Energy & Utilities — Cyber Threat Activity

Energy and utilities is the sector where our measured volume understates the risk by the widest margin. The log records more than 370 incidents across 62 countries, over 125 in the trailing 180 days, with 66 groups attributed at least one claim: Qilin (45), Akira (35), Play (29), RansomHub (24) and Hunters International (20) lead. Nearly all of that is enterprise-side extortion against generators, distributors, retailers and service providers, and almost none of it touches control systems. The activity that matters most produces no leak-site post at all. CISA, NSA and FBI assess that Chinese state actors have pre-positioned inside US energy and water networks for potential disruptive or destructive use rather than for espionage, moving to virtualisation infrastructure as a step toward operational assets and holding that access quietly using built-in system tools. Separately, IRGC-affiliated operators compromised internet-exposed Unitronics programmable logic controllers across water and energy targets, and pro-Russia hacktivist groups have reached VNC-exposed human-machine interfaces to alter setpoints and lock operators out of their own controls, which CISA notes they do without the engineering knowledge to predict the physical result. Our actor graph carries 137 groups associated with the sector once profile-level research is counted, and 194 malware families are linked through those actors. Recorded geography is United States-led at 147 claims, then Canada, Germany, the United Kingdom, Australia and Thailand. Read the incident totals as criminal claims and the state activity as the part you cannot see in them; for this sector the absence of an incident is not evidence of the absence of an intruder.

All sectors

Recent incidents

Threat actors targeting Energy & Utilities

Where these victims are

Malware used against Energy & Utilities

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions