Cyberattacks on Energy Infrastructure
Every cyberattack recorded on this site, in one searchable list
Cyberattacks and cyber-linked disruptions affecting energy infrastructure worldwide, drawn from the same source-linked incident records shown on the main map. Use the filters below to narrow by year, region, confidence level, or search by name, country or keyword.
- Recorded
- 59
- Documented
- 38
- Regions
- 6
- Sources
- 94
- Date range
- 1970–2026
Archive
All cyberattacks
2026
1 cyberattackUnidentified UK small-scale generator — four-day cyber shutdown
United Kingdom (facility withheld; country-level marker) · Power Station · Europe
A cyberattack shut an unidentified small-scale British energy generator for four days. The Department for Energy Security and Net Zero confirmed that the incident affected a small generator and said the wider UK energy system was never at risk. The National Cyber Security Centre was involved in the response; the NCSC and energy department subsequently briefed energy-sector chief executives and wrote to companies with advice, direction and next steps. Media attributed the operation to Iran-linked hackers and described it as the first known successful Iranian-linked cyberattack to take a UK power facility offline, but the public government statement did not confirm either the actor or that historical characterization. The Telegraph reported that the incident coincided with attacks on US water infrastructure affecting 12 states and drawing White House concern. Separately, Al Jazeera and Reuters reported that more than 30 Minnesota community water systems were affected in a coordinated attack and that officials considered similarities to Iran-aligned activity preliminary; no public evidence reviewed established that the UK and US campaigns were operationally connected. Officials withheld the plant's identity and location for security reasons. Its generating technology, capacity, intrusion method and exact July dates also remain undisclosed, so the marker is a country-level reference.
5 sourcesDetails +Reported impactSmall-scale generator shut down for four days; no risk to the wider UK energy systemA cyberattack shut an unidentified small-scale British energy generator for four days. The Department for Energy Security and Net Zero confirmed that the incident affected a small generator and said the wider UK energy system was never at risk. The National Cyber Security Centre was involved in the response; the NCSC and energy department subsequently briefed energy-sector chief executives and wrote to companies with advice, direction and next steps. Media attributed the operation to Iran-linked hackers and described it as the first known successful Iranian-linked cyberattack to take a UK power facility offline, but the public government statement did not confirm either the actor or that historical characterization. The Telegraph reported that the incident coincided with attacks on US water infrastructure affecting 12 states and drawing White House concern. Separately, Al Jazeera and Reuters reported that more than 30 Minnesota community water systems were affected in a coordinated attack and that officials considered similarities to Iran-aligned activity preliminary; no public evidence reviewed established that the UK and US campaigns were operationally connected. Officials withheld the plant's identity and location for security reasons. Its generating technology, capacity, intrusion method and exact July dates also remain undisclosed, so the marker is a country-level reference.
2024
2 cyberattacksRECOPE ransomware attack — RansomHub intrusion disrupts Costa Rica's state fuel refiner
San José, Costa Rica · Refinery · Americas
The ransomware group RansomHub compromised the IT systems of Refinadora Costarricense de Petróleo (RECOPE), Costa Rica's state oil refining and fuel-distribution company, gaining initial access via a phishing email and remaining undetected for several months before encrypting files and demanding a $5 million ransom on 27 November 2024, the day before the US Thanksgiving holiday. The attack disrupted RECOPE's operations for several days, causing fuel tanker trucks to back up at gas stations and forcing the company to process payments manually, prompting public concern reminiscent of the 2021 Colonial Pipeline ransomware incident in the United States. The US State Department's newly created Foreign Assistance Leveraged for Cybersecurity Operational Needs (FALCON) program deployed its first real-world rapid-response team in response, with a mixed team of government personnel and federal contractors arriving in San José within 36 hours. The team conducted forensic investigation, ransomware removal, data restoration from backups and system hardening, remaining on-site for approximately ten days with continued remote support through mid-December, at a total cost of roughly $500,000 drawn from a $10 million fund. US Ambassador Nate Fick said FALCON aimed to deliver swift, decisive support using 'best in breed' private-sector capabilities within 48 hours of a request. No physical damage to refining or pipeline infrastructure was reported.
1 sourceDetails +Reported impactThe ransomware attack disrupted RECOPE's operations for several days, causing fuel tanker trucks to accumulate at gas stations and forcing RECOPE to process payments manually. No physical damage to refining or pipeline infrastructure was reported; the disruption was confined to IT systems and the business/logistics processes dependent on them.The ransomware group RansomHub compromised the IT systems of Refinadora Costarricense de Petróleo (RECOPE), Costa Rica's state oil refining and fuel-distribution company, gaining initial access via a phishing email and remaining undetected for several months before encrypting files and demanding a $5 million ransom on 27 November 2024, the day before the US Thanksgiving holiday. The attack disrupted RECOPE's operations for several days, causing fuel tanker trucks to back up at gas stations and forcing the company to process payments manually, prompting public concern reminiscent of the 2021 Colonial Pipeline ransomware incident in the United States. The US State Department's newly created Foreign Assistance Leveraged for Cybersecurity Operational Needs (FALCON) program deployed its first real-world rapid-response team in response, with a mixed team of government personnel and federal contractors arriving in San José within 36 hours. The team conducted forensic investigation, ransomware removal, data restoration from backups and system hardening, remaining on-site for approximately ten days with continued remote support through mid-December, at a total cost of roughly $500,000 drawn from a $10 million fund. US Ambassador Nate Fick said FALCON aimed to deliver swift, decisive support using 'best in breed' private-sector capabilities within 48 hours of a request. No physical damage to refining or pipeline infrastructure was reported.
Orpak fuel-management systems — CyberAv3ngers compromise claim
Israel and United States (campaign; country-level marker in Israel) · Fuel Retail Station · Middle East
CyberAv3ngers claimed it compromised Orpak SiteOmat fuel-management systems used by filling stations in Israel and the United States, publishing screenshots and stolen data and asserting that 200 stations were affected. Claroty later analyzed IOCONTROL malware recovered from a closely related Gasboy payment terminal and identified command-and-control infrastructure associated with the campaign. The available evidence supports a real effort against fuel-retail operational technology, but public reporting did not verify that all 200 claimed stations were compromised or establish nationwide fuel shortages, panic buying or a prolonged dispatch-system outage. The record therefore remains reported rather than documented at the claimed scale.
1 sourceDetails +Reported impactUp to 200 Israeli and US stations claimed · victim count and service impact not independently confirmedCyberAv3ngers claimed it compromised Orpak SiteOmat fuel-management systems used by filling stations in Israel and the United States, publishing screenshots and stolen data and asserting that 200 stations were affected. Claroty later analyzed IOCONTROL malware recovered from a closely related Gasboy payment terminal and identified command-and-control infrastructure associated with the campaign. The available evidence supports a real effort against fuel-retail operational technology, but public reporting did not verify that all 200 claimed stations were compromised or establish nationwide fuel shortages, panic buying or a prolonged dispatch-system outage. The record therefore remains reported rather than documented at the claimed scale.
2023
2 cyberattacksIranian fuel stations — Predatory Sparrow disruption
Iran (national; country-level marker) · Fuel Retail Station · Middle East
A cyberattack disrupted payment and fuel-management services at about 70% of Iran's filling stations. Oil Minister Javad Owji confirmed the cyberattack, while the group calling itself Predatory Sparrow claimed responsibility and said it deliberately left some stations unaffected. Many stations switched to manual operation. Iran's petrol-station association said there was no underlying fuel-supply shortage. The event occurred on 18 December 2023, not April 2024, and is distinct from the nationwide Iranian fuel-card attack of October 2021.
2 sourcesDetails +Reported impactAbout 70% of stations disrupted · manual operation used · no physical fuel shortage reportedA cyberattack disrupted payment and fuel-management services at about 70% of Iran's filling stations. Oil Minister Javad Owji confirmed the cyberattack, while the group calling itself Predatory Sparrow claimed responsibility and said it deliberately left some stations unaffected. Many stations switched to manual operation. Iran's petrol-station association said there was no underlying fuel-supply shortage. The event occurred on 18 December 2023, not April 2024, and is distinct from the nationwide Iranian fuel-card attack of October 2021.
MOVEit exploitation campaign — energy-sector data theft
Global (energy-sector campaign; marker at Shell headquarters, London) · Oil or fuel facility · Europe
Cl0p exploited a zero-day SQL-injection vulnerability in Progress Software's MOVEit Transfer product, installed the LEMURLOOT web shell and stole data from victim file-transfer databases. Energy-related victims publicly identified included Shell, Siemens Energy and two US Department of Energy entities. Shell said there was no evidence its core IT systems were affected, and no reviewed source reported interruption of refining, generation, drilling or grid operations at the named energy organizations. This is an aggregate supply-chain data-theft record, not a claim that the whole energy sector or operational technology was disabled.
2 sourcesDetails +Reported impactShell, Siemens Energy and 2 US DOE entities affected · no physical energy disruption reportedCl0p exploited a zero-day SQL-injection vulnerability in Progress Software's MOVEit Transfer product, installed the LEMURLOOT web shell and stole data from victim file-transfer databases. Energy-related victims publicly identified included Shell, Siemens Energy and two US Department of Energy entities. Shell said there was no evidence its core IT systems were affected, and no reviewed source reported interruption of refining, generation, drilling or grid operations at the named energy organizations. This is an aggregate supply-chain data-theft record, not a claim that the whole energy sector or operational technology was disabled.
2022
1 cyberattackNordex — cyberattack disrupts wind-turbine manufacturer IT
Hamburg, Germany (global company systems) · Power Grid · Europe
Nordex detected a cyberattack on 31 March and shut down internal IT systems across several business units. It also disabled remote access from its corporate network to customer turbines as a precaution and established alternative monitoring. Turbines continued operating without restriction, and wind-farm communications with grid operators and energy traders remained available. Nordex later said unavailable business applications and databases affected production and commissioning schedules. The company did not publicly identify an attacker in the cited disclosure, so the record does not assert a ransomware family or state sponsor.
2 sourcesDetails +Reported impactTurbines kept operating and grid communications continued; internal-system loss affected production and commissioning schedules.Nordex detected a cyberattack on 31 March and shut down internal IT systems across several business units. It also disabled remote access from its corporate network to customer turbines as a precaution and established alternative monitoring. Turbines continued operating without restriction, and wind-farm communications with grid operators and energy traders remained available. Nordex later said unavailable business applications and databases affected production and commissioning schedules. The company did not publicly identify an attacker in the cited disclosure, so the record does not assert a ransomware family or state sponsor.
2021
4 cyberattacksVestas — ransomware disrupts internal wind-industry IT
Aarhus, Denmark (global company systems) · Power Grid · Europe
Wind-turbine manufacturer Vestas detected a ransomware attack that compromised internal IT systems and data across multiple business units. The company shut down affected systems, restored operations in stages and notified authorities. Vestas said wind-turbine operations were not affected and later reported no significant direct operational or financial impact, correcting the supplied characterization that the incident halted wind-farm operations worldwide.
2 sourcesDetails +Reported impactWind turbines remained operational; Vestas reported no significant direct operational impact, though internal systems and data were affected.Wind-turbine manufacturer Vestas detected a ransomware attack that compromised internal IT systems and data across multiple business units. The company shut down affected systems, restored operations in stages and notified authorities. Vestas said wind-turbine operations were not affected and later reported no significant direct operational or financial impact, correcting the supplied characterization that the incident halted wind-farm operations worldwide.
Transnet ports — cyberattack disrupts South African freight and export terminals
South Africa (national port network; marker at Durban) · Port Export Terminal · Africa
A group-wide cyberattack forced Transnet to shut down information systems and invoke business-continuity procedures across South Africa's port and freight network. Port terminals declared force majeure, container operations were disrupted, and staff used manual processes for incoming and outgoing ships and cargo movements. Government reporting said bulk, break-bulk and automotive operations — including coal, iron ore and manganese cargoes — switched immediately to manual handling. The main NAVIS N4 terminal system and normal port operations were restored by 29 July. Transnet described the event as a cyberattack, security intrusion and sabotage but did not publicly identify an attacker in the cited official material; this record therefore assigns no perpetrator or ransomware family.
3 sourcesDetails +Reported impactContainer operations and customer links disrupted across the national port network; bulk energy and mineral cargo processes switched to manual handlingA group-wide cyberattack forced Transnet to shut down information systems and invoke business-continuity procedures across South Africa's port and freight network. Port terminals declared force majeure, container operations were disrupted, and staff used manual processes for incoming and outgoing ships and cargo movements. Government reporting said bulk, break-bulk and automotive operations — including coal, iron ore and manganese cargoes — switched immediately to manual handling. The main NAVIS N4 terminal system and normal port operations were restored by 29 July. Transnet described the event as a cyberattack, security intrusion and sabotage but did not publicly identify an attacker in the cited official material; this record therefore assigns no perpetrator or ransomware family.
Oldsmar water plant — disputed remote chemical-setting change
Oldsmar, Florida, United States · Power Grid · Americas
A plant operator reported seeing the sodium-hydroxide dosing setting on Oldsmar's water-treatment control system remotely raised from about 100 parts per million to 11,100 parts per million. The operator immediately reversed the change, independent process safeguards remained in place, and officials said no unsafe water reached the public. Authorities initially announced the event as an external computer intrusion, and it became a widely cited critical-infrastructure cyber case. Later, however, the FBI said its investigation could not confirm that a targeted cyber intrusion caused it, while the city's former manager said employee error was likely. The record is therefore marked investigating and disputed rather than asserting that a hacker attempted to poison the water supply.
3 sourcesDetails +Reported impactNo treatment shutdown, contamination or customer water-service lossA plant operator reported seeing the sodium-hydroxide dosing setting on Oldsmar's water-treatment control system remotely raised from about 100 parts per million to 11,100 parts per million. The operator immediately reversed the change, independent process safeguards remained in place, and officials said no unsafe water reached the public. Authorities initially announced the event as an external computer intrusion, and it became a widely cited critical-infrastructure cyber case. Later, however, the FBI said its investigation could not confirm that a targeted cyber intrusion caused it, while the city's former manager said employee error was likely. The record is therefore marked investigating and disputed rather than asserting that a hacker attempted to poison the water supply.
Eletronuclear — ransomware reaches administrative servers
Angra dos Reis, Rio de Janeiro, Brazil · Nuclear Power Plant · Americas
Eletrobras disclosed that ransomware reached part of the administrative-server network at its nuclear subsidiary Eletronuclear. The affected network was separate from the operational systems of the Angra 1 and Angra 2 nuclear plants, and the company reported no impact on plant operations. Brazilian government cyber-response and nuclear-security bodies were notified. No reliable evidence supports the supplied August 2021 date or attribution to Black Basta, a group that emerged later.
1 sourceDetails +Reported impactNo impact to reactor operations or electricity generation was reported.Eletrobras disclosed that ransomware reached part of the administrative-server network at its nuclear subsidiary Eletronuclear. The affected network was separate from the operational systems of the Angra 1 and Angra 2 nuclear plants, and the company reported no impact on plant operations. Brazilian government cyber-response and nuclear-security bodies were notified. No reliable evidence supports the supplied August 2021 date or attribution to Black Basta, a group that emerged later.
2020
2 cyberattacksSolarWinds supply-chain compromise — U.S. DOE and FERC networks exposed
Washington, D.C., United States · Power Grid · Americas
The SolarWinds Orion supply-chain compromise reached business networks at the U.S. Department of Energy, including the National Nuclear Security Administration, and affected the Federal Energy Regulatory Commission. DOE said the malware was isolated to business networks and did not affect mission-essential national-security functions; no grid control or generation disruption was reported. The incident exposed sensitive government and regulatory environments, but the supplied claim that attackers obtained a complete 'roadmap' of U.S. grid vulnerabilities is not stated as fact.
2 sourcesDetails +Reported impactNo compromise of operational energy systems or interruption to electricity supply was reported.The SolarWinds Orion supply-chain compromise reached business networks at the U.S. Department of Energy, including the National Nuclear Security Administration, and affected the Federal Energy Regulatory Commission. DOE said the malware was isolated to business networks and did not affect mission-essential national-security functions; no grid control or generation disruption was reported. The incident exposed sensitive government and regulatory environments, but the supplied claim that attackers obtained a complete 'roadmap' of U.S. grid vulnerabilities is not stated as fact.
Light S.A. — ransomware attack on Rio electricity distributor
Rio de Janeiro, Brazil · Power Grid · Americas
Brazilian electricity distributor Light S.A. reported a cyber incident while security researchers linked the intrusion to Sodinokibi/REvil ransomware and a multimillion-dollar extortion demand. Public evidence did not establish an outage, compromise of operational technology or effect on electricity delivery. The record is marked reported because the ransomware-family attribution and claimed data access were not fully confirmed in a detailed company disclosure.
2 sourcesDetails +Reported impactNo interruption to electricity delivery or operational control systems was established in the reviewed reporting.Brazilian electricity distributor Light S.A. reported a cyber incident while security researchers linked the intrusion to Sodinokibi/REvil ransomware and a multimillion-dollar extortion demand. Public evidence did not establish an outage, compromise of operational technology or effect on electricity delivery. The record is marked reported because the ransomware-family attribution and claimed data access were not fully confirmed in a detailed company disclosure.
2019
1 cyberattackKudankulam NPP — DTrack malware found on administrative network
Tamil Nadu, India · Nuclear Power Plant · Asia
India's Nuclear Power Corporation confirmed that malware had infected an internet-connected computer on Kudankulam's administrative network after CERT-In alerted it on 4 September 2019. A Department of Atomic Energy investigation found the affected administrative network was isolated from the plant's critical internal control network; reactor control and safety systems were not affected and generation continued. Independent security researchers identified the malware as DTrack and associated it with the North Korea-linked Lazarus Group, but the Indian government did not formally attribute the intrusion. The record uses the detection date rather than the supplied April–May date, for which no reliable support was found.
2 sourcesDetails +Reported impactNo reactor shutdown, safety-system impact or electricity-generation loss was reported.India's Nuclear Power Corporation confirmed that malware had infected an internet-connected computer on Kudankulam's administrative network after CERT-In alerted it on 4 September 2019. A Department of Atomic Energy investigation found the affected administrative network was isolated from the plant's critical internal control network; reactor control and safety systems were not affected and generation continued. Independent security researchers identified the malware as DTrack and associated it with the North Korea-linked Lazarus Group, but the Indian government did not formally attribute the intrusion. The record uses the detection date rather than the supplied April–May date, for which no reliable support was found.
2017
1 cyberattackNotPetya — Maersk port logistics and Rosneft systems disrupted
Global campaign (marker at Maersk headquarters, Copenhagen, Denmark) · Port or tanker · Europe
The destructive NotPetya malware spread from a compromised Ukrainian accounting-software update into organizations worldwide. A.P. Moller–Maersk said applications and data became unavailable across its global network, significantly interrupting Maersk Line, APM Terminals and Damco and forcing manual workarounds; vessels remained controllable and Maersk estimated a US$200–300 million financial impact. Rosneft also reported a large-scale attack on its servers, but said oil production continued. This aggregate record captures the campaign's direct energy-logistics and oil-sector impact rather than counting every affected non-energy company as a separate incident.
3 sourcesDetails +Reported impactMaersk Line, APM Terminals and Damco suffered operational disruption; Rosneft said oil production was unaffectedThe destructive NotPetya malware spread from a compromised Ukrainian accounting-software update into organizations worldwide. A.P. Moller–Maersk said applications and data became unavailable across its global network, significantly interrupting Maersk Line, APM Terminals and Damco and forcing manual workarounds; vessels remained controllable and Maersk estimated a US$200–300 million financial impact. Rosneft also reported a large-scale attack on its servers, but said oil production continued. This aggregate record captures the campaign's direct energy-logistics and oil-sector impact rather than counting every affected non-energy company as a separate incident.
2015
1 cyberattackUkraine distribution grid — BlackEnergy cyberattack and first confirmed cyber blackout
Ivano-Frankivsk, Kyiv and Chernivtsi oblasts, Ukraine · Power Grid · Europe
Attackers compromised three Ukrainian regional electricity distributors, including Prykarpattyaoblenergo, and remotely opened substation breakers on 23 December 2015. The coordinated operation used stolen credentials, BlackEnergy-enabled access, KillDisk wiping, corrupted field devices and telephone denial-of-service to obstruct response. Seven 110 kV and 23 35 kV substations were disconnected at the most affected utility, and about 225,000 customers lost electricity for one to six hours before operators restored service manually. It is widely recognised as the first publicly confirmed cyberattack to cause a power-grid outage. This prologue record remains available on the map and as an incident page, while the Incidents by month chart continues to begin on 1 January 2016 as requested.
2 sourcesDetails +Reported impactApproximately 225,000 customers across three regional distribution companies lost power for one to six hoursAttackers compromised three Ukrainian regional electricity distributors, including Prykarpattyaoblenergo, and remotely opened substation breakers on 23 December 2015. The coordinated operation used stolen credentials, BlackEnergy-enabled access, KillDisk wiping, corrupted field devices and telephone denial-of-service to obstruct response. Seven 110 kV and 23 35 kV substations were disconnected at the most affected utility, and about 225,000 customers lost electricity for one to six hours before operators restored service manually. It is widely recognised as the first publicly confirmed cyberattack to cause a power-grid outage. This prologue record remains available on the map and as an incident page, while the Incidents by month chart continues to begin on 1 January 2016 as requested.
1970
44 cyberattacksEcopetrol — ransomware attempt blocked after cloud-data theft
Bogotá / Ecopetrol Group operations, Colombia · Oil or fuel facility · Americas
Ecopetrol detected unauthorized access to cloud file-storage environments used by about 15 group companies, with files associated with approximately 3,300 user accounts downloaded. The attacker then attempted to destroy, delete or encrypt data, but Ecopetrol said its security controls blocked the ransomware payload and found no compromise of transactional systems, user identities or access credentials. The company reported no material interruption to critical operations, production capacity or essential services. The Gentlemen ransomware group later claimed responsibility and asserted that it held roughly one terabyte of data, including drilling and corporate records; samples reviewed by outside reporting appeared consistent with genuine company documents, but Ecopetrol did not validate the group's total-volume or file-content claims. This is therefore a confirmed corporate data-theft and attempted-ransomware incident without demonstrated operational-technology or production impact.
2 sourcesDetails +Reported impactEcopetrol reported no material interruption to critical operations, production capacity or essential services.Ecopetrol detected unauthorized access to cloud file-storage environments used by about 15 group companies, with files associated with approximately 3,300 user accounts downloaded. The attacker then attempted to destroy, delete or encrypt data, but Ecopetrol said its security controls blocked the ransomware payload and found no compromise of transactional systems, user identities or access credentials. The company reported no material interruption to critical operations, production capacity or essential services. The Gentlemen ransomware group later claimed responsibility and asserted that it held roughly one terabyte of data, including drilling and corporate records; samples reviewed by outside reporting appeared consistent with genuine company documents, but Ecopetrol did not validate the group's total-volume or file-content claims. This is therefore a confirmed corporate data-theft and attempted-ransomware incident without demonstrated operational-technology or production impact.
US water and energy control systems — PLC exploitation campaign
United States (at least twelve states; 30+ Minnesota and nine Michigan systems reported) · Power Grid · Americas
Federal agencies issued joint advisory AA26-097A on 7 April and expanded it on 22 July, documenting an Iran-affiliated campaign against internet-facing programmable logic controllers at US water, wastewater, energy and government facilities. The update widened the affected equipment from Rockwell Automation/Allen-Bradley devices to Schneider Electric and Siemens systems, described project-file exfiltration and malicious project files, and noted cases where altered programming disabled shutdown and alarm functions or manipulated HMI/SCADA displays. On 26–27 July, coordinated intrusions affected operational technology at more than 30 Minnesota community water systems: one plant went temporarily offline, other operators switched to manual control, and Braham, Plymouth, South St. Paul and Maple Plain were named publicly. Minnesota officials reported no effect on water quality or safety. By 10 August, Dark Reading reported related attacks across at least twelve states, with disclosed activity in Minnesota, Georgia, Michigan, South Dakota, Alabama and New Jersey. Attackers reportedly changed PLC passwords and IP addresses, locking some operators out of remote visibility and control and forcing manual workarounds. The most consequential publicly reported case was in Clayton County, Georgia, where cyber activity was linked to a water-pressure drop and a boil-water advisory. Michigan reported nine affected systems, all operating safely and without a public-health concern. No definitive attribution has been announced for the latest multistate intrusions: researchers noted similarities to earlier IRGC-linked CyberAv3ngers activity, while federal authorities continued to treat attribution as unresolved. The affected water utilities are normally outside this map's core energy scope; this campaign is retained because the same documented activity targets energy facilities and shared industrial-control equipment.
2 sourcesDetails +Reported impactAt least 12 states · manual control required at some utilities · Georgia pressure drop and boil-water advisory reportedFederal agencies issued joint advisory AA26-097A on 7 April and expanded it on 22 July, documenting an Iran-affiliated campaign against internet-facing programmable logic controllers at US water, wastewater, energy and government facilities. The update widened the affected equipment from Rockwell Automation/Allen-Bradley devices to Schneider Electric and Siemens systems, described project-file exfiltration and malicious project files, and noted cases where altered programming disabled shutdown and alarm functions or manipulated HMI/SCADA displays. On 26–27 July, coordinated intrusions affected operational technology at more than 30 Minnesota community water systems: one plant went temporarily offline, other operators switched to manual control, and Braham, Plymouth, South St. Paul and Maple Plain were named publicly. Minnesota officials reported no effect on water quality or safety. By 10 August, Dark Reading reported related attacks across at least twelve states, with disclosed activity in Minnesota, Georgia, Michigan, South Dakota, Alabama and New Jersey. Attackers reportedly changed PLC passwords and IP addresses, locking some operators out of remote visibility and control and forcing manual workarounds. The most consequential publicly reported case was in Clayton County, Georgia, where cyber activity was linked to a water-pressure drop and a boil-water advisory. Michigan reported nine affected systems, all operating safely and without a public-health concern. No definitive attribution has been announced for the latest multistate intrusions: researchers noted similarities to earlier IRGC-linked CyberAv3ngers activity, while federal authorities continued to treat attribution as unresolved. The affected water utilities are normally outside this map's core energy scope; this campaign is retained because the same documented activity targets energy facilities and shared industrial-control equipment.
Origin Energy — customer data breach
Australia · Power Grid · Asia-Pacific
Origin Energy, one of Australia's largest electricity and gas retailers, confirmed that an unauthorized party accessed and exfiltrated personal data of about 900,000 current and former customers, including names, addresses, dates of birth, contact details, account information and partial payment details (the last four digits of payment cards, or BSB and last three digits of bank accounts). Origin received emails on 2 July from an individual claiming to hold customer records, received proof of access on 22 July, and disclosed the incident publicly on 28 July. The company notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. This is an IT customer-data breach at an energy retailer rather than a disruption of operational energy infrastructure; the record is kept for its energy-sector relevance and the marker is placed at Origin's Sydney headquarters.
1 sourceDetails +Origin Energy, one of Australia's largest electricity and gas retailers, confirmed that an unauthorized party accessed and exfiltrated personal data of about 900,000 current and former customers, including names, addresses, dates of birth, contact details, account information and partial payment details (the last four digits of payment cards, or BSB and last three digits of bank accounts). Origin received emails on 2 July from an individual claiming to hold customer records, received proof of access on 22 July, and disclosed the incident publicly on 28 July. The company notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. This is an IT customer-data breach at an energy retailer rather than a disruption of operational energy infrastructure; the record is kept for its energy-sector relevance and the marker is placed at Origin's Sydney headquarters.
Australian critical-infrastructure provider — state-sponsored cyber pre-positioning
Australia (provider and sector undisclosed; country-level marker) · Power Grid · Asia-Pacific
ASIO disclosed that nation-state hackers compromised the network of an unnamed Australian critical-infrastructure provider, acquired credentials belonging to active users including IT and network-defence personnel, mapped the network and maintained persistent access. ASIO assessed the operation as preparation for sabotage, identified and attributed the intrusion internally, and worked with the victim and security partners on continuing remediation. The agency did not publicly identify the provider, its sector, the responsible state, the compromise date or any operational disruption. Energy and communications were described as top targets generally, not as confirmation that this victim was an energy company. This marker is therefore placed at country level and does not represent a facility outage.
1 sourceDetails +ASIO disclosed that nation-state hackers compromised the network of an unnamed Australian critical-infrastructure provider, acquired credentials belonging to active users including IT and network-defence personnel, mapped the network and maintained persistent access. ASIO assessed the operation as preparation for sabotage, identified and attributed the intrusion internally, and worked with the victim and security partners on continuing remediation. The agency did not publicly identify the provider, its sector, the responsible state, the compromise date or any operational disruption. Energy and communications were described as top targets generally, not as confirmation that this victim was an energy company. This marker is therefore placed at country level and does not represent a facility outage.
Melbourne water retailers — Metrix Consulting customer-data breach
Melbourne, Victoria, Australia (multi-utility customer-data incident) · Power Grid · Asia-Pacific
South East Water, City West Water and Yarra Valley Water disclosed that a data-security incident at research contractor Metrix Consulting affected about 4,000 business and residential customer records shared for a research project. The exposed data included billing names, account numbers and addresses, with some email addresses and phone numbers; the utilities said financial, payment-card and driver's-licence data were not accessed. No water-treatment, distribution or operational-technology impact was reported. Although sometimes recirculated with recent Australian cyber incidents, the disclosure dates to March 2020. The marker is a metropolitan reference rather than a breached utility facility.
1 sourceDetails +South East Water, City West Water and Yarra Valley Water disclosed that a data-security incident at research contractor Metrix Consulting affected about 4,000 business and residential customer records shared for a research project. The exposed data included billing names, account numbers and addresses, with some email addresses and phone numbers; the utilities said financial, payment-card and driver's-licence data were not accessed. No water-treatment, distribution or operational-technology impact was reported. Although sometimes recirculated with recent Australian cyber incidents, the disclosure dates to March 2020. The marker is a metropolitan reference rather than a breached utility facility.
Quebec municipal water plant — claimed NoName OT access
Quebec, Canada (municipality undisclosed; province-level marker) · Power Grid · Americas
CSIRTAmericas alerted Canada's Cyber Centre to NoName's claim that it had obtained unauthorized access to a Quebec municipality's water-treatment systems, including the alleged ability to covertly control pumps, chlorine dosing, pressure settings and monitoring or alert functions. The Cyber Centre rapidly assessed the threat and coordinated mitigation with partners to reduce the public-safety risk. CSE did not name the municipality or report contamination, injury, service loss or malicious process changes. Reports identifying a particular town are therefore not repeated here, and the marker remains province-level and reported rather than treating every actor claim as confirmed fact.
1 sourceDetails +CSIRTAmericas alerted Canada's Cyber Centre to NoName's claim that it had obtained unauthorized access to a Quebec municipality's water-treatment systems, including the alleged ability to covertly control pumps, chlorine dosing, pressure settings and monitoring or alert functions. The Cyber Centre rapidly assessed the threat and coordinated mitigation with partners to reduce the public-safety risk. CSE did not name the municipality or report contamination, injury, service loss or malicious process changes. Reports identifying a particular town are therefore not repeated here, and the marker remains province-level and reported rather than treating every actor claim as confirmed fact.
Nova Scotia Power — foreign-actor breach and smart-meter billing disruption
Halifax, Nova Scotia, Canada (company headquarters) · Power Grid · Americas
Nova Scotia Power said an employee visited a malware-compromised website and clicked a link that enabled a sophisticated foreign threat actor to enter its network. The actor stole internal data and personal information affecting approximately 375,000 current and 540,000 former customers, and destroyed or locked key business systems. Electricity generation and delivery continued, and meters still measured usage accurately, but malware severed the flow of readings into billing systems, producing estimated bills and prolonged customer-service disruption. Meter-to-billing connections were restored by 31 March 2026. The company has not publicly identified the actor's country, so Russia-linked claims are not assigned here.
1 sourceDetails +Reported impactNo generation or delivery outage; smart-meter communications and billing disrupted until March 2026Nova Scotia Power said an employee visited a malware-compromised website and clicked a link that enabled a sophisticated foreign threat actor to enter its network. The actor stole internal data and personal information affecting approximately 375,000 current and 540,000 former customers, and destroyed or locked key business systems. Electricity generation and delivery continued, and meters still measured usage accurately, but malware severed the flow of readings into billing systems, producing estimated bills and prolonged customer-service disruption. Meter-to-billing connections were restored by 31 March 2026. The company has not publicly identified the actor's country, so Russia-linked claims are not assigned here.
Monterrey water utility — AI-assisted IT compromise and failed OT pivot
Monterrey, Nuevo León, Mexico · Power Grid · Americas
Dragos confirmed a significant compromise of Servicios de Agua y Drenaje de Monterrey's enterprise IT network by an unknown actor during a wider campaign against Mexican government organizations. Recovered artifacts showed extensive use of Anthropic's Claude for intrusion planning and tool development and OpenAI GPT models for processing stolen data. After identifying an internal vNode industrial gateway as an OT-adjacent target, the actor used AI-generated credential lists in two password-spray attempts. Both failed, and Dragos found no evidence that the actor gained visibility into or control of the underlying operational environment. This record therefore describes a successful IT breach and failed OT pivot, not a water-service disruption.
1 sourceDetails +Dragos confirmed a significant compromise of Servicios de Agua y Drenaje de Monterrey's enterprise IT network by an unknown actor during a wider campaign against Mexican government organizations. Recovered artifacts showed extensive use of Anthropic's Claude for intrusion planning and tool development and OpenAI GPT models for processing stolen data. After identifying an internal vNode industrial gateway as an OT-adjacent target, the actor used AI-generated credential lists in two password-spray attempts. Both failed, and Dragos found no evidence that the actor gained visibility into or control of the underlying operational environment. This record therefore describes a successful IT breach and failed OT pivot, not a water-service disruption.
PDVSA — cyberattack suspends oil-cargo administration
Caracas, Venezuela (PDVSA headquarters; nationwide systems) · Oil or fuel facility · Americas
A cyberattack disrupted PDVSA's centralized administrative systems, forcing personnel to disconnect systems and use manual records. PDVSA said production and fuel supply were unaffected, while company and shipping sources reported that export loading instructions and cargo deliveries were temporarily suspended and several scheduled tankers turned away. Deliveries began resuming by 17 December after operational sites were isolated from the central system. PDVSA and Venezuela's oil ministry blamed US-linked foreign interests, but published no evidence and responsibility remains disputed. This incident is not treated as proven to be the separate Lotus Wiper campaign.
1 sourceDetails +Reported impactOil-cargo instructions and deliveries temporarily suspended; production, refining and domestic fuel distribution reportedly continuedA cyberattack disrupted PDVSA's centralized administrative systems, forcing personnel to disconnect systems and use manual records. PDVSA said production and fuel supply were unaffected, while company and shipping sources reported that export loading instructions and cargo deliveries were temporarily suspended and several scheduled tankers turned away. Deliveries began resuming by 17 December after operational sites were isolated from the central system. PDVSA and Venezuela's oil ministry blamed US-linked foreign interests, but published no evidence and responsibility remains disputed. This incident is not treated as proven to be the separate Lotus Wiper campaign.
Venezuelan energy and utilities sector — Lotus Wiper destructive campaign
Venezuela (victim company undisclosed; country-level marker) · Power Grid · Americas
Kaspersky identified artifacts from a highly targeted destructive campaign against an unnamed Venezuelan energy or utilities company. Two preparatory scripts disabled defences, changed or disabled accounts, cut network interfaces and coordinated execution before launching a previously undocumented payload named Lotus Wiper. The wiper removed recovery mechanisms, overwrote physical drives and systematically deleted files, leaving affected systems unrecoverable. The samples lacked payment instructions or extortion mechanisms, supporting a destructive rather than financial motive. Kaspersky did not publicly identify the victim or attacker, quantify the operational impact, or establish a connection to PDVSA's December administrative-system incident, so this remains a separate country-level record.
1 sourceDetails +Kaspersky identified artifacts from a highly targeted destructive campaign against an unnamed Venezuelan energy or utilities company. Two preparatory scripts disabled defences, changed or disabled accounts, cut network interfaces and coordinated execution before launching a previously undocumented payload named Lotus Wiper. The wiper removed recovery mechanisms, overwrote physical drives and systematically deleted files, leaving affected systems unrecoverable. The samples lacked payment instructions or extortion mechanisms, supporting a destructive rather than financial motive. Kaspersky did not publicly identify the victim or attacker, quantify the operational impact, or establish a connection to PDVSA's December administrative-system incident, so this remains a separate country-level record.
Kyiv Pivnichna substation — Industroyer/CrashOverride grid attack
Kyiv region, Ukraine · Power Grid · Europe
Custom malware known as Industroyer (also CrashOverride) opened circuit breakers at the Pivnichna 330 kV transmission substation outside Kyiv, cutting power to a portion of the capital — roughly one-fifth of the city by some accounts — for about an hour before operators restored supply manually. It was the first known malware purpose-built to disrupt electric grid operations, speaking industrial protocols including IEC-101, IEC-104 and IEC-61850 directly to substation equipment. ESET called it the biggest threat to industrial control systems since Stuxnet. The marker is placed at the substation; coordinates are approximate.
1 sourceDetails +Custom malware known as Industroyer (also CrashOverride) opened circuit breakers at the Pivnichna 330 kV transmission substation outside Kyiv, cutting power to a portion of the capital — roughly one-fifth of the city by some accounts — for about an hour before operators restored supply manually. It was the first known malware purpose-built to disrupt electric grid operations, speaking industrial protocols including IEC-101, IEC-104 and IEC-61850 directly to substation equipment. ESET called it the biggest threat to industrial control systems since Stuxnet. The marker is placed at the substation; coordinates are approximate.
Saudi petrochemical plant — Triton/Trisis safety-system malware
Saudi Arabia (plant identified in press reporting as Petro Rabigh) · Petrochemical Plant · Middle East
Attackers deployed malware known as Triton, Trisis or HatMan against Schneider Electric Triconex safety instrumented systems at a Saudi petrochemical plant, attempting to reprogram the controllers that provide the last line of automated protection against dangerous plant conditions. A coding error tripped the plant into a safe shutdown in August 2017, leading to discovery. It was the first publicly known malware designed specifically to target industrial safety systems, a capability security researchers class as potentially lethal. The plant is widely identified in press reporting as Petro Rabigh; the marker is placed at the Rabigh complex.
1 sourceDetails +Attackers deployed malware known as Triton, Trisis or HatMan against Schneider Electric Triconex safety instrumented systems at a Saudi petrochemical plant, attempting to reprogram the controllers that provide the last line of automated protection against dangerous plant conditions. A coding error tripped the plant into a safe shutdown in August 2017, leading to discovery. It was the first publicly known malware designed specifically to target industrial safety systems, a capability security researchers class as potentially lethal. The plant is widely identified in press reporting as Petro Rabigh; the marker is placed at the Rabigh complex.
US and European energy sector — Dragonfly 2.0 espionage campaign
United States and Europe (multi-year campaign; no single site) · Power Grid · Americas
A sustained espionage campaign targeted energy-sector companies in the United States and Europe using spear-phishing, watering-hole sites and supply-chain staging targets, building on the earlier Havex/Dragonfly activity. In confirmed cases the actors reached workstations with access to industrial control systems, capturing screenshots of HMI interfaces and reconnaissance on generation and transmission networks, though no disruption was recorded. Related FSB-linked pre-positioning against US and international energy networks continued through roughly 2018–2020 and later produced US indictments. This is a campaign record rather than a single incident; the marker is a country-level reference, not a facility.
1 sourceDetails +A sustained espionage campaign targeted energy-sector companies in the United States and Europe using spear-phishing, watering-hole sites and supply-chain staging targets, building on the earlier Havex/Dragonfly activity. In confirmed cases the actors reached workstations with access to industrial control systems, capturing screenshots of HMI interfaces and reconnaissance on generation and transmission networks, though no disruption was recorded. Related FSB-linked pre-positioning against US and international energy networks continued through roughly 2018–2020 and later produced US indictments. This is a campaign record rather than a single incident; the marker is a country-level reference, not a facility.
sPower wind and solar fleet — firewall denial-of-service
United States (control center in Salt Lake City, Utah) · Power Grid · Americas
An attacker exploited a known, unpatched vulnerability in internet-facing Cisco firewalls at renewables operator sPower, forcing repeated reboots that cut communications between the control center and about a dozen wind and solar generation sites totalling roughly 500 MW. Interruptions lasted under five minutes each across about 12 hours. No generation was lost and no attribution was made, but Department of Energy records make it the first cyber event confirmed to have interrupted US electrical-system operations, and it exposed how exposed distributed renewable fleets can be. The marker is placed at the operator's Salt Lake City control center.
1 sourceDetails +An attacker exploited a known, unpatched vulnerability in internet-facing Cisco firewalls at renewables operator sPower, forcing repeated reboots that cut communications between the control center and about a dozen wind and solar generation sites totalling roughly 500 MW. Interruptions lasted under five minutes each across about 12 hours. No generation was lost and no attribution was made, but Department of Energy records make it the first cyber event confirmed to have interrupted US electrical-system operations, and it exposed how exposed distributed renewable fleets can be. The marker is placed at the operator's Salt Lake City control center.
Azerbaijan energy sector — PoetRAT espionage with wind-SCADA interest
Azerbaijan · Power Grid · Asia
Cisco Talos documented waves of a previously unknown Python remote-access trojan, dubbed PoetRAT, delivered via malicious Word documents including COVID-19-themed lures styled as Azerbaijani government letters. Targets included government and energy-sector organizations, and the actor demonstrated specific interest in SCADA systems associated with wind turbines, collecting files, credentials and webcam images. Talos could not link the activity to a known actor, and no operational disruption of turbines was confirmed — this is an espionage record, kept because of the demonstrated targeting of renewable-energy control systems. The marker is a country-level reference at Baku.
1 sourceDetails +Cisco Talos documented waves of a previously unknown Python remote-access trojan, dubbed PoetRAT, delivered via malicious Word documents including COVID-19-themed lures styled as Azerbaijani government letters. Targets included government and energy-sector organizations, and the actor demonstrated specific interest in SCADA systems associated with wind turbines, collecting files, credentials and webcam images. Talos could not link the activity to a known actor, and no operational disruption of turbines was confirmed — this is an espionage record, kept because of the demonstrated targeting of renewable-energy control systems. The marker is a country-level reference at Baku.
Colonial Pipeline — DarkSide ransomware shutdown
United States (Houston, Texas to Linden, New Jersey system) · Pipeline · Americas
DarkSide ransomware compromised Colonial Pipeline's IT network, and the company proactively shut down its entire 5,500-mile refined-products system — which carries over 100 million gallons a day, nearly half the US East Coast's fuel — for about five days as a containment precaution. The shutdown triggered fuel shortages, panic buying, price spikes and emergency declarations across the southeastern US. Colonial paid a ransom of roughly $4.4 million, part of which the Department of Justice later recovered. The operational technology systems were not confirmed to be directly compromised; the disruption came from the precautionary shutdown. The marker is placed at Colonial's Alpharetta, Georgia headquarters.
1 sourceDetails +DarkSide ransomware compromised Colonial Pipeline's IT network, and the company proactively shut down its entire 5,500-mile refined-products system — which carries over 100 million gallons a day, nearly half the US East Coast's fuel — for about five days as a containment precaution. The shutdown triggered fuel shortages, panic buying, price spikes and emergency declarations across the southeastern US. Colonial paid a ransom of roughly $4.4 million, part of which the Department of Justice later recovered. The operational technology systems were not confirmed to be directly compromised; the disruption came from the precautionary shutdown. The marker is placed at Colonial's Alpharetta, Georgia headquarters.
Iranian fuel-card payment system — nationwide cyberattack
Iran · Oil or fuel facility · Middle East
A cyberattack disabled the nationwide system allowing Iranian motorists to buy government-subsidized fuel with state-issued smart cards, affecting all of the country's roughly 4,300 gas stations. Long queues and traffic disruption followed as many drivers could only buy fuel at the unsubsidized rate; digital billboards in Tehran and Isfahan were also compromised, and affected pump screens displayed a message including a phone number linked to the Supreme Leader's office. Iran's oil minister said the fuel-supply system itself was not compromised and that stations continued dispensing fuel manually. About 3,200 of 4,300 stations had been reconnected to the card system within four days.
1 sourceDetails +A cyberattack disabled the nationwide system allowing Iranian motorists to buy government-subsidized fuel with state-issued smart cards, affecting all of the country's roughly 4,300 gas stations. Long queues and traffic disruption followed as many drivers could only buy fuel at the unsubsidized rate; digital billboards in Tehran and Isfahan were also compromised, and affected pump screens displayed a message including a phone number linked to the Supreme Leader's office. Iran's oil minister said the fuel-supply system itself was not compromised and that stations continued dispensing fuel manually. About 3,200 of 4,300 stations had been reconnected to the card system within four days.
Danish energy sector — coordinated Zyxel firewall intrusions
Denmark · Power Grid · Europe
In a first wave on 11 May 2023, attackers exploited a critical command-injection vulnerability (CVE-2023-28771) in Zyxel firewalls to compromise 11 of 16 targeted Danish energy companies, reading device configurations and credentials. A second, more sophisticated wave beginning 22 May exploited two Zyxel zero-day vulnerabilities not patched until 24 May, and SektorCERT said attackers in this phase reached the industrial control systems of multiple companies. In total, 22 Danish energy-sector organizations were compromised across the two waves. Some operators deliberately disconnected from the wider grid and ran in island mode, generating and distributing power locally, as a precaution. SektorCERT described the campaign as the largest coordinated cyberattack on Danish critical infrastructure to date. The marker is placed at a national reference point since the affected companies were not individually named in the cited reporting.
1 sourceDetails +In a first wave on 11 May 2023, attackers exploited a critical command-injection vulnerability (CVE-2023-28771) in Zyxel firewalls to compromise 11 of 16 targeted Danish energy companies, reading device configurations and credentials. A second, more sophisticated wave beginning 22 May exploited two Zyxel zero-day vulnerabilities not patched until 24 May, and SektorCERT said attackers in this phase reached the industrial control systems of multiple companies. In total, 22 Danish energy-sector organizations were compromised across the two waves. Some operators deliberately disconnected from the wider grid and ran in island mode, generating and distributing power locally, as a precaution. SektorCERT described the campaign as the largest coordinated cyberattack on Danish critical infrastructure to date. The marker is placed at a national reference point since the affected companies were not individually named in the cited reporting.
Ukrainian high-voltage substations — Industroyer2 attempt
Ukraine (regional energy provider; sites undisclosed) · Power Grid · Europe
CERT-UA and ESET disrupted an attempted attack on high-voltage electrical substations of a Ukrainian regional energy provider using Industroyer2, an updated variant of the malware behind the 2016 Kyiv blackout, deployed alongside CaddyWiper and other destructive tools for Linux and Solaris systems. The malware was scheduled to cut power on 8 April 2022 during the Russian invasion and to wipe systems afterward to slow recovery. The targeted operator and substation locations were not disclosed, so the marker is a country-level reference. The attempt was largely mitigated before the planned detonation.
1 sourceDetails +CERT-UA and ESET disrupted an attempted attack on high-voltage electrical substations of a Ukrainian regional energy provider using Industroyer2, an updated variant of the malware behind the 2016 Kyiv blackout, deployed alongside CaddyWiper and other destructive tools for Linux and Solaris systems. The malware was scheduled to cut power on 8 April 2022 during the Russian invasion and to wipe systems afterward to slow recovery. The targeted operator and substation locations were not disclosed, so the marker is a country-level reference. The attempt was largely mitigated before the planned detonation.
Viasat KA-SAT / Enercon wind fleet — AcidRain wiper spillover
Germany (Enercon fleet); KA-SAT coverage across Europe · Power Grid · Europe
In the opening hour of Russia's invasion of Ukraine, a wiper later named AcidRain bricked tens of thousands of Viasat KA-SAT satellite modems across Europe. Spillover from the attack — aimed at Ukrainian communications — severed remote monitoring and control links to about 5,800 Enercon wind turbines in Germany, roughly 11 GW of capacity. The turbines kept generating in autonomous mode, but operators lost SCADA visibility, and restoring or replacing modems took weeks to months. The incident is a defining example of collateral cyber damage to energy infrastructure from an attack on a third-party communications provider. The marker is placed at Enercon's Aurich headquarters.
1 sourceDetails +In the opening hour of Russia's invasion of Ukraine, a wiper later named AcidRain bricked tens of thousands of Viasat KA-SAT satellite modems across Europe. Spillover from the attack — aimed at Ukrainian communications — severed remote monitoring and control links to about 5,800 Enercon wind turbines in Germany, roughly 11 GW of capacity. The turbines kept generating in autonomous mode, but operators lost SCADA visibility, and restoring or replacing modems took weeks to months. The incident is a defining example of collateral cyber damage to energy infrastructure from an attack on a third-party communications provider. The marker is placed at Enercon's Aurich headquarters.
Pipedream/Incontroller — ICS attack toolkit disclosure
United States (capability disclosure; LNG and electric targets reported) · Power Grid · Americas
DOE, CISA, NSA and the FBI jointly warned that state-linked actors had built a modular attack toolkit — called Pipedream by Dragos, which tracks the developer as Chernovite, and Incontroller by Mandiant — capable of scanning, compromising and controlling Schneider Electric and Omron PLCs and OPC UA servers, plus a Windows kernel exploit via a vulnerable ASRock driver. Reporting indicated the tools were positioned toward US LNG and electric targets but were discovered before being employed in a disruptive attack. No public attribution to a specific state has been made. This is a capability record rather than an executed attack; the marker is a country-level reference.
1 sourceDetails +DOE, CISA, NSA and the FBI jointly warned that state-linked actors had built a modular attack toolkit — called Pipedream by Dragos, which tracks the developer as Chernovite, and Incontroller by Mandiant — capable of scanning, compromising and controlling Schneider Electric and Omron PLCs and OPC UA servers, plus a Windows kernel exploit via a vulnerable ASRock driver. Reporting indicated the tools were positioned toward US LNG and electric targets but were discovered before being employed in a disruptive attack. No public attribution to a specific state has been made. This is a capability record rather than an executed attack; the marker is a country-level reference.
Lvivteploenergo district heating — FrostyGoop Modbus attack
Lviv, Ukraine · Power Grid · Europe
Attackers used FrostyGoop, the first known malware to disrupt operational technology by speaking Modbus TCP directly, against a municipal district-energy company serving Lviv. Malicious Modbus commands to ENCO controllers in heating substations produced false measurements and malfunctions, and the actors downgraded controller firmware to a version without monitoring, blinding operators. More than 600 apartment buildings lost heating and hot water for about two days in sub-zero January temperatures before manual recovery. Dragos, which analyzed the malware, did not formally attribute it; the attack occurred amid sustained Russian cyber and kinetic operations against Ukrainian energy. The marker is placed at Lviv.
1 sourceDetails +Attackers used FrostyGoop, the first known malware to disrupt operational technology by speaking Modbus TCP directly, against a municipal district-energy company serving Lviv. Malicious Modbus commands to ENCO controllers in heating substations produced false measurements and malfunctions, and the actors downgraded controller firmware to a version without monitoring, blinding operators. More than 600 apartment buildings lost heating and hot water for about two days in sub-zero January temperatures before manual recovery. Dragos, which analyzed the malware, did not formally attribute it; the attack occurred amid sustained Russian cyber and kinetic operations against Ukrainian energy. The marker is placed at Lviv.
US critical infrastructure — Volt Typhoon pre-positioning
United States (campaign; energy among targeted sectors) · Power Grid · Americas
US agencies assessed that PRC state-sponsored actors tracked as Volt Typhoon compromised IT networks of US critical-infrastructure organizations — including energy, communications, transportation and water — and maintained access in some environments for at least five years, using living-off-the-land techniques and valid accounts to evade detection. The stated concern is pre-positioning for disruptive or destructive attacks against operational technology in a crisis or conflict, rather than espionage alone. No disruption of energy operations has been publicly confirmed. This is a campaign record; the marker is a country-level reference, not a facility.
1 sourceDetails +US agencies assessed that PRC state-sponsored actors tracked as Volt Typhoon compromised IT networks of US critical-infrastructure organizations — including energy, communications, transportation and water — and maintained access in some environments for at least five years, using living-off-the-land techniques and valid accounts to evade detection. The stated concern is pre-positioning for disruptive or destructive attacks against operational technology in a crisis or conflict, rather than espionage alone. No disruption of energy operations has been publicly confirmed. This is a campaign record; the marker is a country-level reference, not a facility.
Polish wind, solar and CHP sites — coordinated wiper attack
Poland (30+ wind and photovoltaic farms; CHP plant serving ~500,000) · Power Grid · Europe
Coordinated intrusions hit more than 30 wind and photovoltaic farms, a large combined heat and power plant supplying heat to nearly half a million customers, and a manufacturing company across Poland. Attackers entered through internet-exposed FortiGate VPN and firewall devices — many without multi-factor authentication and running unpatched firmware — reused credentials, moved laterally, and deployed destructive wiper malware tracked as DynoWiper and LazyWiper against industrial systems. CERT Polska reported that detonation attempts largely failed and no interruption of electricity or heat supply occurred, though communications and monitoring at multiple sites were disrupted. The incident is regarded as the most serious attack on Polish energy infrastructure to date and highlighted the exposure of distributed renewable assets. The marker is a country-level reference.
1 sourceDetails +Coordinated intrusions hit more than 30 wind and photovoltaic farms, a large combined heat and power plant supplying heat to nearly half a million customers, and a manufacturing company across Poland. Attackers entered through internet-exposed FortiGate VPN and firewall devices — many without multi-factor authentication and running unpatched firmware — reused credentials, moved laterally, and deployed destructive wiper malware tracked as DynoWiper and LazyWiper against industrial systems. CERT Polska reported that detonation attempts largely failed and no interruption of electricity or heat supply occurred, though communications and monitoring at multiple sites were disrupted. The incident is regarded as the most serious attack on Polish energy infrastructure to date and highlighted the exposure of distributed renewable assets. The marker is a country-level reference.
Unidentified Polish CHP plant — private-APN cyber-physical disruption
Poland (facility withheld; country-level marker) · Power Station · Europe
CERT Polska's follow-up report described a destructive intrusion into a smaller Polish combined heat and power plant serving roughly 50,000 residents during the wider 29 December 2025 energy-sector campaign. The attacker first compromised infrastructure at a separate wind farm, reached a Teltonika router attached to a private cellular APN that allowed client-to-client communication, scanned that network and pivoted through a WAGO PFC200 controller whose web interface retained default administrator credentials. After reconnaissance on 25 December, the attacker reportedly placed Siemens S7-300, S7-1200 and S7-1500 controllers into STOP mode and password-protected them on 29 December, stopping a steam turbine and the plant's process-water treatment system. Moxa serial servers and switches were also reset or made unreachable. No bespoke malware was required because legitimate device functions and existing industrial protocols were abused. Operators initially mistook the interruption for contractor error during maintenance. Customers reportedly lost neither heat nor electricity. The plant and its location were withheld, so the marker is a country-level reference. This is kept separate from the larger CHP plant serving nearly 500,000 customers, where CERT Polska said endpoint protection blocked the attempted wiper deployment; the reviewed follow-up reporting links both to the broader campaign but does not provide a public facility identity or an independently adjudicated attribution for this smaller plant.
3 sourcesDetails +Reported impactSteam turbine and process-water treatment controls stopped; no customer loss of heat or electricity reportedCERT Polska's follow-up report described a destructive intrusion into a smaller Polish combined heat and power plant serving roughly 50,000 residents during the wider 29 December 2025 energy-sector campaign. The attacker first compromised infrastructure at a separate wind farm, reached a Teltonika router attached to a private cellular APN that allowed client-to-client communication, scanned that network and pivoted through a WAGO PFC200 controller whose web interface retained default administrator credentials. After reconnaissance on 25 December, the attacker reportedly placed Siemens S7-300, S7-1200 and S7-1500 controllers into STOP mode and password-protected them on 29 December, stopping a steam turbine and the plant's process-water treatment system. Moxa serial servers and switches were also reset or made unreachable. No bespoke malware was required because legitimate device functions and existing industrial protocols were abused. Operators initially mistook the interruption for contractor error during maintenance. Customers reportedly lost neither heat nor electricity. The plant and its location were withheld, so the marker is a country-level reference. This is kept separate from the larger CHP plant serving nearly 500,000 customers, where CERT Polska said endpoint protection blocked the attempted wiper deployment; the reviewed follow-up reporting links both to the broader campaign but does not provide a public facility identity or an independently adjudicated attribution for this smaller plant.
Municipal Water Authority of Aliquippa — Unitronics PLC compromise
Aliquippa, Pennsylvania, United States (wider campaign across multiple states) · Power Grid · Americas
Actors operating as CyberAv3ngers compromised a Unitronics Vision series programmable logic controller at a booster station of the Municipal Water Authority of Aliquippa, taking the station out of automatic control and defacing the operator screen with a political message stating that Israeli-made equipment was a target. Entry required no sophisticated exploit — the devices were exposed to the internet on their default programming port with default or weak passwords, including the factory default '1111'. CISA, the FBI, NSA, EPA and Israel's INCD issued joint advisory AA23-335A after confirming further Unitronics compromises across US water and wastewater facilities in multiple states. Water utilities are outside this map's usual scope; the record is kept because the same actor, tooling and exposure pattern reappear in the 2026 campaign against US energy and water control systems. The marker is placed at Aliquippa.
1 sourceDetails +Actors operating as CyberAv3ngers compromised a Unitronics Vision series programmable logic controller at a booster station of the Municipal Water Authority of Aliquippa, taking the station out of automatic control and defacing the operator screen with a political message stating that Israeli-made equipment was a target. Entry required no sophisticated exploit — the devices were exposed to the internet on their default programming port with default or weak passwords, including the factory default '1111'. CISA, the FBI, NSA, EPA and Israel's INCD issued joint advisory AA23-335A after confirming further Unitronics compromises across US water and wastewater facilities in multiple states. Water utilities are outside this map's usual scope; the record is kept because the same actor, tooling and exposure pattern reappear in the 2026 campaign against US energy and water control systems. The marker is placed at Aliquippa.
Halliburton — RansomHub ransomware
United States (Houston, Texas headquarters) · Oil or fuel facility · Americas
Halliburton, one of the world's largest oilfield services companies, detected unauthorized access to its corporate IT systems and proactively took certain applications offline, including production-planning and shipment-tracking systems used in customer service delivery. The company disclosed the incident to the SEC on 23 August 2024 and later confirmed data had been exfiltrated. Halliburton reported roughly $35 million in expenses and lost or delayed revenue, about $0.02 per share, while stating the incident was not reasonably likely to have a material impact on its financial condition. The compromise affected corporate IT rather than operational technology at wellsites, and no disruption to physical energy production was reported. The marker is placed at the company's Houston headquarters.
1 sourceDetails +Halliburton, one of the world's largest oilfield services companies, detected unauthorized access to its corporate IT systems and proactively took certain applications offline, including production-planning and shipment-tracking systems used in customer service delivery. The company disclosed the incident to the SEC on 23 August 2024 and later confirmed data had been exfiltrated. Halliburton reported roughly $35 million in expenses and lost or delayed revenue, about $0.02 per share, while stating the incident was not reasonably likely to have a material impact on its financial condition. The compromise affected corporate IT rather than operational technology at wellsites, and no disruption to physical energy production was reported. The marker is placed at the company's Houston headquarters.
Swedish thermal heating plant — attempted destructive OT attack
Sweden (facility not publicly identified) · Power Grid · Europe
Swedish authorities disclosed that a pro-Russian group attempted a destructive intrusion into the operational technology systems of a thermal plant supplying heating, intending to disrupt its operation. The attempt failed because of protections built into the facility, and no loss of heat supply occurred. Swedish officials framed the case as a shift by pro-Russian actors from distributed denial-of-service nuisance attacks toward attempted physical disruption of energy infrastructure, part of a broader wave of activity against European critical infrastructure. The facility was not publicly identified, so the marker is a country-level reference rather than a site location.
1 sourceDetails +Swedish authorities disclosed that a pro-Russian group attempted a destructive intrusion into the operational technology systems of a thermal plant supplying heating, intending to disrupt its operation. The attempt failed because of protections built into the facility, and no loss of heat supply occurred. Swedish officials framed the case as a shift by pro-Russian actors from distributed denial-of-service nuisance attacks toward attempted physical disruption of energy infrastructure, part of a broader wave of activity against European critical infrastructure. The facility was not publicly identified, so the marker is a country-level reference rather than a site location.
Risevatnet dam — cyberattack opens discharge valve
Bremanger, Vestland, Norway (approximate location) · Power Grid · Europe
Attackers obtained remote access to an operational-technology control panel at a dam by Lake Risevatnet, changed its settings and left a discharge valve fully open for about four hours. Norwegian authorities reported a flow of roughly 500 litres per second before the manipulation was detected and stopped. NSM said the event had apparently limited physical and economic consequences, while PST attributed it to a pro-Russian hacktivist group. The dam supplies water to a fish-farming facility; public reporting often called it a hydropower dam, but the reviewed official material does not establish that the affected system generated electricity. The marker is approximate.
1 sourceDetails +Reported impactValve fully open for about four hours; approximately 500 litres per second released, with limited physical and economic consequencesAttackers obtained remote access to an operational-technology control panel at a dam by Lake Risevatnet, changed its settings and left a discharge valve fully open for about four hours. Norwegian authorities reported a flow of roughly 500 litres per second before the manipulation was detected and stopped. NSM said the event had apparently limited physical and economic consequences, while PST attributed it to a pro-Russian hacktivist group. The dam supplies water to a fish-farming facility; public reporting often called it a hydropower dam, but the reviewed official material does not establish that the affected system generated electricity. The marker is approximate.
Tureby–Alkestrup waterworks — cyberattack bursts distribution pipes
Tureby, Køge Municipality, Denmark (approximate location) · Power Grid · Europe
Pro-Russian cyber actors manipulated operational controls at the small Tureby–Alkestrup drinking-water utility, changing network pressure and causing pipes to burst. Denmark's cyber-security authority reported that about 450 households briefly lost water because of low pressure and around 50 were without water for several hours after increased pressure ruptured a pipe. In December 2025, Denmark's Defence Intelligence Service attributed the destructive attack to Z-Pentest, assessed the group as linked to the Russian state, and described it as an instrument of Russia's hybrid campaign against Western countries supporting Ukraine. The marker is approximate.
1 sourceDetails +Reported impactAbout 450 households briefly lost water; roughly 50 remained without supply for several hours after a pipe burstPro-Russian cyber actors manipulated operational controls at the small Tureby–Alkestrup drinking-water utility, changing network pressure and causing pipes to burst. Denmark's cyber-security authority reported that about 450 households briefly lost water because of low pressure and around 50 were without water for several hours after increased pressure ruptured a pipe. In December 2025, Denmark's Defence Intelligence Service attributed the destructive attack to Z-Pentest, assessed the group as linked to the Russian state, and described it as an instrument of Russia's hybrid campaign against Western countries supporting Ukraine. The marker is approximate.
Colonial Pipeline — ransomware attack and shutdown
Southeastern United States (pipeline system originating in Houston, Texas) · Pipeline · Americas
The DarkSide criminal group compromised Colonial Pipeline's IT systems using stolen VPN credentials, prompting the company to proactively shut down its entire fuel pipeline network — the largest refined-products pipeline in the US, supplying roughly 45% of East Coast fuel — as a precaution, though operational control systems were not directly compromised. The shutdown triggered panic buying and localised fuel shortages across the southeastern US; Colonial paid DarkSide a $4.4 million ransom and restarted the pipeline on 13 May. CISA and the FBI issued a joint advisory on the DarkSide ransomware-as-a-service variant.
1 sourceDetails +Reported impact≈45% of East Coast refined-fuel supply disrupted for about a weekThe DarkSide criminal group compromised Colonial Pipeline's IT systems using stolen VPN credentials, prompting the company to proactively shut down its entire fuel pipeline network — the largest refined-products pipeline in the US, supplying roughly 45% of East Coast fuel — as a precaution, though operational control systems were not directly compromised. The shutdown triggered panic buying and localised fuel shortages across the southeastern US; Colonial paid DarkSide a $4.4 million ransom and restarted the pipeline on 13 May. CISA and the FBI issued a joint advisory on the DarkSide ransomware-as-a-service variant.
Oiltanking Deutschland fuel-loading systems
Germany, primarily northern Germany · Oil or fuel facility · Europe
A ransomware attack disrupted Oiltanking Deutschland's automated fuel-loading systems, forcing terminal operators to use manual processes and alternative loading points. Supplies to roughly 200 petrol stations, primarily in northern Germany, were disrupted, while Shell rerouted deliveries from other depots. This aggregate marker is placed at Hamburg as a regional reference and does not represent a single attacked petrol station.
1 sourceDetails +A ransomware attack disrupted Oiltanking Deutschland's automated fuel-loading systems, forcing terminal operators to use manual processes and alternative loading points. Supplies to roughly 200 petrol stations, primarily in northern Germany, were disrupted, while Shell rerouted deliveries from other depots. This aggregate marker is placed at Hamburg as a regional reference and does not represent a single attacked petrol station.
Oiltanking Deutschland — ransomware attack on fuel-loading systems
Germany (Hamburg-area terminals affected) · Oil or fuel facility · Europe
A ransomware attack disrupted Oiltanking Deutschland's automated fuel-loading systems at its German terminals, forcing a switch to manual loading and rerouting to alternative depots; supplies to roughly 200 petrol stations were disrupted as a result. The attack coincided with similar disruption at Belgian terminal operators (SEA-Invest and Evos) during the same window. The identity of the attacker was not established in the cited reporting.
1 sourceDetails +A ransomware attack disrupted Oiltanking Deutschland's automated fuel-loading systems at its German terminals, forcing a switch to manual loading and rerouting to alternative depots; supplies to roughly 200 petrol stations were disrupted as a result. The attack coincided with similar disruption at Belgian terminal operators (SEA-Invest and Evos) during the same window. The identity of the attacker was not established in the cited reporting.
Shell — Clop ransomware group claims data-theft attack
The Hague / global operations, Netherlands · Oil or fuel facility · Europe
The Russia-linked Clop ransomware/extortion group claimed on its dark-web leak site to have stolen data from Shell (along with Philips and other companies), reportedly around 89 gigabytes of Shell material including technical drawings, images of company facilities, test-report scans and project plans, according to the dark-web-monitoring platform GalaxyWarden. Shell said it was 'aware of a potential incident' and that its security teams and outside experts were investigating; the company did not confirm a breach, data loss or any operational impact on refining, production or grid-connected assets. Clop is a known extortion group that typically exfiltrates data rather than deploying disruptive ransomware, and its leak-site claims have not always been independently verified in past incidents. No impact on Shell's physical energy infrastructure or operations was reported, so this is recorded as an unconfirmed corporate data-theft claim rather than a documented breach.
2 sourcesDetails +Reported impactClop claims ~89 GB of Shell data stolen; Shell confirms only that it is investigatingThe Russia-linked Clop ransomware/extortion group claimed on its dark-web leak site to have stolen data from Shell (along with Philips and other companies), reportedly around 89 gigabytes of Shell material including technical drawings, images of company facilities, test-report scans and project plans, according to the dark-web-monitoring platform GalaxyWarden. Shell said it was 'aware of a potential incident' and that its security teams and outside experts were investigating; the company did not confirm a breach, data loss or any operational impact on refining, production or grid-connected assets. Clop is a known extortion group that typically exfiltrates data rather than deploying disruptive ransomware, and its leak-site claims have not always been independently verified in past incidents. No impact on Shell's physical energy infrastructure or operations was reported, so this is recorded as an unconfirmed corporate data-theft claim rather than a documented breach.
Smart Energies (France) — Qilin ransomware group claims data-theft attack
Paris, France · Power Grid · Europe
The Qilin ransomware/extortion group listed Smart Energies, a Paris-based developer and operator of solar, hydroelectric and biogas power plants across Europe and Africa, among five new victims added to its dark-web leak site around 18–19 August 2026 (alongside Philippe Hottinguer Group, InVentry, W.I.S. Logistics and Medochemie). The listing was reported by the ransomware-tracking outlet RedPacket Security and by the monitoring account FalconFeeds. No technical detail, data sample, ransom amount or confirmation from Smart Energies itself was available at the time of this entry, and there is no indication of any operational impact on the company's generation assets. Qilin leak-site claims are self-reported by the extortion group and have not always proven accurate or complete in past cases, so this is recorded as an unconfirmed corporate data-theft claim rather than a documented breach.
2 sourcesDetails +Reported impactQilin lists Smart Energies among 5 new leak-site victims; company has not confirmedThe Qilin ransomware/extortion group listed Smart Energies, a Paris-based developer and operator of solar, hydroelectric and biogas power plants across Europe and Africa, among five new victims added to its dark-web leak site around 18–19 August 2026 (alongside Philippe Hottinguer Group, InVentry, W.I.S. Logistics and Medochemie). The listing was reported by the ransomware-tracking outlet RedPacket Security and by the monitoring account FalconFeeds. No technical detail, data sample, ransom amount or confirmation from Smart Energies itself was available at the time of this entry, and there is no indication of any operational impact on the company's generation assets. Qilin leak-site claims are self-reported by the extortion group and have not always proven accurate or complete in past cases, so this is recorded as an unconfirmed corporate data-theft claim rather than a documented breach.
Quaker State Mexico — Qilin ransomware group claims data-theft attack
Naucalpan de Juárez, State of Mexico, Mexico (corporate marker) · Oil or fuel facility · Americas
The Qilin ransomware/extortion group listed Quaker State Mexico among victims added to its dark-web leak site on 21 August. Independent ransomware indexes captured the listing, but the company had not acknowledged a breach and no public technical evidence, stolen-data sample, ransom demand or operational disruption was available when this record was added. Quaker State Mexico produces and distributes automotive and industrial lubricants and is associated with Shell-branded lubricant operations in Mexico; this corporate marker does not identify a compromised plant or assert an attack on operational technology. Because the only evidence is the extortion group's own claim as relayed by monitoring services, the event is recorded as an unconfirmed data-theft claim rather than a documented ransomware incident.
2 sourcesDetails +Reported impactNo interruption to lubricant manufacturing, distribution or other physical operations was reported.The Qilin ransomware/extortion group listed Quaker State Mexico among victims added to its dark-web leak site on 21 August. Independent ransomware indexes captured the listing, but the company had not acknowledged a breach and no public technical evidence, stolen-data sample, ransom demand or operational disruption was available when this record was added. Quaker State Mexico produces and distributes automotive and industrial lubricants and is associated with Shell-branded lubricant operations in Mexico; this corporate marker does not identify a compromised plant or assert an attack on operational technology. Because the only evidence is the extortion group's own claim as relayed by monitoring services, the event is recorded as an unconfirmed data-theft claim rather than a documented ransomware incident.
EVNHANOI — Emperador ransomware group claims customer-data theft
Hanoi, Vietnam (corporate marker; no affected facility identified) · Power Grid · Asia
The Emperador ransomware/extortion group listed Hanoi Power Corporation (EVNHANOI), the Hanoi distribution subsidiary of state-owned Vietnam Electricity, and claimed to have stolen more than 300 GB of customer, subscription and account data. Ransomware monitors captured the listing, but no statement from EVNHANOI, EVN, a Vietnamese regulator or a national cyber authority confirmed the intrusion, data volume or record counts. No encryption, operational-technology access, grid-control impact or electricity outage was reported. The claim applies to the Hanoi distribution subsidiary, not EVN's nationwide generation and transmission systems; the corporate marker must not be read as evidence of national-grid compromise.
3 sourcesDetails +Reported impactNo interruption to Hanoi electricity distribution, grid control or other operational systems was reported.The Emperador ransomware/extortion group listed Hanoi Power Corporation (EVNHANOI), the Hanoi distribution subsidiary of state-owned Vietnam Electricity, and claimed to have stolen more than 300 GB of customer, subscription and account data. Ransomware monitors captured the listing, but no statement from EVNHANOI, EVN, a Vietnamese regulator or a national cyber authority confirmed the intrusion, data volume or record counts. No encryption, operational-technology access, grid-control impact or electricity outage was reported. The claim applies to the Hanoi distribution subsidiary, not EVN's nationwide generation and transmission systems; the corporate marker must not be read as evidence of national-grid compromise.
Shell — Cl0p ransomware group claims data-theft attack via PTC Windchill exploit
London, United Kingdom (corporate marker; no refinery or facility identified) · Oil or fuel facility · Europe
The Cl0p ransomware/extortion group listed Shell among dozens of victims (reports cite 43 to more than 50 organizations, including GE and Philips) added to its dark-web leak site in mid-August, tied to exploitation of a since-patched vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM product-lifecycle-management software. For Shell specifically, Cl0p claimed roughly 89 GB of data, allegedly including engineering drawings, facility photographs, project roadmaps and testing reports. Shell said it was investigating with its security teams and stated it had found no evidence of disruption to its refining, drilling or core IT operations; GE said it was assessing the claim. Neither company confirmed the intrusion, the data volume or its authenticity. This record documents an alleged corporate data-theft claim, not a confirmed breach or any refinery or operational-technology compromise, and is unrelated to Cl0p's separate 2025 Oracle E-Business Suite extortion campaign.
3 sourcesDetails +Reported impactNo interruption to Shell's refining, drilling or core IT operations was reported.The Cl0p ransomware/extortion group listed Shell among dozens of victims (reports cite 43 to more than 50 organizations, including GE and Philips) added to its dark-web leak site in mid-August, tied to exploitation of a since-patched vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM product-lifecycle-management software. For Shell specifically, Cl0p claimed roughly 89 GB of data, allegedly including engineering drawings, facility photographs, project roadmaps and testing reports. Shell said it was investigating with its security teams and stated it had found no evidence of disruption to its refining, drilling or core IT operations; GE said it was assessing the claim. Neither company confirmed the intrusion, the data volume or its authenticity. This record documents an alleged corporate data-theft claim, not a confirmed breach or any refinery or operational-technology compromise, and is unrelated to Cl0p's separate 2025 Oracle E-Business Suite extortion campaign.
CRI Electric — Rhysida ransomware leak-site claim
Anaheim, California, United States (corporate marker) · Power Grid · Americas
The Rhysida ransomware group listed CRI Electric as a victim on its criminal leak site. Secondary reporting described data theft and encryption, but did not publish victim-supplied confirmation, forensic evidence, affected-data detail or a verified incident date. CRI Electric is an Anaheim-based commercial and industrial electrical contractor rather than a grid operator. No evidence reviewed linked the claim to a power plant, utility control system or customer-site outage, so this is an unconfirmed corporate IT claim represented by a headquarters marker.
2 sourcesDetails +Reported impactNo outage or disruption to client electrical systems, backup generation or industrial power distribution was reported.The Rhysida ransomware group listed CRI Electric as a victim on its criminal leak site. Secondary reporting described data theft and encryption, but did not publish victim-supplied confirmation, forensic evidence, affected-data detail or a verified incident date. CRI Electric is an Anaheim-based commercial and industrial electrical contractor rather than a grid operator. No evidence reviewed linked the claim to a power plant, utility control system or customer-site outage, so this is an unconfirmed corporate IT claim represented by a headquarters marker.
AmSpec — Qilin ransomware group claims internal-file theft
Cranbury, New Jersey, United States (headquarters marker; global operations) · Oil or fuel facility · Americas
Qilin listed AmSpec on its ransomware leak site and claimed to have exfiltrated internal files, reportedly publishing a sample as proof. The available reporting did not identify the data volume, intrusion vector, encryption scope or number of affected people, and AmSpec had not issued public confirmation. AmSpec provides inspection, testing and certification services across petroleum, chemical, gas and other commodity supply chains, but no operational impact on those services or on any client terminal, refinery or energy asset was reported. This is therefore an unconfirmed corporate data-extortion claim, not a documented attack on physical energy infrastructure.
2 sourcesDetails +Reported impactNo disruption to AmSpec inspection, testing or certification services, or to customer energy facilities, was reported.Qilin listed AmSpec on its ransomware leak site and claimed to have exfiltrated internal files, reportedly publishing a sample as proof. The available reporting did not identify the data volume, intrusion vector, encryption scope or number of affected people, and AmSpec had not issued public confirmation. AmSpec provides inspection, testing and certification services across petroleum, chemical, gas and other commodity supply chains, but no operational impact on those services or on any client terminal, refinery or energy asset was reported. This is therefore an unconfirmed corporate data-extortion claim, not a documented attack on physical energy infrastructure.
Weber Water Resources — Metaencryptor ransomware leak-site claim
Mesa, Arizona, United States (corporate marker; multi-state operations) · Power Grid · Americas
Metaencryptor listed Weber Water Resources on its ransomware leak site. Public reporting did not identify the alleged data types, volume, intrusion method, affected systems or number of people involved, and the company had not acknowledged a breach. Weber Water Resources provides water-well drilling, pump services, SCADA and electrical work, and water-production-facility construction for public and private clients. Nothing reviewed showed access to a client's operational systems or any interruption to water supply, so this headquarters marker records only an unconfirmed corporate extortion claim.
2 sourcesDetails +Reported impactNo disruption to water wells, pumps, SCADA work or municipal water production was reported.Metaencryptor listed Weber Water Resources on its ransomware leak site. Public reporting did not identify the alleged data types, volume, intrusion method, affected systems or number of people involved, and the company had not acknowledged a breach. Weber Water Resources provides water-well drilling, pump services, SCADA and electrical work, and water-production-facility construction for public and private clients. Nothing reviewed showed access to a client's operational systems or any interruption to water supply, so this headquarters marker records only an unconfirmed corporate extortion claim.
Ariel Energia — TheGentlemen ransomware leak-site claim
Turin, Italy (corporate marker) · Power Grid · Europe
TheGentlemen ransomware group listed Ariel Energia on its criminal leak site on 21 August. The available aggregator record did not independently verify stolen data, encryption, initial access or the date of compromise, and no victim statement was located. Ariel Energia sells and installs domestic heating, cooling, pellet-stove and photovoltaic products; it is not an electricity network operator. No evidence reviewed showed disruption to customer installations or other physical energy systems, so this is an unconfirmed corporate IT/extortion claim represented at the company's Turin address.
2 sourcesDetails +Reported impactNo interruption to product sales, installations, service operations or customer energy systems was reported.TheGentlemen ransomware group listed Ariel Energia on its criminal leak site on 21 August. The available aggregator record did not independently verify stolen data, encryption, initial access or the date of compromise, and no victim statement was located. Ariel Energia sells and installs domestic heating, cooling, pellet-stove and photovoltaic products; it is not an electricity network operator. No evidence reviewed showed disruption to customer installations or other physical energy systems, so this is an unconfirmed corporate IT/extortion claim represented at the company's Turin address.
Alto Calore Servizi — Titan ransomware leak-site claim
Avellino, Campania, Italy (utility headquarters marker) · Power Grid · Europe
Titan listed Alto Calore Servizi on its leak site and threatened to publish a full data leak unless the company contacted the group. The listing did not establish what data was taken, whether systems were encrypted, how access was obtained or when an intrusion occurred, and no confirmation from the utility or an Italian authority was located. Alto Calore Servizi manages drinking-water capture, conveyance and distribution for 125 municipalities in Avellino and Benevento provinces. The company's public notices showed ordinary weather, supply and equipment-related interruptions around the period but did not attribute a service outage to cyber activity. This is recorded as an unconfirmed data-extortion claim, not an operational water-infrastructure incident.
2 sourcesDetails +Reported impactNo cyber-related interruption to drinking-water capture, conveyance or distribution was reported.Titan listed Alto Calore Servizi on its leak site and threatened to publish a full data leak unless the company contacted the group. The listing did not establish what data was taken, whether systems were encrypted, how access was obtained or when an intrusion occurred, and no confirmation from the utility or an Italian authority was located. Alto Calore Servizi manages drinking-water capture, conveyance and distribution for 125 municipalities in Avellino and Benevento provinces. The company's public notices showed ordinary weather, supply and equipment-related interruptions around the period but did not attribute a service outage to cyber activity. This is recorded as an unconfirmed data-extortion claim, not an operational water-infrastructure incident.
Siemens S7-series PLCs — AI-generated exploitation-script threat advisory
United States (nationwide advisory; internet-exposed Siemens S7 PLCs) · Power Grid · Americas
The NSA, CISA, FBI, Department of Energy and EPA issued joint advisory AA26-231A on 19 August 2026, warning of an active threat campaign using AI-generated exploitation scripts — disguised as legitimate monitoring tools — against internet-exposed Siemens S7-series programmable logic controllers running outdated software. The agencies said attackers used internet-scanning services to locate vulnerable, internet-facing PLCs before deploying the AI-written scripts, and characterised the threat as active rather than theoretical, with the potential to disrupt industrial processes, trigger safety incidents or expose sensitive operational data. Affected sectors named in the advisory include water, food, energy, chemical, manufacturing and commercial facilities. The advisory is distinct from, but related to, the CyberAv3ngers/Iran-affiliated PLC campaign documented in AA26-097A (7 April–22 July 2026): that campaign involved actors abusing vendor configuration software (Rockwell Studio 5000, Schneider EcoStruxure, Siemens TIA Portal) to exfiltrate and tamper with project files on Rockwell, Schneider and Siemens equipment, whereas AA26-231A describes a newer AI-assisted scanning-and-exploitation technique specifically against Siemens S7 devices, with no attacker attribution confirmed at the time of this entry. No specific facility, outage or safety incident tied to this AI-assisted campaign had been publicly confirmed when the advisory was issued.
3 sourcesDetails +Reported impactNSA, CISA, FBI, DOE and EPA joint advisory · AI-generated exploitation scripts targeting internet-exposed Siemens S7 PLCs · no confirmed attributionThe NSA, CISA, FBI, Department of Energy and EPA issued joint advisory AA26-231A on 19 August 2026, warning of an active threat campaign using AI-generated exploitation scripts — disguised as legitimate monitoring tools — against internet-exposed Siemens S7-series programmable logic controllers running outdated software. The agencies said attackers used internet-scanning services to locate vulnerable, internet-facing PLCs before deploying the AI-written scripts, and characterised the threat as active rather than theoretical, with the potential to disrupt industrial processes, trigger safety incidents or expose sensitive operational data. Affected sectors named in the advisory include water, food, energy, chemical, manufacturing and commercial facilities. The advisory is distinct from, but related to, the CyberAv3ngers/Iran-affiliated PLC campaign documented in AA26-097A (7 April–22 July 2026): that campaign involved actors abusing vendor configuration software (Rockwell Studio 5000, Schneider EcoStruxure, Siemens TIA Portal) to exfiltrate and tamper with project files on Rockwell, Schneider and Siemens equipment, whereas AA26-231A describes a newer AI-assisted scanning-and-exploitation technique specifically against Siemens S7 devices, with no attacker attribution confirmed at the time of this entry. No specific facility, outage or safety incident tied to this AI-assisted campaign had been publicly confirmed when the advisory was issued.
