CISA Red Team Finds One Org Compromised, Another Detected Attack
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed the starkly different outcomes of two simultaneous red team assessments against critical infrastructure organizations, finding that one was completely compromised while the other quickly detected and contained the simulated attack. The findings, published in an advisory on August 25, 2026, highlight that effective defense depends more on trained personnel and proper processes than on the security tools themselves. CISA conducted the assessments using similar tradecraft against an unnamed Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector entity (Organization B). In both cases, the red team gained initial access through phishing and escalated privileges by exploiting common Active Directory misconfigurations. However, the defensive responses were worlds apart. At Organization A, the red team operated entirely undetected. They accessed sensitive business systems using cleartext credentials, reached cloud resources, and even read the security team's emails to check if defenders were aware of the activity.