Nobody phishes a PLC. They phish a buyer, a controls engineer or a maintenance planner, and the ladder logic is downstream of that. This page is about putting a list of DNS-verified, currently-live phishing hostnames where it does the most good in a plant: the mail path, the enterprise resolver, the DMZ, and the one file you can carry across an air gap without opening a hole in it.
Every plant-floor disruption that made the trade press started somewhere much more boring than the plant floor.
Walk the sequence backwards from any production outage caused by an intruder and the last few steps are always industrial — a domain controller in the plant DMZ, a jump host with cached credentials, an engineering workstation that had a direct path to the control network because somebody needed it to have one during commissioning and nobody revoked it afterwards. Keep walking backwards and the industrial part runs out. What you find at the origin is somebody in finance opening a remittance advice, or a controls engineer authenticating to what looked like the vendor's licence portal, or a maintenance planner clicking a tracking link for a part that genuinely was overdue.
Plants buy passive monitors that fingerprint Modbus and EtherNet/IP traffic, unidirectional gateways and asset inventory appliances that listen rather than scan. All of it is worth having, and none of it touches the point of entry, because the point of entry was not on the control network. It sat two or three segments and one trust relationship away, in an environment that looks like any other office. Control-network tooling meets the intruder at the boundary, which is late.
Levels 0 through 2 are instruments, controllers and operator stations. Level 3 is site operations — historians, batch management, the MES. Level 3.5 is the DMZ where IT and OT meet under supervision. Levels 4 and 5 are enterprise IT and the corporate WAN. Phishing is a Level 4 and Level 5 phenomenon almost without exception, and the entire architecture of segmentation exists to keep it there.
A shared Active Directory forest. A historian replicating upward through a hole in the firewall. An engineering laptop that lives on the corporate domain during the week and gets carried down to the line on Saturday. Each of those was justified at the time by an engineer who needed a line running before the shift ended, and the accumulated residue of twenty years of those decisions is the real network, not the one on the diagram.
A known-bad domain list does nothing about a flaw in a protocol converter and will not save a site where an adversary already has persistence. What it removes is a large, cheap, high-volume category of opening move — the commodity credential-harvesting page reached from a link — from the set of things that can succeed against your buyers, your engineers and your shift supervisors. A control network that never receives the intruder is worth considerably more than one that detects them quickly.
Most security products assume every device has an owner, an agent and a patch window. A plant is none of those things.
Before deciding how to deploy anything into a manufacturing environment, write down what that environment genuinely is rather than what a datasheet assumes. The left column below is what a controls engineer will tell you over coffee; the right is the constraint that falls out of it. Every row on the right is a design requirement, and any tool that cannot satisfy all six ends up deployed on the enterprise side only, with the plant network quietly dropped from scope and nobody wanting to say so out loud in the steering meeting.
LINE3-OP and four people use it, conditional access, risk scoring and user-behaviour analytics all degrade into noise. A destination-based block is one of the very few controls whose effectiveness does not depend on knowing who did the clicking.Engineering-focused phishing does not look like phishing. It looks like work. A request for quotation arrives from a name that sounds like a tier-one integrator, references a programme that is plausibly public, and asks the recipient to sign in to a portal to pull the drawing pack and upload a response. The recipient is an application engineer whose job is literally to answer requests like this, under a deadline, several times a week.
A PLM login is not a mailbox. It is indexed access to the product structure: assembly trees, revision history, tolerances, approved supplier lists, the heat-treatment step that took four years to get right. Teamcenter, Windchill and their smaller equivalents are built to make that material easy to traverse for anyone with legitimate access — which is precisely the property an intruder inherits on arrival.
The theft is quiet in a way ransomware is not. No line goes down, no note appears, and the first external signal is often a competitor bidding suspiciously well on a part you thought was hard to make. That delay is why credential phishing against engineering staff is a favourite of well-resourced actors, and why it is systematically under-reported — many manufacturers never establish that it happened at all.
A drawing-theft campaign still needs somewhere for the engineer to type the password, and that somewhere is a hostname. If it is already on the list, the sign-in page never renders and the campaign fails at its cheapest point. Pair it with the patterns on our email security and brand protection pages if the same actors are cloning your own supplier portal.
The dramatic scenario is a stopped line. The common scenario is a payment run. Manufacturers hold long, stable supplier relationships with predictable invoicing cadences, high individual invoice values, and an approval process involving several people who each assume one of the others verified something. That combination is what fraudsters mean when they talk about a good target.
Once a genuine supplier mailbox is under someone else's control, the resulting message is technically indistinguishable from correspondence you have received for years. The place a blocklist earns its keep is one step earlier: reducing the chance that the supplier's credentials were harvested in the first place, and catching the impatient variants that still route through a hostname one character away from the real one, or the supplier's name parked as a subdomain of something registered last week.
The domains you already transact with are a finite list, usually a few thousand entries pulled straight out of the ERP. Running it through the /batch endpoint, a hundred domains per request at one lookup each, tells you whether any hostname you do business with sits on a verified phishing list today. Twenty minutes, repeatable, and it occasionally produces a very awkward and very valuable phone call. The supply chain and accounting pages go further into the finance-side workflow.
The shape of the data matters more than the marketing around it, particularly where a security team has to defend every byte crossing a boundary.
The verification standard is the part that matters for a plant, because it changes what the file costs you operationally. Every entry has been confirmed to resolve. Domains that stop resolving fall out of the next build rather than accumulating forever, so the list stays a picture of what is live rather than a growing archive of everything ever reported. That is the difference between a blocklist your DMZ resolver parses in a second each morning and a multi-megabyte historical dump that grows without bound and slows every lookup on the site.
A daily record of domains added and removed ships alongside the feed, which lets a nightly update be expressed as a diff rather than a wholesale replacement. The change record you file then says "412 hostnames added, 380 removed" instead of "list replaced". Reviewers can read the first sentence; a full-file swap is opaque and invites the entirely reasonable objection that nobody knows what changed.
Confidence is 0.98 for a confirmed match and 0.0 for no match, with nothing between them. There is no scoring model to explain to an auditor and no debate about where the line should sit. For a plant security team obliged to justify every automated action to an operations manager, a control with no tuning knobs is a feature rather than a shortcoming.
is_phishing is a boolean. category reads phishing/malware. dns_status reads resolves. last_checked carries a date. Four fields, no interpretation required, and nothing that changes shape between releases in a way that breaks a script somebody wrote two years ago and has not looked at since.
Four steps, each of which fits inside a normal management-of-change conversation, and none of which requires downtime on a production asset.
Start at Level 4, where change is cheap. The /stats endpoint needs no key, no credits and no authentication, so you can confirm database size and last update before anyone drafts a change request, then test hostnames from your own quarantine.
Load the list into the enterprise resolver with matches logged rather than blocked. One full production cycle gives you a hit count from your own estate, which carries an MOC review far better than any vendor claim.
A scheduled job after 04:30 UTC, a sanity check on record count and file integrity before promotion, the previous file retained, and a one-line rollback. Alert if the file is more than 48 hours old — a silently stale list is the realistic failure mode.
Only now does anything touch Level 3.5, and it goes in as a scheduled change like any other: file moved through the approved path, hash recorded, resolver reloaded, verification test run, change closed with evidence attached.
Both models answer the same question. Only one survives an air gap, a WAN outage, a change-control board and a site that lost its uplink at three in the morning.
| Question an OT security lead will ask | Per-query cloud lookup | Local daily file |
|---|---|---|
| Works on a network with no outbound internet? | No — the model requires the call to leave | Yes — matching runs against a local copy |
| Survives a WAN failure at a remote site? | Fails open or fails closed; both are bad at 03:00 | Unaffected — yesterday's file is still enforcing |
| Can the change be reviewed before it takes effect? | The verdict logic changes without your knowledge | The file is inspectable, hashable and diffable |
| Can it be transferred one-way across a diode? | No — it is a request and response protocol | Yes — it is a file with a checksum |
| Does it reveal which hostnames your sites resolve? | Every query is a data point held elsewhere | Nothing about a lookup leaves the site |
| Latency added to a resolution on the plant network | Internet round trip plus provider processing | A local set-membership test |
| Cost shape as sites and devices multiply | Scales with query volume | Flat — feed downloads are unlimited on a subscription |
| Where it genuinely wins | Ad-hoc checks, enrichment, one-off investigation | Standing enforcement everywhere traffic resolves |
The Daily Threat Feed runs at $499 per month, with downloads unlimited so the cost does not move when you add a plant. Take it annually and it also folds in historical archive access, priority support, custom format options, a dedicated account manager and 100,000 API credits — which then covers the API-shaped work such as vendor-master sweeps and one-off hostname checks without a second purchase order.
If the API side is all you need, plans are monthly subscriptions via PayPal and billed monthly, from Growth at $99/month for 25,000 lookups up through Professional at $249/month for 100,000 lookupsand $999 for 750,000. Bank transfer opens above $4,000, which matters where purchasing runs on requisitions rather than cards. Groups needing SFTP or S3 delivery, STIX/TAXII into a SOC platform, a custom update frequency, an SLA or a genuinely on-premise deployment are quoted individually.
The largest population with access to a plant network is usually not on the plant's payroll, and their security posture is inherited rather than chosen.
Every production line arrives with people attached. The system integrator who commissioned the cell keeps a remote-access path because the support contract says they do. The robot OEM has a diagnostic tunnel. The vision-system vendor has a laptop that comes on site twice a year and connects to whatever it needs to. The building-management contractor holds credentials to something that shares a VLAN with something else for reasons lost to history. Collectively these parties hold more standing access to the plant network than the plant's own IT department, and every one of them is an organisation whose mailbox hygiene you cannot inspect, audit or improve.
You will not get multi-factor authentication rolled out across four integrators, two OEMs and a contractor still using a shared engineering account, because you do not employ any of them and the commercial leverage to force it does not exist below a certain contract size. Blocking the destination works anyway, on your side of the relationship, without anybody's consent or cooperation.
No per-user identity, no realistic patch cadence, and a browser that exists because somebody needs to look up a part number. It is not a candidate for conditional access, device-compliance policy or an endpoint agent, and pretending otherwise produces a compliance document rather than a control. It is, however, sitting behind a resolver — and a resolver does not need to know who is logged in.
Commodity kits, reused templates and hostnames rotating through a campaign that also hit four hundred other companies this week — that is the traffic reaching your buyers and your maintenance planners. Removing it lets your people and your monitoring concentrate on the small remainder genuinely aimed at you, alongside the practices on our endpoint protection, incident response and DNS filtering pages.
This is a known-bad lookup, and the asymmetry in it matters: a hit is a fact, whereas a miss is only the absence of a fact. Nothing in a clean response asserts that the destination is harmless. A hostname registered before breakfast and pointed at one buyer by lunchtime will not be in the file yet, which is exactly the profile of a campaign assembled for one recipient at one company. Against a patient adversary who builds infrastructure for you specifically and burns it after a single use, a record of what everybody else has already been hit with contributes very little — and any plant security team should hear that from a supplier rather than discover it in week three.
/batch request at one lookup each is far kinder to the ten-requests-per-second limit than a hundred single calls, and the response returns checked, phishing_found and credits_used so a scheduled job can log one line and move on.These are the objections that come up in the room, including the ones that are uncomfortable to answer honestly.
No, and nothing should be. The enforcement point is a resolver or firewall the traffic already passes through — the enterprise resolver at Level 4, the DMZ resolver at Level 3.5, or an external dynamic list on the perimeter firewall — so the control assets themselves are untouched: no agent, no configuration change, no restart, nothing that would require re-validation of a safety function. That is deliberate rather than a limitation, because any product requiring software on a controller or an operator station is asking a plant to accept a risk that outweighs the threat it addresses, and a competent controls engineer will say so in the first meeting.
Yes, and it is one of the reasons the feed exists in file form: the download is a single authenticated call made from a host that does have connectivity, typically on the enterprise side, and what you then move inward is a CSV or JSON file with a known size, a hash you generated yourself and content you can read in a text editor. That is a shape one-way transfer paths and data diodes are designed for, unlike a request-and-response API which fundamentally cannot cross an air gap in any configuration. If the transfer is manual and happens weekly rather than nightly, that is still a working deployment — the coverage is simply a few days behind rather than a few hours, which is a known degradation rather than a failure.
Plan for it in advance rather than treating it as an incident: maintain a local allow-list your reload script applies after each import so an exception survives the next update, and log matches for a full cycle before switching to blocking so a collision surfaces during observation rather than during a production run. Because inclusion requires verified active DNS resolution plus confirmation as phishing infrastructure, false positives are uncommon — but no list is perfect, and in a plant the correction path matters more than the error rate, so make sure whoever is on shift at two in the morning can add an exception without raising a change request first.
Quite possibly not, and letting that question hang would be worse than answering it: a hostname stood up for one manufacturer and burned after a single use has never been seen by anybody, so it appears on no blocklist anywhere, this one included. Verification is retrospective by construction — something has to be observed resolving before it can be published as hostile. Where this earns its keep is the large commodity layer sitting beneath every headline case: reused kits, rotating infrastructure, the campaign that also swept hundreds of other firms the same week. That layer is what actually lands in your buyers' mailboxes in volume, and taking it off the table is what frees scarce attention for the handful of attempts that are genuinely about you.
Two things: first, it is a different data source built with a different collection method, and layered detection works because independent sources fail independently, so a hostname your gateway has not classified may already be verified here and the reverse is equally true. Second, and more importantly for a plant, it enforces somewhere your mail platform cannot reach — mail security stops at the mailbox, and it does nothing about a QR code printed on a work order, a link in a chat message from a compromised integrator, a shortcut saved on a shared station, or a browser session on a machine that has never been enrolled in anything. Blocking at the resolver covers all of those with a single control.
The evidence trail is ordinary, and that is a virtue: you have a scheduled job with a run history, a downloaded file carrying a date and a hash, a record count you can compare against the /stats endpoint for the same day, a change record for each promotion, and resolver logs showing matched queries. For an IEC 62443 zone-and-conduit argument or an ISO 27001 control set, that maps onto the boundary-protection and malicious-code controls without much creative writing, and the daily changelog helps further because it lets you demonstrate what specifically changed on a given date rather than asserting that an update occurred at some point.
The relevant number is not how many domains have ever been reported but how many are live right now, and that is over 390,000, each verified as holding an active A record through rotating proxy infrastructure, with entries that stop resolving dropping out at the next 24-hour rebuild rather than accumulating — so the file stays a working set instead of an archive that grows until somebody has to deal with it. Operationally the effort is a scheduled download, a validation check and a resolver reload, genuinely an afternoon for whoever already maintains that infrastructure, and thereafter it is one of the very few security controls that runs without asking anybody for anything.
For a single site the credit route is often the honest answer rather than the feed, because a monthly vendor-master sweep plus ad-hoc checks against links in suspicious mail will not consume 10,000 lookups quickly and the $59 package is frequently a multi-year supply at that rate. If you already run your own resolver, the feed becomes worthwhile the moment you want standing enforcement across the whole site rather than periodic checks, and multi-site groups tend to hold one feed subscription centrally and distribute the file to plants — which is also the cleanest answer for sites with no security staff at all. The daily feed and pricing pages set out the delivery options.
Confirm the database size through the open statistics endpoint, run the list in log-only mode for one production cycle, and take your own hit count to the change review. If standing enforcement across every plant is the goal, the daily feed is the deployment that works with an air gap rather than against it.