Energy (Includes Power and Utilities)

Industry

DESFA, Greece’s Natural Gas Supplier, Suffers Cyberattack

August 19, 2022

Greece’s largest natural gas supplier, DESFA, said Saturday it fell victim to a cyberattack on part of its IT infrastructure by cybercriminals who tried to gain access to electronic files and with a confirmed impact on the availability of certain systems and possible leakage of a number of files and data.
Ragnar Locker ransomware group claimed them as its victim on Friday by leaking some of the DEFSA data.
“We managed to ensure and continue the operation of the National Natural Gas System (NSGS) in a safe and reliable manner,” the company said in an advisory. “The management of DESFA continues to operate smoothly and DESFA continues to supply natural gas to all entry and exit points of the country safely and adequately. We are investigating the root causes of the attack and have mobilized teams of technical and specialist experts to assist us in this matter and in getting the systems back up and running as soon as possible.”

read more

Blackcat / ALPHV Ransomware Attack Hits Luxembourg-based Critical Infrastructure Companies

July 22, 2022

A ransomware gang with direct ties to the group behind last year’s attack on Colonial Pipeline has struck again. This time hitting a Luxembourg-based critical infrastructure companies pipeline Creos and electricity operator Enovos. Encevo, the parent company of both business units, said data was exfiltrated during the attack between July 22 and 23, rendering the customer portals of Creos and Enovos non operational. The company said electricity and gas are still flowing to customers without interruption.

Threat actor ALPHV, also known as BlackCat, claimed responsibility for the attack on July 29 . In a post on a leak site, the group claims it exfiltrated 180,000 files totaling 150 gigabytes from Creos and threatened to publish the data. The group said the data includes contracts, agreements, passports, bills, and emails.

read more

Energy Supplier Entega’s Customer Data Posted on the Dark Web after Ultimatum Expired

June 12, 2022

Hacker attacks paralyzed the websites of the regional utility Entega and the municipal utility Stadtwerke Mainz. There is no fear of supply interruptions for private and commercial customers, as these systems are separately secured.

At the same time as Entega, the lights also went out on the Stadtwerke Mainz website. Both companies are managed by their joint subsidiary, the IT service provider Count+Care. The malware got into the system because an employee had accidentally opened an email attachment. Entega’s website and e-mail server were paralyzed as a result. The systems of the Darmstädter Bauverein and the Frankfurt utility company FES were also affected by the attack on Count+Care, an Entega subsidiary.

To repair the damage, the hackers apparently demanded a ransom of 15 million euros. Entega let the ultimatum expire without paying, and much of the customer data was leaked on the dark web. An Entega spokesman said the majority of customers could be affected, but to varying degrees. The investigation into the stolen data is still ongoing. According to Entega’s annual report, the number of customer contracts at the end of 2021 was almost 700,000.

According to information from the Frankfurter Rundschau, the hacker gang “Black Cat” is said to be behind the attacks. The newspaper relies on information from an insider. “Black Cat” was recently also responsible for attacks on the IT systems in the Austrian state of Carinthia , where they also demanded a ransom.

read more

German Wind Turbine Maker Enercon’s Services 90% Restored

February 24, 2022

German wind turbine maker, Enercon GmbH, is still restoring remote monitoring and maintenance capabilities for its turbines affected by a satellite outage at the end of February.
The company said over 90 percent of its 5,800 machines are online. The communication link has been restored for 1,156 wind parks in central Europe and service teams continue to work on the remaining 193 wind farms, the wind turbine manufacturer said Friday.
The remote monitoring and maintenance of the 5,800 machines with a combined output of more than 10 GW was affected by a satellite outage at Viasat on the same day as Russia invaded Ukraine. Viasat also had satellite operations going on in Ukraine and Enercon may have suffered as a part of being collateral damage in the attack.

read more

German Wind Turbine Maker Hit in Cyberattack

March 31, 2022

A cyberattack shut down a German wind turbine maker’s IT systems across multiple locations and business units March 31.
Nordex designs, sells and manufactures wind turbines, reporting just over $5.9 billion in sales last year. The company has factories in Germany, China, Mexico, United States, Brazil, Spain and India.
“On 31 March 2022 Nordex Group IT security detected that the company is subject to a cyber security incident,” the company said in an advisory. “The intrusion was noted in an early stage and response measures initiated immediately in line with crisis management protocols. As a precautionary measure, the company decided to shut down IT systems across multiple locations and business units.”

read more

Global IT Firm Recovering From Ransomware Attack

December 19, 2021

Global IT services company, Inetum Group, suffered a ransomware attack December 19, impacting operations in France.
While the global company suffered the hit in France, its operations were ongoing in other parts of the world. Among the multiple sectors the company works with are energy and utilities, aerospace, automotive, and chemicals and life sciences. The company said none of the main infrastructures, communication, collaboration tools or delivery operations for its clients ended up affected.

read more

German Nuke Infected with Malware

April 26, 2016

A nuclear power plant in Germany suffered from an infection of computer viruses, but they appear not to have posed a threat to the facility’s operations, the station’s operator said April 26.
The Gundremmingen plant, located about 120 km (75 miles) northwest of Munich, is run by the German utility RWE.
The viruses, which include W32.Ramnit and Conficker, ended up discovered at Gundremmingen’s B unit in a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods, RWE said. The operating system ended up saved because it was not connected to the Internet.
Malware was also on 18 removable data drives, mainly USB sticks, in office computers maintained separately from the plant’s operating systems. RWE said it increased cyber security measures as a result.

read more

FL Utility Suffers DDoS

February 17, 2013

The website of Jacksonville, FL-based JEA, a not-for-profit community-owned utility company that serves one million people, suffered a distributed denial-of-service (DDOS) attack.
The company notified customers the attack, which disrupted its website and its automatic phone system, started February 17, 2013.

read more

Poughkeepsie, NY, Utility Hacked

February 19, 2013

Hackers gained entry to as many as 110,000 customer accounts at Poughkeepsie, NY-based Central Hudson Gas and Electric.
Employees detected the computer system intrusion Feb. 20, 2013. The attack occurred over a weekend, and as a result of regular control procedures, employees found the attack and reported it, the utility said.

read more

CS Energy Hit In Ransomware Attack

November 27, 2021

The incident occurred Nov. 27 on CS Energy’s corporate network and did not have an impact on electricity generation at the Callide and Kogan Creek power stations, officials said. Those stations are continuing to generate and dispatch electricity into the National Electricity Market.

read more