Energy (Includes Power and Utilities)

Industry

Encino Energy Says Operations Not impacted by Cyberattack

February 27, 2023

Major U.S. private natural gas and oil producer Encino Energy has disclosed that its operations were not impacted by a cyberattack, which it has already remediated, days after it was added by the ALPHV ransomware operation, also known as BlackCat, to its data leak site, reports The Record. Encino Energy spokesperson Jackie Stewart would not say if the cyberattack was a ransomware incident, if the company paid a ransom or if it had examined the 400GB of data on ALPHV’s site. The post by the cybercrime group does not mention a dollar figure or a deadline for payment.

ALPHV had exposed 400 GB of data claimed to be stolen from Encino Energy, which is Ohio’s primary oil producer, but company spokesperson Jackie Stewart refused to confirm the nature of the cyberattack and whether the demanded ransom was paid, as well as the veracity of the data leaked by the ransomware group.

Such an attack against Encino Energy comes after the ransomware gang’s intrusions against two Luxembourg-based energy firms, as well as German oil companies Mabanaft and Oiltanking.

read more

Australian Infrastructure Services Provider Takes Down Systems

July 8, 2023

The Australian infrastructure services provider Ventia says a cyberattack on the weekend of July 8 and 9 is contained. The attack on the Sydney-headquartered essential infrastructure services provider caused it to take key systems offline. However, in a July 12 statement, Ventia says its key internal systems have been safely re-enabled and external-facing networks are systematically being restored. Ventia is giving little away about the nature of the cyberattack, but the company’s decision to shut down its systems is a characteristic response to a ransomware-style attack.

An APAC Analyst Technical Director at DarkTrace says some of Ventia’s systems were offline for at least three days and switching off services would significantly impact customers. “Ventia are an important pillar in the management of critical infrastructure. They operate sites across Australia and New Zealand on behalf of defence, electricity, gas, and water companies,”

read more

Unknown Actor Targets South African Power Generator

March 8, 2023

Researchers have uncovered a suspected cyberattack targeting a power generator in southern Africa with a new variant of the SystemBC malware. The attack was carried out by an unknown hacker group in March of this year, according to a report by cybersecurity firm Kaspersky. The hackers used a Cobalt Strike tool and DroxiDat — a new variant of the SystemBC payload — to profile compromised systems and establish remote connections on the electric utility.

No ransomware was delivered to the organization, however.

read more

China linked-Hackers Breach Power Grid in undisclosed Asian country

February 13, 2023

Symantec revealed that a Chinese hacker group with connections to APT41, which Symantec is calling RedFly, breached the computer network of a national power grid in an Asian country—though Symantec has declined to name which country was targeted. The breach began in February of this year and persisted for at least six months as the hackers expanded their foothold throughout the IT network of the country’s national electric utility, though it’s not clear how close the hackers came to gaining the ability to disrupt power generation or transmission.

Signs suggest the culprits worked within a notorious Chinese hacker group that may have also hacked Indian electric utilities years earlier.

read more

Unnamed US Energy Company Targeted with QR code Phishing Campaign

May 20, 2023

Cybersecurity researchers uncovered a large phishing campaign using malicious QR codes with the hopes of acquiring Microsoft credentials at several targets, including a major U.S. energy company.

QR codes have become widely adopted since the onset of the COVID-19 pandemic, with thousands of restaurants and businesses replacing physical menus and guides with the machine-readable images that pull up webpages containing the same information. But hackers have been quick to exploit the trend, launching campaigns that spread fake QR codes to steal user information.

Cybersecurity firm Cofense released a new report on Wednesday identifying a campaign that began in May targeting a wide array of industries. The hackers sent thousands of emails containing malicious QR codes to companies, which took users to a Microsoft credential phishing page. The author of the report declined to name the energy company that was attacked but said that about 29% of the emails they tracked as part of the campaign were sent to the energy company.

read more

Ransomware Attack Against Montreal Utility

August 3, 2023

A 100-year-old municipal organization that manages electrical infrastructure in the city of Montreal suffered a ransomware attack at the hands of the Lockbit criminal group.
Commission des services electriques de Montréal (CSEM) suffered the attack at the hands of the ransomware gang called Lockbit this past Wednesday which said it “added Commission des services electriques de Montreal to their victim list.”
The electric provider said in an advisory it was hit with ransomware on August 3 but refused to pay the ransom.

read more

Energy One Suffers Attack

August 18, 2023

Wholesale energy software provider Energy One suffered a cyberattack last week that hit systems in Australia and the United Kingdom.
The 15-year-old business provides software and services to Australia, New Zealand and other Pacific islands and European companies.
Once Energy One detected the attack August 18 and it took “immediate steps to limit the impact of the incident, engaged cyber security specialists, CyberCX, and alerted the Australian Cyber Security Centre and certain UK authorities,” the company said in a statement to the Australian Securities Exchange dated Monday.

read more

225K Customers Without Power in Ukraine Power Grid Hack

December 23, 2015

On the evening of December 23, 2015, the cursor on the grid operator’s computer screen started to move on its own. Hackers had struck the power distributor company Prykarpattyaoblenergo in Ukraine, disabling one circuit breaker after another. It was one of a kind cyberattack on a power grid executed successfully. Soon after, half of the population of Ukraine’s Ivano-Frankivsk region were in the dark without power for up to six hours. While the power was restored in a few hours, it took months for all the control centers to become fully operational again.

The hack on Ukraine’s power grid was a first-of-its-kind attack that sets an ominous precedent for the security of power grids everywhere.

read more

Russian Natural Gas Network System Attacked by pro-Ukrainian Hacker Group

August 23, 2022

A SCADA attack targeted the natural gas system of Khanty-Mansiysk city. The attack destroyed the city’s natural gas facility, knocked out its power plant and caused a blackout at its airport, reports International Business Times. As the world’s second biggest oil producing region (before western sanctions hit Russian oil) Khanty Mansi was the center of the old Soviet oil industry. The SCADA system of Khanty-Mansiysk city’s natural gas network along with its backup system at the airport was completely destroyed in the attack.

Reportedly the pro-Ukrainian group: Team OneFist is behind the attack. The group stressed they observe the rules of war and had taken steps to avoid potential damage to hospitals and civilians. And said that the latest hack was launched by Team OneFist’s new Ukrainian team members and Voltage as a “joint training-mission” to give the new members “a feel of what a SCADA attack is like.”

read more

Hackers disrupt IT network of Rome’s Public Utility and Power Company, ACEA

February 2, 2023

Acea’s computer system network was restored 4 days after the cyber attack by the Black Basta ransomware group.

“The Group’s websites and the online platforms for managing the commercial aspects of water, electricity and gas supplies are operational, as well as – from Saturday – the contact center service of the Group companies for customers” The Company reiterates “that the IT disruption generated by the cyber attack did not affect the essential electricity and water distribution services which have always been regularly guaranteed”.

The Italian cybersecurity agency says at least a dozen hacks are likely tied to the BlackBasta ransomware group. Investigators say the ransomware campaign may have hit thousands of organizations worldwide since Thursday. The first attack was against energy company Acea.

read more