Keeping systems safe from cyber attacks
12th August 2026
USA: Recent incidents involving cyber attacks on HVACR control systems have underlined their potential vulnerability and the need for vigilance.
Last week we reported that an Israeli food processor had been targeted in an Iranian-sponsored attack which reprogrammed the refrigeration controllers and destroyed the compressors. This week it was reported that a health facility in Winnipeg, Canada, has been hit by a ransomware attack that disrupted several building services systems, including its HVAC systems.
Preventing cyber attacks on HVACR systems requires a range of measures such as isolating building networks from corporate IT, implementing multi-factor authentication for remote vendors, changing factory-default passwords, and promptly applying new firmware patches and updates to building automation controllers.
Cyber security company Claroty has now revealed that its own research carried out last year identified vulnerabilities in both Copeland and Danfoss controllers.
Claroty’s specialised vulnerability and threat research arm, Team82, immediately disclosed these vulnerabilities to the controls manufacturers, who were able to address them with a new firmware update.
Team82 researched the attack surface of the Danfoss Adap-Kool AK-SM 800A centralised system manager and identified multiple vulnerabilities affecting the embedded web management interface. They also identified thousands of publicly accessible management interfaces.The AK-SM 800A controller is widely used in supermarkets, cold-storage facilities, warehouses, and other commercial environments.
The research uncovered a hidden “code-of-the-day” authentication mechanism that could be abused to bypass normal authentication, a command-injection vulnerability leading to remote code execution, and an issue allowing authenticated users to inject arbitrary individual instructions, which could be leveraged to manipulate web traffic and trigger a denial-of-service condition.
Danfoss investigated Claroty’s Team82 findings and released firmware version R4.3.1 in August last year which addressed the vulnerabilities.
Danfoss recommended that its users should also avoid exposing management interfaces directly to the internet and ensure that access to administrative services is restricted to trusted management networks or secured through VPNs and other appropriate network segmentation controls.
At much the same time, Team82 researched the attack surface of the Copeland XWEB Pro web-based HVACR monitoring, data capture, and supervisory system. This included the XWEB300D PRO and XWEB500D PRO which manage distributed field devices, coordinating compressors, evaporators, and environmental sensors while maintaining the temperature records required for regulatory compliance.
The analysis uncovered a total of 23 vulnerabilities, 21 of which were described as high-severity.
It found that each issue independently posed a significant security risk and could ultimately allow an unauthenticated attacker to progressively bypass the platform’s security mechanisms, resulting in root-level remote code execution. A live physical test demonstrated that a compromised supervisory controller could grant an attacker the ability to physically manipulate refrigeration systems.
Claroty Team82 shared its findings with Copeland and worked together to develop a comprehensive remediation strategy. Firmware update version 1.13 was subsequently issued in February this year to patch the vulnerabilities.
Insisting that cybersecurity was a top priority for Danfoss, Mirko Travaglin, Danfoss Climate Solutions’ head of monitoring and connectivity portfolio, said: “We appreciate the responsible disclosure process with Claroty Team82, which enabled us to quickly investigate and address these vulnerabilities in firmware version R4.3.1. We remain committed to partnering with the security community, continuously improving our products, and safeguarding our customers’ operations. Customers using affected AK-SM 800A controllers were informed to upgrade to version R4.3.1 or later and ensure they are running the latest software releases from 2025 to benefit from the latest security protections.”
A Copeland spokesperson told the Cooling Post: “When Clarity notified us in November 2025 of potential vulnerabilities affecting certain XWEB monitoring solutions, we immediately investigated the issue and implemented the necessary fixes. We kept affected customers informed throughout the process and provided actionable guidance to help them mitigate risk and maintain operational continuity.
“Safeguarding the security, quality and performance of our products is fundamental to everything we do, and we value collaboration with the cybersecurity research community to help advance industry-wide security standards.”






