Energy (Includes Power and Utilities)

Industry

Energy Exploration Firm Beusa Energy Hit in Cyberattack

July 24, 2025

The Woodlands, Texas-based private energy exploration company Beusa Energy, LLC, discovered a cyberattack this past May that occurred in July last year where personally identifiable information ended up stolen.
On May 20, 2026, Beusa Energy, LLC, a privately held oil and gas exploration and production company discovered an unauthorized party had accessed its computer network.
The company hired an outside cybersecurity provider to help conduct a forensic investigation and they found between July 24 and July 30, 2025, files containing personal information may have been accessed or copied.

read more

Energy Supplier, Eversource Energy Suffered Phishing Attack

April 14, 2026

Westwood, Massachusetts-based energy supplier, Eversource Energy suffered a phishing cyberattack in April where personally identifiable information ended up stolen in the hack.
“In April of 2026, Eversource was a victim of a cybercriminal phishing campaign that resulted in unauthorized use of the credentials of two employees to access a limited number of files, some of which contained customer information,” said a notice sent to victims of the attack. “Eversource immediately blocked activities by this hacker group and implemented additional security measures in response to this incident to further strengthen our cybersecurity systems.”
Eversource said it quickly started up an investigation with the assistance of external experts to review the data contained in the files accessed.

read more

Cyberattack at Utility Technology Provider, Itron

April 13, 2026

Liberty Lake, Washington-based utility technology provider, Itron Inc., suffered a cyberattack earlier this month and is continuing its investigation into the hack.
“On April 13, 2026, Itron, Inc. ended up notified that an unauthorized third party had gained access to certain of its systems,” the company said in an 8-K report to the Securities and Exchange Commission (SEC). “The company activated its cybersecurity response plan and launched an investigation with the support of external advisors to assess, mitigate, remediate, and contain the unauthorized activity.”
Additionally, the company’s response efforts included proactively notifying law enforcement.

read more

ICS/OT Cyberattack Disrupts Operations at Tczew Hydropower Plant, Poland

August 10, 2025

A small hydropower plant near Tczew (in northern Poland, close to Gdańsk) was successfully breached in a cyberattack that disrupted its industrial control systems (ICS/OT).The attack disrupted the hydropower plant’s control systems, causing erratic turbine behavior, sudden stoppages, and periods of zero power output as attackers manipulated operational parameters. Unlike an earlier attempted breach in May 2025 (when the plant was offline and unaffected), the August incident was significant because it interfered with a functioning energy facility. There were no reported widespread blackouts in Poland due to this attack.

read more

Cyberattacks on Poland’s Energy Infrastructure Successfully Prevented

December 29, 2025

On 29–30 December 2025, Poland’s energy sector came under a coordinated cyberattack targeting critical infrastructure, including combined‑heat‑and‑power (CHP) plants and systems controlling renewable energy generation such as wind and solar farms. The attackers sought to disrupt operational control systems, potentially affecting energy distribution, grid stability, and heating supply in key regions during winter.

Polish cybersecurity teams, energy operators, and government incident response units successfully repelled the attacks, preventing any blackouts or significant service interruptions. The incident required rapid isolation of affected control systems, verification of operational integrity, and enhanced monitoring of the national energy grid. Authorities noted that if the attack had been successful, it could have impacted hundreds of thousands of households and industrial facilities, demonstrating the high risk posed by cyber intrusions against energy ICS/OT systems.

Officials and cybersecurity analysts highlighted that the attack pattern and infrastructure targets suggest Russian‑linked actors, consistent with a series of hybrid warfare campaigns aimed at destabilizing critical infrastructure in Poland and Eastern Europe. The December attack underscored the vulnerability of energy networks to coordinated cyber operations, the importance of robust ICS/OT security, and the need for real-time threat detection and rapid incident response.

read more

Cybersecurity Breach Temporarily Halts IPEN Radioisotope Production

March 28, 2025

The Brazilian research Instituto de Pesquisas Energéticas e Nucleares (IPEN) in São Paulo suffered a cyberattack. IPEN/CNEN temporarily halted the production and supply of critical radioisotopes and radiofármacos, substances used across Brazil for medical diagnostics and cancer treatments. Production resumed in early April. Officials emphasized that the physical, radiological, and nuclear safety of the institute’s facilities was not compromised at any point.

read more

Ransomware Attack at Utility Solution Provider, Minsait ACS

March 26, 2025

Sandy Springs, Georgia-based IT-OT utility solution provider, Minsait ACS, Inc., suffered a ransomware in March and is now informing employee victims of the attack.
“On May 5, 2025, we discovered we were victimized by a sophisticated ransomware attack,” the company said in a letter to victims. “Upon discovery, we immediately began working with our IT team to secure the network, restore our systems to operability, and investigate the full nature and scope of the incident.
“Through the investigation, it was determined that certain Minsait data, kept in the normal course of business, may have been subject to unauthorized access during the attack,” the company said. The attack occurred March 26.

read more

Utility Productivity Provider Hit in Attack

July 11, 2025

Philadelphia, Pennsylvania-based Util-Assist Inc. suffered a cyberattack in July that had an “operational impact on a limited number of personnel and systems.”
“Util-Assist Inc. discovered the incident involving unauthorized access to its IT system.,” the company said in a notice to victims. “In response, Util-Assist immediately took measures to secure the IT system and launched an investigation.”
The investigation revealed an unauthorized actor accessed the system on July 11 where the attackers made off with personally identifiable information such as the victims’ name, Social Security number and bank account number used for direct deposit.

read more

Cyberattack at MA Utility

January 25, 2025

Ludlow, Massachusetts-based utility Massachusetts Municipal Wholesale Electric Company (MMWEC) suffered a ransomware attack where hackers stole personally identifiable information from victims.
“On February 2, 2025, MMWEC discovered suspicious activity in its environment. In response, MMWEC immediately took steps to secure its environment and launched an investigation to determine the nature and scope of the incident,” said a letter to victims of the incident. “The investigation determined that between January 25, 2025 and February 3, 2025, an unknown, unauthorized actor gained access to certain MMWEC computer systems and accessed and/or acquired certain files stored on these systems.
MMWEC said it quickly began a thorough review of the relevant files to identify individuals with personal information potentially impacted. MMWEC completed this review on June 10.

read more

Mississippi Utility Suffers Cyberattack

October 23, 2024

Municipally owned and operated electric and water utility, Starkville Utilities, suffered from a cyberattack last October where threat actors were able to abscond with personally indefinable information from over 11,000 victims.
The Starkville, Mississippi-based utility discovered the attack October 23, 2024, when they noticed unauthorized activity within its computer network.
“Upon discovery of the incident, Starkville immediately disconnected all access to the network and promptly engaged a specialized third-party incident response firm to assist with securing the environment, as well as, to conduct a comprehensive forensic investigation to determine the nature and scope of the incident,” the company said in a letter to victims.

read more