Fort Irwin sits in the Mojave, a training post that eats through commissary inventory the way other bases burn jet fuel. Sometime this month the refrigeration failed. Food that should have stayed cold didn’t. The installation posted a notice, the way you do when the problem is a compressor. Then F.E. Warren in Wyoming posted one. Fort Huachuca. Naval Station Newport. Columbus Air Force Base. Travis. Naval Air Station Lemoore. Call it what it is: a cybersecurity incident that nobody in the building wants to name.
Then Six More Bases Went Quiet
Bruce Schneier asked the question the services would not. Is someone hacking DoD refrigerators? The stores confirmed to be hit stretch from California to Rhode Island, Wyoming to Mississippi. Each installation announced the outage locally. Each service declined to say how many bases were affected, and pointed questions at the Defense Department. Pentagon officials did not respond. That silence is doing real work. When seven commissaries lose cooling in a cluster, you either have a spectacularly unlucky parts run or you have a shared controller, a shared vendor remote-access path, or a shared building network that someone else mapped first.
You already know this movie from civilian plants. A walk-in cooler runs on a small controller, often with a web UI a contractor stood up years ago and never enrolled in patching. The vendor still has a standing VPN. The box speaks BACnet or Modbus into a building management system that has never sent a log to your SOC. Your firewall looks disciplined at the data center edge. It has never seen this VLAN. The people who get paged are facilities techs, not analysts. They swap a board, dump the spoiled milk, and close the work order. Nobody pulls telemetry, because the controller was never asked to produce any.
Refrigeration looks mundane until you remember what it can do. Change a setpoint and you spoil a week’s rations. You force an emergency resupply. You also get a quiet foothold on a network that often touches HVAC, badge panels, and the same jump hosts your Windows admins use. You don’t need a finished attribution brief to take that seriously. You need an asset list that includes the evaporator, and an owner who treats a warm cooler as containment, not janitorial work.
Your Cybersecurity Program Never Met the Evaporator
Most programs still draw the map around identity, email, and the laptop. That’s rational until the blast radius is a warehouse. McKesson, the distributor that keeps hospital shelves stocked, just confirmed a cyber incident after ShinyHunters claimed a huge patient-data theft. Different sector, same blind spot. The unglamorous logistics layer holds the records and the temperature. You can run a mature cyber security program for the clinical apps and still leave the distributor, the commissary, and the building controller outside the threat model.

Defense in depth that stops at Active Directory is a slogan. The depth has to include the OT network, the vendor remote-access account, and the cheap box that talks to the compressors. Threat-protection stacks aimed at phishing kits and commodity malware will not notice a BACnet write that bumps a cooler from 34°F to 55°F. Your incident response runbook probably doesn’t name an owner for “the food is thawing.” Until it does, the attacker gets a head start measured in spoiled pallets and unpaid overtime, not just stolen hashes.
There’s a procurement problem underneath the technical one. These controllers arrive as a facilities purchase. They skip the security hardening bar you apply to a file server. Default credentials survive because the technician’s laptop is the real second factor. Firmware sits years behind. Management ports hang off a contractor SSID. If that sounds like every building system you’ve audited, you’ve already seen the Fort Irwin problem at smaller scale. The military version just has more eyes on it, and still no public explanation.
Put the Cold Chain on the Same Watch as Active Directory
Start this week with an inventory you can finish on foot. Walk the commissary, the pharmacy fridge, the data center CRACs, the warehouse coolers. Write down make, model, firmware, network path, and who can reach the management plane. If the honest answer is “the vendor,” that is the finding. Pull those interfaces off the open campus LAN. Park them behind a jump host with MFA, named accounts, and session recording. Kill shared passwords. If a web UI is reachable from the internet, take it down before you finish this paragraph. That is the immediate work. Everything else is theater until those boxes are off the public path.
Assume any login page you leave up will eat brute-force traffic. Exposed BMS portals and vendor VPNs get sprayed the same way RDP did a decade ago. Use key-based access where the device supports it, plus lockouts and dynamic IP bans on the jump host. An ipban-style control, or IPBan Pro if your jump boxes are Windows, raises the cost of password spraying. It is not a strategy by itself. Pair it with alerts on repeated failures, after-hours logins, and any setpoint change outside a maintenance window. Threat detection for this gear is mostly “did something change that should never change.” You can build that with syslog and a historian. You cannot build it if the controller has never been configured to log.

Give incident response a facilities liaison and a pre-agreed containment step: isolate the refrigeration VLAN without waiting for a blessing from upstairs. Tabletop the boring scenario. Who calls the vendor. Who decides to dump inventory. Who talks to the installation commander. Patch controller firmware on the same cadence you patch the domain controller, even when the vendor portal looks abandoned. Keep that cadence going; one heroic weekend does not count as a program. And while you’re staring at the ticket queue, remember the queue is in scope. ServiceNow just patched three critical code injection flaws that could let an attacker run code and tamper with data. The platform you use to track a cooler outage can become the outage.
You will not get a clean yes from the Pentagon this week. You don’t need one to act. If your map of the enterprise still ends at the server room, the next outage that looks like a compressor already has a second owner. Put the walk-in cooler on the watch list. Then keep it there when the news cycle moves on.
Sources
- Is Someone Hacking DoD Refrigerators?
- McKesson confirms cyber incident after ShinyHunters claims patient-data theft
- ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
