrichment One-way transfer
Change control

Deploying it the way a plant actually accepts changes

Four steps, each of which fits inside a normal management-of-change conversation, and none of which requires downtime on a production asset.

1

Prove the data on the enterprise side

Start at Level 4, where change is cheap. The /stats endpoint needs no key, no credits and no authentication, so you can confirm database size and last update before anyone drafts a change request, then test hostnames from your own quarantine.

2

Run it in log-only for a cycle

Load the list into the enterprise resolver with matches logged rather than blocked. One full production cycle gives you a hit count from your own estate, which carries an MOC review far better than any vendor claim.

3

Script the pull, validation and rollback

A scheduled job after 04:30 UTC, a sanity check on record count and file integrity before promotion, the previous file retained, and a one-line rollback. Alert if the file is more than 48 hours old — a silently stale list is the realistic failure mode.

4

Carry it inward during a window

Only now does anything touch Level 3.5, and it goes in as a scheduled change like any other: file moved through the approved path, hash recorded, resolver reloaded, verification test run, change closed with evidence attached.

Step two is the one people skip. A fortnight of log-only operation converts the proposal from "the vendor says this is useful" into "we observed sixty-one attempted resolutions across our own sites last month", and only the second sentence survives a capital review.
Shape of the deployment

Why a downloaded file beats a cloud verdict service in a plant

Both models answer the same question. Only one survives an air gap, a WAN outage, a change-control board and a site that lost its uplink at three in the morning.

Question an OT security lead will askPer-query cloud lookupLocal daily file
Works on a network with no outbound internet? No — the model requires the call to leave Yes — matching runs against a local copy
Survives a WAN failure at a remote site? Fails open or fails closed; both are bad at 03:00 Unaffected — yesterday's file is still enforcing
Can the change be reviewed before it takes effect? The verdict logic changes without your knowledge The file is inspectable, hashable and diffable
Can it be transferred one-way across a diode? No — it is a request and response protocol Yes — it is a file with a checksum
Does it reveal which hostnames your sites resolve? Every query is a data point held elsewhere Nothing about a lookup leaves the site
Latency added to a resolution on the plant network Internet round trip plus provider processing A local set-membership test
Cost shape as sites and devices multiplyScales with query volumeFlat — feed downloads are unlimited on a subscription
Where it genuinely winsAd-hoc checks, enrichment, one-off investigationStanding enforcement everywhere traffic resolves
Standing enforcement

The feed, for everywhere traffic resolves

The Daily Threat Feed runs at $499 per month, with downloads unlimited so the cost does not move when you add a plant. Take it annually and it also folds in historical archive access, priority support, custom format options, a dedicated account manager and 100,000 API credits — which then covers the API-shaped work such as vendor-master sweeps and one-off hostname checks without a second purchase order.

Occasional checking

Credits, for the jobs that run monthly

If the API side is all you need, plans are monthly subscriptions via PayPal and billed monthly, from Growth at $99/month for 25,000 lookups up through Professional at $249/month for 100,000 lookupsand $999 for 750,000. Bank transfer opens above $4,000, which matters where purchasing runs on requisitions rather than cards. Groups needing SFTP or S3 delivery, STIX/TAXII into a SOC platform, a custom update frequency, an SLA or a genuinely on-premise deployment are quoted individually.

The people you do not employ

Integrators, OEM support and the accounts nobody owns

The largest population with access to a plant network is usually not on the plant's payroll, and their security posture is inherited rather than chosen.

Every production line arrives with people attached. The system integrator who commissioned the cell keeps a remote-access path because the support contract says they do. The robot OEM has a diagnostic tunnel. The vision-system vendor has a laptop that comes on site twice a year and connects to whatever it needs to. The building-management contractor holds credentials to something that shares a VLAN with something else for reasons lost to history. Collectively these parties hold more standing access to the plant network than the plant's own IT department, and every one of them is an organisation whose mailbox hygiene you cannot inspect, audit or improve.

Why identity controls stall here

You will not get multi-factor authentication rolled out across four integrators, two OEMs and a contractor still using a shared engineering account, because you do not employ any of them and the commercial leverage to force it does not exist below a certain contract size. Blocking the destination works anyway, on your side of the relationship, without anybody's consent or cooperation.

The supervisor terminal beside line three

No per-user identity, no realistic patch cadence, and a browser that exists because somebody needs to look up a part number. It is not a candidate for conditional access, device-compliance policy or an endpoint agent, and pretending otherwise produces a compliance document rather than a control. It is, however, sitting behind a resolver — and a resolver does not need to know who is logged in.

Where the value actually is

Commodity kits, reused templates and hostnames rotating through a campaign that also hit four hundred other companies this week — that is the traffic reaching your buyers and your maintenance planners. Removing it lets your people and your monitoring concentrate on the small remainder genuinely aimed at you, alongside the practices on our endpoint protection, incident response and DNS filtering pages.

The limit, stated before you find it yourself

This is a known-bad lookup, and the asymmetry in it matters: a hit is a fact, whereas a miss is only the absence of a fact. Nothing in a clean response asserts that the destination is harmless. A hostname registered before breakfast and pointed at one buyer by lunchtime will not be in the file yet, which is exactly the profile of a campaign assembled for one recipient at one company. Against a patient adversary who builds infrastructure for you specifically and burns it after a single use, a record of what everybody else has already been hit with contributes very little — and any plant security team should hear that from a supplier rather than discover it in week three.

Ask for the access list before you ask for a budget. Most plants cannot produce a current inventory of third parties with network access. Producing one is free, takes about a week, and usually reframes the security conversation more effectively than any product evaluation.
Batch rather than loop. A hundred domains per /batch request at one lookup each is far kinder to the ten-requests-per-second limit than a hundred single calls, and the response returns checked, phishing_found and credits_used so a scheduled job can log one line and move on.
From the change review

What plant managers and OT leads ask before they sign anything

These are the objections that come up in the room, including the ones that are uncomfortable to answer honestly.

Does anything have to be installed on a PLC, an operator station or a historian?

No, and nothing should be. The enforcement point is a resolver or firewall the traffic already passes through — the enterprise resolver at Level 4, the DMZ resolver at Level 3.5, or an external dynamic list on the perimeter firewall — so the control assets themselves are untouched: no agent, no configuration change, no restart, nothing that would require re-validation of a safety function. That is deliberate rather than a limitation, because any product requiring software on a controller or an operator station is asking a plant to accept a risk that outweighs the threat it addresses, and a competent controls engineer will say so in the first meeting.

Our control network has no internet access at all. Can we still use this?

Yes, and it is one of the reasons the feed exists in file form: the download is a single authenticated call made from a host that does have connectivity, typically on the enterprise side, and what you then move inward is a CSV or JSON file with a known size, a hash you generated yourself and content you can read in a text editor. That is a shape one-way transfer paths and data diodes are designed for, unlike a request-and-response API which fundamentally cannot cross an air gap in any configuration. If the transfer is manual and happens weekly rather than nightly, that is still a working deployment — the coverage is simply a few days behind rather than a few hours, which is a known degradation rather than a failure.

What happens if this blocks a supplier portal or a licence server we need?

Plan for it in advance rather than treating it as an incident: maintain a local allow-list your reload script applies after each import so an exception survives the next update, and log matches for a full cycle before switching to blocking so a collision surfaces during observation rather than during a production run. Because inclusion requires verified active DNS resolution plus confirmation as phishing infrastructure, false positives are uncommon — but no list is perfect, and in a plant the correction path matters more than the error rate, so make sure whoever is on shift at two in the morning can add an exception without raising a change request first.

Would this have stopped the campaign that hit a manufacturer we read about?

Quite possibly not, and letting that question hang would be worse than answering it: a hostname stood up for one manufacturer and burned after a single use has never been seen by anybody, so it appears on no blocklist anywhere, this one included. Verification is retrospective by construction — something has to be observed resolving before it can be published as hostile. Where this earns its keep is the large commodity layer sitting beneath every headline case: reused kits, rotating infrastructure, the campaign that also swept hundreds of other firms the same week. That layer is what actually lands in your buyers' mailboxes in volume, and taking it off the table is what frees scarce attention for the handful of attempts that are genuinely about you.

We already have an email security platform. What does this add?

Two things: first, it is a different data source built with a different collection method, and layered detection works because independent sources fail independently, so a hostname your gateway has not classified may already be verified here and the reverse is equally true. Second, and more importantly for a plant, it enforces somewhere your mail platform cannot reach — mail security stops at the mailbox, and it does nothing about a QR code printed on a work order, a link in a chat message from a compromised integrator, a shortcut saved on a shared station, or a browser session on a machine that has never been enrolled in anything. Blocking at the resolver covers all of those with a single control.

How do we prove to an auditor that this is operating?

The evidence trail is ordinary, and that is a virtue: you have a scheduled job with a run history, a downloaded file carrying a date and a hash, a record count you can compare against the /stats endpoint for the same day, a change record for each promotion, and resolver logs showing matched queries. For an IEC 62443 zone-and-conduit argument or an ISO 27001 control set, that maps onto the boundary-protection and malicious-code controls without much creative writing, and the daily changelog helps further because it lets you demonstrate what specifically changed on a given date rather than asserting that an update occurred at some point.

Is the list big enough to be worth the operational effort?

The relevant number is not how many domains have ever been reported but how many are live right now, and that is over 390,000, each verified as holding an active A record through rotating proxy infrastructure, with entries that stop resolving dropping out at the next 24-hour rebuild rather than accumulating — so the file stays a working set instead of an archive that grows until somebody has to deal with it. Operationally the effort is a scheduled download, a validation check and a resolver reload, genuinely an afternoon for whoever already maintains that infrastructure, and thereafter it is one of the very few security controls that runs without asking anybody for anything.

We run a single small plant with two IT people. Is this proportionate?

For a single site the credit route is often the honest answer rather than the feed, because a monthly vendor-master sweep plus ad-hoc checks against links in suspicious mail will not consume 10,000 lookups quickly and the $59 package is frequently a multi-year supply at that rate. If you already run your own resolver, the feed becomes worthwhile the moment you want standing enforcement across the whole site rather than periodic checks, and multi-site groups tend to hold one feed subscription centrally and distribute the file to plants — which is also the cleanest answer for sites with no security staff at all. The daily feed and pricing pages set out the delivery options.

Stop the campaign at Level 4, before it becomes an OT incident

Confirm the database size through the open statistics endpoint, run the list in log-only mode for one production cycle, and take your own hit count to the change review. If standing enforcement across every plant is the goal, the daily feed is the deployment that works with an air gap rather than against it.