Executive Answer
A China-linked espionage group tracked as Fire Ant compromised Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts inside critical infrastructure environments. They captured network traffic, harvested credentials, and suppressed the logging defenders need to detect attacks. CIRCIA requires covered entities to report substantial cyber incidents to CISA within 72 hours of becoming aware. Fire Ant specifically targeted the tools that create awareness. This is not a detection gap. It is a structural compliance gap — and most CIRCIA readiness programs have not addressed it.
Key Numbers
- 72 hours — CIRCIA reporting deadline from the moment a covered entity reasonably believes a covered cyber incident has occurred.
- 24 hours — CIRCIA deadline for reporting ransomware payments to CISA.
- 16 — Critical infrastructure sectors covered by CIRCIA, including energy, financial services, healthcare, and communications.
- 0 — Configuration history entries for the GRE tunnel interface that triggered the Fire Ant investigation. It appeared on a router with no commit record.
- 20+ — Organizations across 9 countries that Sygnia assessed Fire Ant had targeted in the expanded campaign beyond VMware into Cisco IOS XR infrastructure.
- Months — Estimated dwell time inside compromised network infrastructure before detection, based on the scope of activity Sygnia documented.
The most important detail in the Fire Ant investigation is not what they stole. It is what they destroyed before leaving.
Sygnia, the incident response firm that investigated the intrusion, found that Fire Ant — a China-linked espionage group assessed as strongly overlapping with UNC3886 — had expanded beyond VMware hypervisors into a more dangerous layer: the network infrastructure itself. Cisco IOS XR routers. TACACS authentication servers. Linux management hosts used to route, authenticate, and manage high-value networks.
Once inside those devices, the actors did three things. They captured network traffic flowing through trusted paths. They harvested credentials as users authenticated through TACACS. And they suppressed the logging and telemetry that defenders rely on to reconstruct an attack.
The investigation began with an anomaly: a GRE tunnel interface operating on a Cisco IOS XR router with no running configuration and no commit history to explain how it had been created. It simply existed. Sygnia worked backward from that artifact to uncover the full scope of the campaign.
When Attackers Control Routers, They Control Perspective
Network security programs are built around a model where the perimeter is the adversary boundary. Firewalls inspect traffic crossing that boundary. EDR monitors endpoints inside it. SIEMs aggregate logs from both. The implicit assumption is that the network infrastructure — routers, switches, the devices that move packets — is trusted and intact.
Fire Ant invalidated that assumption. Controlling a router does not just provide access to traffic passing through it. It provides control over what gets logged, what gets forwarded to security tools, and what disappears silently. Sygnia described it precisely: the actors gained not just reach but perspective. They could observe traffic moving through trusted network paths. They could position themselves between defenders and the evidence of their own activity.
TACACS servers — the authentication layer for network device access — are particularly valuable targets. Credential harvesting at the TACACS layer gives attackers valid credentials for every device that authenticates through it. It also means that the authentication logs that would show unauthorized access are controlled by infrastructure the attacker already owns.
The CIRCIA Detection Prerequisite
CIRCIA's 72-hour reporting obligation begins when a covered entity "reasonably believes" a covered cyber incident has occurred. The law does not start a clock at the moment of compromise. It starts a clock at the moment of awareness.
Awareness depends on detection. Detection depends on logging. Logging depends on the infrastructure being monitored functioning correctly and independently of the systems being attacked.
This is the specific gap Fire Ant exploited. The logging infrastructure — router telemetry, TACACS authentication records, management host audit trails — was compromised before or concurrent with the broader campaign. Defenders looking for evidence of intrusion were looking at logs controlled by the attacker.
Under those conditions, the 72-hour clock never starts. The organization cannot become aware of a reportable incident because the evidence of the incident has been suppressed. The CIRCIA reporting obligation technically cannot be triggered — not because there is nothing to report, but because the attacker ensured nothing would be detected.
Where CIRCIA Readiness Programs Fall Short
Most CIRCIA compliance programs I see are built around the reporting workflow. Who contacts CISA. What information goes into the initial report. How the 72-hour deadline is tracked. What constitutes a covered cyber incident. These are legitimate questions, and having clear answers to them is necessary.
They are not sufficient.
The reporting workflow is downstream of detection. If your organization does not have the monitoring in place to detect a significant incident within a timeframe that allows a 72-hour report, the workflow is academic. You will learn about the incident from a third party — a customer, a government notification, a security researcher — long after the reporting deadline has passed.
The Fire Ant campaign is a concrete example of what that looks like. The organization discovered the compromise through an anomaly in router configuration, not through proactive detection from any security tool. The GRE tunnel was the artifact that triggered the investigation. Everything else — the credential harvesting, the traffic capture, the log suppression — had been happening for months without generating an alert.
Network edge devices are almost universally excluded from the monitoring scope of enterprise security programs. They are classified as infrastructure, not endpoints. EDR does not run on IOS XR. Most SIEMs have thin log coverage from routers and switches compared to servers and workstations. Management hosts that administer network devices often have weaker monitoring than the servers they control.
This exclusion is the structural CIRCIA compliance gap. Not the form. Not the deadline. The gap between the monitoring scope that most programs treat as sufficient and the monitoring scope that CIRCIA's detection prerequisite actually requires.
What CISOs in Critical Infrastructure Should Do Now
Extend your asset inventory to the network edge. If your router inventory exists only in a network management tool and not in your security asset inventory, your security program does not know what it needs to protect. Add routers, TACACS servers, and network management hosts to the same inventory that drives your monitoring and vulnerability management programs.
Implement out-of-band logging that does not depend on the devices being monitored. Router telemetry forwarded to a SIEM is only as reliable as the router forwarding it. Critical logging — authentication events, configuration changes, interface status — should be captured and stored independently of the monitored device. This is what makes logging tamper-resistant when the router itself is compromised.
Audit router configurations for unauthorized changes on a defined schedule. The GRE tunnel that exposed Fire Ant was detectable through a configuration audit. Scheduled comparisons of router running configuration against known-good baselines, with alerts on unauthorized changes, are a detection mechanism that does not depend on the router's own logging being intact.
Monitor TACACS authentication independently. If TACACS logs are stored only on the TACACS servers themselves, they are controlled by any attacker who has compromised those servers. Centralize TACACS authentication logging to a security-controlled platform and monitor for anomalous authentication patterns — unusual source IPs, off-hours activity, credentials used across multiple devices simultaneously.
Include network infrastructure compromise in your CIRCIA incident response plan. Most incident response plans model server or endpoint compromise. Run a tabletop exercise where the scenario begins with a compromised core router. What does your team see? What tools still work? How do you establish trusted logging when the logging infrastructure may be controlled by an attacker? What triggers the CIRCIA reporting decision, and who makes it?
Asaf's Take
The Fire Ant investigation should be read as a blueprint for what sophisticated state-linked actors do when they want persistence inside critical infrastructure without triggering the reporting requirements that would bring regulatory attention. They do not target the most sensitive data first. They target the infrastructure that would detect them targeting the most sensitive data. CIRCIA is a good law. The 72-hour requirement creates real urgency and accountability. But its effectiveness depends entirely on whether covered entities can detect a substantial incident fast enough to report it. Most cannot, because their monitoring does not extend to the network layer where Fire Ant operates. That is the gap to close — not the reporting form, but the detection capability that makes reporting possible.
Related Reading
Does your CIRCIA readiness program address network edge visibility, or just the reporting workflow?
Let's Assess Your CIRCIA Detection ReadinessSources
- Sygnia: "Fire Ant Evolves from Hypervisors to Trusted Infrastructure" (August 2026): sygnia.co
- The Hacker News: "China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs" (August 31, 2026)
- CISA: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Final Rule
- Mandiant / Google Cloud: UNC3886 threat actor reporting