ResourcesTexas Breach Tracker › Wood Group Mustang (Houston)
Oil & Gas OT Remediated

Wood Group Mustang (Houston)
Breach Analysis

Wood Group Mustang, an oil and gas engineering firm operating from Houston, experienced a cyberattack in 2023 that impacted OT (operational technology) engineering systems. Production workflow and project systems disrupted.

Incident Date
2023-07-15
Records Exposed
400+ ep
Attack Type
OT
Threat Actor
Unconfirmed

How they got in

Initial access via spear-phishing targeting a senior engineer with OT system access. Credential compromise gave attacker lateral access to engineering design systems adjacent to OT infrastructure. No confirmed impact to industrial control systems but close proximity noted.

Sentinel / Fortress / Command coverage

Sentinel Spear-phishing with engineer-targeted content detected via email sandbox — behavioral URL analysis catches zero-day phishing links
Fortress OT-adjacent workstation segmentation: engineering systems require VPN + MFA to access; attacker cannot pivot from email compromise to OT network
Command OT risk assessment identifies and documents crown jewel systems (ICS/SCADA adjacent) with enhanced monitoring requirements

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
NERC CIP CIP-007-6 System security management — OT-adjacent systems lacked endpoint security and access management controls
TDPA Tex. B&C Code §521.053 Any exfiltrated employee PII triggers TX notification requirement

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.