Energy (Includes Power and Utilities)

Industry

GSE, Italy’s Energy Services Firm, Temporarily Takes Portals Offline

August 29, 2022

Italy’s energy services firm GSE confirmed a hacking attack on its IT systems. GSE stated its gas purchases were not affected. The company added its website and portals were temporarily suspended to secure data.

The BlackCat ransomware group took credit for the attack on GSE, claiming to have stolen more than 700 GB of data from the agency.

read more

Attempted Cyberattacks at Nuclear Research Laboratories in US in Summer ’22.

June 21, 2022

A Russian hacking team known as Cold River targeted three nuclear research laboratories in the United States this past summer, according to internet records reviewed by Reuters and five cyber security experts.
Between August and September Cold River targeted the Brookhaven (BNL), Argonne (ANL) and Lawrence Livermore National Laboratories (LLNL), according to internet records that showed the hackers creating fake login pages for each institution and emailing nuclear scientists in a bid to make them reveal their passwords.

Reuters was unable to determine why the labs were targeted or if any attempted intrusion was successful. A BNL spokesperson declined to comment. LLNL did not respond to a request for comment. An ANL spokesperson referred questions to the U.S. Department of Energy, which declined to comment.

read more

Colombian Utility, EPM, Suffers Ransomware Attack

December 13, 2022

Colombian energy company Empresas Públicas de Medellín (EPM) suffered a BlackCat/ALPHV ransomware attack, which ended up affecting financial operations and taking down online services. EPM is one of Colombia’s largest public energy, water, and gas providers.

The company’s information was decrypted, affected the alternate Data Center and analyzed a 25% contagion. of the infrastructure; in addition, the additional loss of information is still being studied.

The company who provide services to 123 municipalities, closed its customer service offices and asked 4,000 employees to work from home as a preventative measure. The same day they indicated that “fortunately the provision of energy, water and gas services was not affected.” EPM provided alternative methods for customers to pay for services.

Reports claim that a sizeable amount of data was stolen and around 40 devices were compromised during the attack, but organization is yet to comment on these claims.

read more

German Energy System Supplier Hit by Ransonware Attack

November 21, 2021

On November 10-11, Kisters AG in Germany was hit by a ransomware attack. Kisters AG is a critical infrastructure supplier for energy systems with the potential for downstream compromise. The software provider, which specializes in the energy industry, has shut down the system “to prevent further damage”. Their website reports a new IT infrastructure was built. Close to normal operations was resumed by January 12, 2022.

read more

Cyberattack at Iranian Nuclear Power Plant

October 17, 2022

The Iranian Atomic Energy Organization (AEOI) has confirmed that one of its subsidiaries’ email servers was hacked after the ”Black Reward’ hacking group published stolen data online. AEOI says an unauthorized party from a specific foreign country, which is not named, stole emails from the hacked server, which consisted of daily correspondence and technical memos. The agency says it immediately took the necessary preventive measures to mitigate the results of this incident and informed all concerned parties and officials to be prepared for potential exploitation attempts.

The hacker group responsible for the attack calls itself ‘Black Reward’ and has leaked some of the stolen data on their Telegram channel. Black Reward posted a 27GB 14-part collection of RAR archives allegedly containing 85,000 email messages characterized as “perfect for researchers.” The hackers’ message is signed “For women, life, freedom,” giving the email server breach and data leak action the character of hacktivism.

read more

Major German Regional Energy Company Hit by Cyberattack

October 26, 2022

Enercity, one of Germany’s largest municipal energy suppliers, confirmed it was targeted by a cyberattack on Wednesday morning. The Hannover-based company said its security systems “reacted immediately” and that “greater damage to the company” has been averted. Enercity confirmed that it would continue supplying energy to customers, explaining its operational technology and critical infrastructure was not affected. “Our grids and power plants are stable and the security of supply is guaranteed,” the company stated. However the attack has impacted customer service, which has limited availability. The company added: “Not all IT systems can currently be used to their full extent, which means that they may be minor restrictions.”

read more

India’s Largest Integrated Power Company, Tata Power, Hit by Cyberattack

October 14, 2022

Tata Power, a leading power generation company in India, confirmed it was hit by a cyberattack. In a brief statement released on Friday, the Mumbai-based company said that the attack impacted some of its IT systems.
“The company has taken steps to retrieve and restore the systems. All critical operational systems are functioning. As a measure of abundant precaution, restricted access and preventive checks have been put in place for employee and customer-facing portals and touchpoints,”

read more

Cyberattack Source of Widespread Electricity Cuts Across Istanbul

December 30, 2016

Sources from the Energy Ministry claim that a major cyberattack is the source of the widespread electricity cuts across Istanbul in recent days, according to reports in the Turkish media. “Many infiltration attempts to the systems controlling our transmission and electricity producing lines were determined and prevented. The infiltration attempts are indicators of a major sabotage preparation against Turkey’s national electricity network,” a senior anonymous source said, as quoted by state-run Anadolu Agency. Energy Minister Berat Albayrak said a comprehensive investigation has been launched to figure out the real reasons behind the electricity cuts in a trip to the northwestern province of Kocaeli, which is the main center of the breakdowns.

read more

Lansing, MI, Public Utility Compromised by Attack, $25K Ransom paid.

April 25, 2016

The Board of Water and Light (BWL) in Lansing, Michigan, was struck by ransomware on Monday, April 25. 2016. The cyberattack shut down BWL’s accounting and email systems after an employee unknowingly opened an email with an infected attachment. This would seem to be the first disclosed example of a utility being successfully compromised by ransomware.

The Lansing Board of Water & Light paid a $25,000 ransom to unlock its internal communications systems after they were disabled by a cyberattack last spring, officials said Tuesday. BWL General Manager Dick Peffley pegged the cost of responding to the emergency, including the ransom and technology upgrades to prevent future attacks, at $2.4 million. All but $500,000 of those costs are covered by insurance. Paying the ransom was “the only action we could take to unlock our system and free it from the ransomware.”

read more