Energy & Utilities — Cyber Threat Activity
Threat actors, incidents and malware targeting the Energy & Utilities sector — 377 recorded incidents and 127 tracked groups.
- Recorded incidents: 377
- Incidents, trailing 180 days: 125
- Tracked threat actors: 127
- Malware families: 194
Recent incidents
- EPM 2026-08-05
- NIMR Oil 2026-08-05
- Reid Electric Service, Inc 2026-08-05
- Oleoductos del Valle 2026-08-04
- Northeastern Communications & Electrical 2026-08-04
- Service Electric 2026-08-03
- Belasco Electric 2026-08-03
- OHK Energy 2026-07-31
- Okovolt Solartechnik 2026-07-31
- Pertamina 2026-07-31
- Rondout Electric 2026-07-30
- AguAseo 2026-07-30
- West African Resources ltd 2026-07-26
- Caspian One 2026-07-26
- West Nova Fuels & Superline Fuels 2026-07-26
- Sinop Energia 2026-07-26
- Novum Energy 2026-07-26
- Infinity Pipeline,Inc. 2026-07-26
- msgas.com.br 2026-07-25
- Enedo Power 2026-07-25
Threat actors targeting Energy & Utilities
- Qilin 42 incidents
- Akira 35 incidents
- Play Ransomware 29 incidents
- RansomHub 24 incidents
- Hunters International 20 incidents
- INC Ransom 17 incidents
- DragonForce 16 incidents
- Lynx Ransomware 15 incidents
- The Gentlemen 15 incidents
- LockBit 13 incidents
- Cl0p 11 incidents
- Handala 11 incidents
- Medusa Ransomware 7 incidents
- NightSpire 7 incidents
- SafePay 7 incidents
- ALPHV/BlackCat 6 incidents
- APT73 5 incidents
- BlackSuit 5 incidents
- Deadlock 5 incidents
- RansomHouse 5 incidents
- 8Base 4 incidents
- BianLian 4 incidents
- Everest 4 incidents
- Black Basta 3 incidents
Where these victims are
- United States 146
- Canada 25
- Germany 14
- United Kingdom 11
- Australia 9
- Brazil 8
- Colombia 8
- Thailand 8
- France 7
- Indonesia 7
- Mexico 6
- Spain 6
Malware used against Energy & Utilities
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- NotPetya Malware
- PlugX Malware
- PsExec Tool
- AsyncRAT Tool
- BlackEnergy Malware
- BloodHound Tool
- China Chopper Malware
- DarkComet Malware
Coverage. 76.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.