Energy (Includes Power and Utilities)

Industry

Energy Software Provider, Enverus Holdings Suffers Cyber Incident

August 12, 2025

Energy industry software services provider, Austin, Texas-based Enverus Holdings, Inc. fell victim to a third party provider cybersecurity attack in August where personally indentifiable information ended up stolen from victims.
On August 27, Enverus discovered it was one of hundreds of companies affected by the Salesloft Drift Chatbot cybersecurity incident.
“Upon discovery, Enverus activated its incident response plan, promptly disconnected the integration, and engaged cybersecurity experts to help assess the impact to Enverus,” the company said in a letter to victims.
“The investigation determined that, on August 12, 2025, an unauthorized actor leveraged credentials stolen from Salesloft to access a small amount of information from Enverus’s Salesforce instance,” the letter said.

read more

Cyberattack at SC Utility

June 26, 2025

Greer, South Carolina-based utility Greer Commission of Public Works suffered a cyberattack in June in which a threat actor copied information during the hack and stole personally identifiable information.
“On or about June 26, 2025, Greer CPW became aware of unusual activity in its network environment,” the company said in a letter to victims. “Upon becoming aware, Greer CPW promptly began an investigation into the scope and nature of the suspicious activity and retained legal counsel and third-party forensic specialists to investigate the unusual activity.”
The investigation found certain information ended up copied by an unauthorized individual as part of the event, the company said.

read more

Databreach at Swedish Power Grid Operator Svenska kraftnät

October 25, 2025

Swedish Electricity Provider (Svenska kraftnät) confirmed it suffered a data breach. The incident, disclosed on October 26, 2025, is linked to the notorious Everest ransomware gang. The organization maintains that Sweden’s power infrastructure continues to operate normally, with no disruptions to electricity transmission or distribution across the country. The Everest group alleged that it had stolen 280 GB of data from a file transfer solution.

read more

MA Energy Technology Firm Suffers Ransomware Attack

September 16, 2025

Somerville, Massachusetts-based energy technology firm, Form Energy, Inc., along with its subsidiaries Form Factory 1, LLC, and Form Energy Works, LLC, suffered a ransomware attack in September and is now informing victims.
The breach was the result of a ransomware attack, and the company has since taken action to investigate and address the issue.
“On September 16, 2025, Form Energy became aware of a ransomware attack on its systems,” the company said in a letter to victims. “In response, the company took immediate steps to secure affected systems by taking them offline and engaging external cybersecurity experts to assist with the investigation.”

read more

US Nuclear Weapons Agency Caught up in Microsoft SharePoint Attack

July 19, 2025

Hours after Microsoft revealed that hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg reported that the National Nuclear Security Administration was also breached in the attacks. No sensitive or classified information has leaked according to Bloomberg. “The department was minimally impacted due to its widespread use of the Microsoft M365 cloud. As well as very capable cybersecurity systems,” a department spokesperson said in a statement to Bloomberg. “A very small number of systems were impacted. All impacted systems are being restored.”

read more

Cyberattack hits Nova Scotia Power and Parent Co. Emera

April 25, 2025

Nova Scotia Power and its parent company Emera suffered a cyberattack in April. Unauthorized access to parts of their Canadian network and servers used for business applications was discovered. Nova Scotia Power said their investigation showed customers personal information was accessed and taken. “We are seeing a significant ramp up in utility impersonation fraud,” Shipley says. “Criminals trying to defraud individuals trying to look like Nova Scotia Power.”

The utility says there remains no disruption to any of its Canadian physical operations, including at Nova Scotia Power’s generation, transmission and disruption facilities, the Maritime Link or the Brunswick Pipeline. However, on a social media post Monday morning, Nova Scotia Power said it was experiencing a technical issue with their phone line and customers being able to access their accounts.

read more

Pennsylvania Lighthouse Electric Company Suffered Cyberattack

October 26, 2024

Canonsburg, Pennsylvania-based Lighthouse Electric Company suffered a cyberattack. “Our investigation determined that certain files on LEC’s network may have been copied without authorization between October 21, 2024, and October 26, 2024”. The company said it is continuing its review to enhance its existing safeguards, policies, and procedures.

read more

Utility Provider O’Connor Corporation Announces 2024 Cyberattack.

December 2, 2024

On December 2, the Power Generation Maintenance and Construction and Water and Wastewater provider, O’Connor observed a network disruption that affected the operability of certain systems. The Canton, Massachusetts-based company launched an investigation which was completed on January 2. They informed victims of the incident on February 2025: “The types of information relating to you that our review located in the accessible data included: Name, Social Security number, and financial account information,” the company said in the advisory.

read more

Mississippi Utility Company Confirms 2024 Security Breach Affected 20K Customers.

August 26, 2024

Mississippi Yazoo Valley Electric Power Association was attacked by cybercriminals last summer. The incident exposed the information of more than 20,000 residents.

The company initially warned customers through social media on August 26 that, due to software problems, they were unable to process payments. The system was restored by August 30. In breach notification letters filed with regulators on January 30 2025, the utility confirmed it discovered “suspicious activity” on August 26 and initiated an investigation.

The ransomware gang known as Akira later claimed responsibility, stating they had stolen Social Security numbers and company financial records.

read more