Energy & Utilities — Cyber Threat Activity
Energy and utilities is the sector where our measured volume understates the risk by the widest margin. The log records more than 370 incidents across 62 countries, over 125 in the trailing 180 days, with 66 groups attributed at least one claim: Qilin (45), Akira (35), Play (29), RansomHub (24) and Hunters International (20) lead. Nearly all of that is enterprise-side extortion against generators, distributors, retailers and service providers, and almost none of it touches control systems. The activity that matters most produces no leak-site post at all. CISA, NSA and FBI assess that Chinese state actors have pre-positioned inside US energy and water networks for potential disruptive or destructive use rather than for espionage, moving to virtualisation infrastructure as a step toward operational assets and holding that access quietly using built-in system tools. Separately, IRGC-affiliated operators compromised internet-exposed Unitronics programmable logic controllers across water and energy targets, and pro-Russia hacktivist groups have reached VNC-exposed human-machine interfaces to alter setpoints and lock operators out of their own controls, which CISA notes they do without the engineering knowledge to predict the physical result. Our actor graph carries 137 groups associated with the sector once profile-level research is counted, and 194 malware families are linked through those actors. Recorded geography is United States-led at 147 claims, then Canada, Germany, the United Kingdom, Australia and Thailand. Read the incident totals as criminal claims and the state activity as the part you cannot see in them; for this sector the absence of an incident is not evidence of the absence of an intruder.
- Recorded incidents: 460
- Incidents, trailing 180 days: 152
- Tracked threat actors: 150
- Malware families: 215
Recent incidents
- Siddhi Green Excellence Pvt. Ltd 2026-09-20
- HEOLIS 2026-09-19
- Inland and Offshore Contractors 2026-09-18
- Pertamina 2026-09-17
- ACA Pescara 2026-09-15
- BGR Energy Systems 2026-09-15
- Southern California Telephone Company 2026-09-15
- Goldston Oil Corporation 2026-09-10
- Brent Electric 2026-09-08
- Red Star Oil 2026-09-08
- S A Chile 2026-09-07
- Occidental 2026-09-04
- Engefitas 2026-09-03
- Petrocare Construction 2026-09-03
- Grayson Rural Electric Cooperative 2026-09-02
- PTT Oil and Retail Business 2026-09-02
- Allied Recycling 2026-08-31
- ESB Puerto Rico Corp 2026-08-30
- DistributionNOW (DNOW Inc.) 2026-08-30
- Oilquip Inc 2026-08-29
Threat actors targeting Energy & Utilities
- Qilin 62 incidents
- Akira 38 incidents
- Play Ransomware 32 incidents
- RansomHub 25 incidents
- The Gentlemen 23 incidents
- Hunters International 21 incidents
- INC Ransom 21 incidents
- DragonForce 19 incidents
- Cl0p 17 incidents
- LockBit 16 incidents
- Lynx Ransomware 15 incidents
- SafePay 9 incidents
- Handala 8 incidents
- Medusa Ransomware 7 incidents
- NightSpire 7 incidents
- RansomHouse 7 incidents
- ALPHV/BlackCat 6 incidents
- BlackSuit 6 incidents
- APT73 5 incidents
- Deadlock 5 incidents
- FunkSec 5 incidents
- Everest 4 incidents
- 8Base 4 incidents
- BianLian 4 incidents
Where these victims are
- United States 168
- Canada 29
- Germany 18
- United Kingdom 13
- Australia 11
- Brazil 10
- Indonesia 10
- Italy 10
- Thailand 10
- France 9
- Spain 8
- Colombia 7
Malware used against Energy & Utilities
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- BlackCat Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- NotPetya Malware
- PlugX Malware
- PsExec Tool
- Sliver Tool
- AcidRain Malware
- AsyncRAT Tool
- Babuk Malware
Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.