Energy (Includes Power and Utilities)

Industry

Digital Energy Provider, Tibber Data Leaked Online

November 11, 2024

Hackers have attacked the electricity provider Tibber and stolen data. Apparently over 50,000 customers are affected, all from Germany. Since November 11, a dataset titled “Tibber Data Breach – Leaked, Download” has been available on a popular darknet forum. Some sample lines contain name, email address, order amount and incomplete address data.

read more

Well Servicing Contractor, MMI Services, Hit in Cyberattack

May 21, 2024

Well servicing contractor, MMI Services, Inc., suffered a cyberattack in May and is now letting victims of the attack know about what occurred and what information the threat actors made off with.
“On May 21, 2024, we experienced a network disruption that impacted certain systems,” the Bakersfield, California-based company said in an advisory. “Upon discovery, we took immediate action to address and investigate the event, which included engaging third-party specialists to assist with determining the nature and scope of the incident.
“The investigation determined that limited information maintained on our network may have been acquired by an unauthorized actor between May 20, 2024, and May 21, 2024. We then began a review of the contents of the potentially affected data to determine the type of information contained within and to whom that information related.”

read more

Halliburton Takes Systems Offline following Cyberattack

August 21, 2024

“On August 21, 2024, Halliburton Company became aware that an unauthorized third party gained access to certain of its systems,” the company said in an 8-K report to the SEC. “The Company’s response efforts included proactively taking certain systems offline to help protect them and notifying law enforcement. The Company’s ongoing investigation and response include restoration of its systems and assessment of materiality,” Halliburton vice president Charles Geer said in the report.

Reuters reported on Thursday that some employees were told not to connect to the company’s internal network as a precaution following the cyberattack. The company has not shared many details about the attack, causing other customers to disconnect from Halliburton due to the lack of information being shared. BleepingComputer reports some companies are working with ONG-ISAC—an agency that acts as a central point of coordination and communication for physical and cybersecurity threats against the oil and gas industry—to receive technical information about the attack to determine if they were breached as well.

read more

Spanish Energy Giant Hit by Cyberattack

May 6, 2024

On May 7, Iberdrola detected unauthorized access to customer databases through a supplier. Specifically, it affected 850,000 customers in Spain (600,000 from Iberdrola customers and 250,000 from Curenergia), from whom the data of name, surname, ID and contact information were obtained. Iberdrola denies that financial data has been compromised and claims to have notified all those affected.

read more

Large Data Breach at Iberdrola Energy Company affects 1.3 Million Customers

March 15, 2022

Iberdrola, Spain’s largest energy company, suffered a cyberattack on March 15. The attack compromised the personal data of 1.3 million customers, according to Eldiario.es and confirmed by company sources to EL PAÍS. The company denies that users’ financial or consumer data has been compromised, although it admits that it did reveal their name, ID, address and telephone number.

read more

Sellafield Nuclear Waste Facility in UK Pleads Guilty; Insists There Never has been a Successful Cyberattack

May 29, 2015

The state-owned operator of the UK’s largest nuclear waste site has pleaded guilty to criminal charges brought by the industry regulator over IT security breaches. Lawyers acting for Sellafield told a London court on Thursday that they accepted cyber security was “not sufficiently adhered to for a period”, although they insisted there had not been a successful cyber attack and that its systems were now secure.

One of the charges to which Sellafield pleaded guilty was that it failed in March last year to “ensure that there was adequate protection of sensitive nuclear information on its information technology network”. The other two charges related to failures to arrange “annual health checks” for its systems.

Sellafield pleaded guilty to all three charges in the prosecution brought by the Office for Nuclear Regulation under the Nuclear Industries Security Regulations 2003. Sellafield Ltd, which is owned by the UK’s Nuclear Decommissioning Authority, is in charge of cleaning up and looking after the Sellafield nuclear waste facility in Cumbria, north-west England.

Paul Greaney KC, representing Sellafield, told Westminster Magistrates’ Court that the guilty pleas “reflect the fact that while it had in place systems of cyber security, those systems were not sufficiently adhered to for a period”. “However, it is important to emphasize there was not and has never been a successful cyber attack on Sellafield.” He added: “The offenses to which Sellafield has pleaded guilty are historical. They do not reflect the current position.”

Greaney said that Sellafield’s systems were “robust” and added that media reports that its site had been compromised were “false”. The Guardian newspaper previously alleged that Sellafield’s IT systems had been hacked by groups linked to Russia and China.

The Office for Nuclear Regulation said in a statement on Thursday: “We acknowledge that Sellafield Limited has pleaded guilty to all charges . . . These charges relate to historic offences and there is no evidence that any vulnerabilities were exploited.” The prosecution is the first the ONR has brought under the 2003 regulations.

read more

Malware caused Ukranian Energy Company to Disconnect Heating Services

January 22, 2024

Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures. The attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv’s Sykhiv residential area.

An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo’s network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router. Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive. On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company’s network assets.

FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

read more

Databreach at TotalEnergies exposes over 200,000 Customers

July 3, 2024

TotalEnergies Clientes SAU has reported a significant cyberattack that has compromised the personal data of 210,715 customers. “The company is collaborating with the Police and the Spanish Data Protection Agency “to initiate all relevant legal actions against those responsible for this action.”

The incident has raised serious concerns about data security and the integrity of digital infrastructures in the energy sector.

read more

Ukranian Oil and Gas Company Naftogaz Hit by Cyberattack

January 25, 2024

State-owned critical infrastructure companies in Ukraine fell victim to cyberattacks on Thursday, with the largest oil and gas company, Naftogaz, being among the targets. The cyber assailants targeted Naftogaz’s data center, leading to the complete inactivity of the company’s website and call centers.

As of the latest update, specialists from Naftogaz are actively working to resolve the incident, promising further comments on the nature of the attack. Naftogaz, a cornerstone of Ukraine’s energy industry employing 100,000 people and supplying gas to over 12 million households, faces a critical situation, and the motive and identity of the attackers remain unclear.

read more