⚡ Energy & Utilities
Oil & gas, power, water, energy services — OT-heavy critical infrastructure · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D2▼ −5
Prior 30D7
Active actor L90DCoinbaseCartel · 1
Active actor L90DEmperador · 1
Active actor L90DClop · 1
Today — 12 Sep 2026
No industry-tagged items in today's briefing — see recent activity below.
Last 14 days
Iran continues broadening US infrastructure attack surface as Handala/CyberAv3ngers escalation carries into September; the pattern is deliberate coercion calibration, not escalation toward kinetic response.HighEnergy & UtilitiesGovernment & Public SectorNo material new Handala operation in the Sep 3–4 window, but the operational baseline from prior weeks continues: water, energy, and telecom intrusion attempts documented at a sustained pace. Iran's strategic posture — keep attacks disruptive enough to signal resolve without triggering a formal US cyber-war declaration — is consistent with coercion theory: the goal is not to cause catastrophic failure but to impose ongoing friction costs that accumulate without reaching the threshold requiring a proportionate US response. The Sep 2 joint assessment from The National summarizing FBI/IC reporting is the clearest statement of this calculus to date. The National · Unit 42 Iran OT/ICS threat: EPA, FBI, CISA, NSA joint advisory on Iranian-affiliated PLC exploitation remains active; attacks escalating in SeptemberHighEnergy & UtilitiesGovernment & Public SectorThe joint advisory (CISA/FBI/EPA/NSA on Iranian-affiliated cyber actors targeting US PLCs and HMIs in water and energy sectors) published earlier in 2026 remains current; Iranian-linked cyber activity against US critical infrastructure has escalated in September following continued US/Israeli military strikes on IRGC targets. The FBI has observed ICS intrusion attempts specifically aimed at causing operational disruption rather than data theft. Water, energy, and telecom operators should verify that any internet-facing OT/ICS components are firewalled from production networks. CISA Advisory aa26-097a · TechCrunch Iran-nexus Handala — escalating destructive operations against US and allied infrastructure in September; attacks on water, energy, and telecom confirmed; cyber dimension of the Iran-US military conflictCriticalEnergy & UtilitiesGovernment & Public SectorIn direct response to US and Israeli strikes on IRGC targets since February 2026, Iran-linked hacktivist group Handala (assessed MOIS-affiliated) has intensified attacks on US critical infrastructure through August-September 2026. Recent confirmed or claimed operations include: California Water Service data exfiltration claim (5GB database and GPS network files); coordinated OT/PLC disruption at 30+ Minnesota water utilities (Jul 26, attributed to CyberAv3ngers/IRGC CEC, already in database); Stryker Corporation MDM wiper attack (Mar 11, 200,000+ devices wiped via Microsoft Intune abuse, 56,000 employees idled in 61 countries). As of Sep 2, reporting indicates Iranian actors have broadened targeting to US telecom and energy infrastructure. No new named victim disclosed in the Sep 2–3 window beyond prior runs. The National · NBC News Iran has opened the broadest cyber offensive against US infrastructure since the 2026 war began, targeting water, energy, and telecom simultaneously — a deliberate expansion from targeted harassment to systemic disruption.CriticalEnergy & UtilitiesGovernment & Public SectorThe Feb-Sep 2026 escalation arc runs from FBI Director Patel's personal email compromise (March) through Stryker's MDM wiper (March, 200K devices), California Water Service exfiltration (June), and now multi-sector infrastructure disruption. Handala and CyberAv3ngers are not independent hacktivist groups — both are assessed as proxies for MOIS and the IRGC Cyber Electronic Command respectively. The strategic logic is coercion symmetry: US/Israeli kinetic strikes on IRGC targets are being answered with non-kinetic disruption of American critical infrastructure at a tempo calibrated to stay below the threshold of a formal cyber-war declaration. The National · CSIS Iran's pre-positioning in Qatari LNG infrastructure, flagged in August 31 briefing, should be read alongside the PaperCut and ServiceNow vulnerability windows: a threat actor with pre-positioned access to OT adjacent networks in LNG terminals would exploit a print-management or ITSM zero-day as a lateral-movement vector, not as a primary target.HighEnergy & UtilitiesPaperCut and ServiceNow are both deployed at energy companies and OT-adjacent corporate environments; unpatched instances in those sectors this week represent potential stepping-stone access paths into operational technology networks, not just data-exfiltration risks. CSIS · Canadian Centre for Cyber Security
Recent victim claims
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
August 2026
Aug 22
RXPE Group
CoinbaseCartel
Ransomware · Energy · China
CoinbaseCartel DLS claim Aug 22 2026; RXPE Group (rxpe.com) is a Chinese energy company; data-theft extortion with 48h contact window, 10-day payment deadline; data scope unconfirmed; 🟥 unverified DLS claim · Sources: DEXpose
Aug 22
Vietnam Electricity (EVNHANOI)
Emperador
Ransomware · Energy / Utilities · Vietnam
Emperador ransomware DLS claim Aug 22 2026; EVNHANOI is Vietnam's Hanoi Electricity Corporation, a state-owned critical infrastructure entity; Emperador is a lower-profile group with limited prior reporting; data scope unconfirmed; 🟥 unverified DLS claim · Sources: RansomLook
Aug 13
Shell
Clop
Extortion · Energy · NLD
Clop listed Shell on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 89GB of engineering drawings, facility scans, test reports and project plans. Shell confirmed it is investigating a potential incident. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 09
Siam Oil Product Co. Ltd.
Unknown
Ransomware · Energy / Petroleum · THA
DLS claim posted August 9 on ransomware.live; Thai petroleum and industrial distributor; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
July 2026
Jul 26
Multiple Minnesota Water and Wastewater Utilities (30+)
CyberAv3ngers
Ransomware · Critical Infrastructure · US
Coordinated OT attack on 30+ community water and wastewater systems including Plymouth, South St. Paul, Braham, and Maple Plain; automated control functions disrupted, some systems switched to manual; no water quality impact reported; MNIT activated statewide incident response; FBI investigating; pattern matches CyberAv3ngers/Iranian ICS tradecraft · Sources: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ · https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/
Jul 23
Origin Energy
Unattributed
Breach · Energy / Utilities · Australia
4.8 million customer records breached; names, addresses, DOBs, phone numbers, partial payment card/bank account details. Company engaged ACSC and Australian Federal Police. · Sources: https://therecord.media/australia-origin-energy-data-breach
Jul 18
Reatile Group
INC Ransom
Ransomware · energy (industrial/energy distribution) · South Africa
INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Reatile Group · Sources: https://www.ransomware.live
Jul 17
Acosol
Qilin
Ransomware · utilities (water) · Spain
Spanish public water utility; Qilin DLS claim Jul 17, 2026; company confirmed cyberattack, activated security protocols, warned subscribers personal data including national ID numbers, contract info, and payment methods may be compromised; NIS2-classified critical infrastructure · Sources: https://www.ransomware.live/id/QWNvc29sQHFpbGlu · https://www.hendryadrian.com/acosol-suffers-cyberattack-urges-customers-to-stay-alert/
Jul 17
Ecopetrol
Unattributed
Breach · energy (oil and gas) · Colombia
Colombia's national oil company; unauthorized access to cloud-based file storage environments of approximately 15 subsidiaries; data from ~3,300 user accounts exfiltrated including financial records, customer data, and internal files; ransomware encryption attempt blocked by existing controls; external actor communicated extortion demands; no data published on leak sites as of July 20; criminal complaint filed with Colombian Attorney General; investigation ongoing with insurers and outside experts · Sources: https://www.prnewswire.com/news-releases/ecopetrol-reports-cybersecurity-incident-302828952.html https://colombiaone.com/2026/07/18/colombia-cyberattack-company-ecopetrol/
June 2026
Jun 26
Salters Propane
SpaceBears
Ransomware · energy · propane distribution/US
propane fuel distributor; SpaceBears DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/ · https://www.hendryadrian.com/ · Sources: [RedPacket Security] · [hendryadrian.com]
Jun 15
Deep Well Services
ShinyHunters
Extortion · oilfield services · US
provider of downhole tools and services to the oil and gas industry; 7,000+ customer PII and internal corporate data records claimed; ShinyHunters DLS June 15, 2026; ransom deadline June 18 passed without data publication at time of initial report; no victim statement · https://www.hookphish.com/blog/ransomware-group-shinyhunters-hits-deep-well-services/ · https://www.ransomware.live/id/RGVlcCBXZWxsIFNlcnZpY2VzQHNoaW55aHVudGVycw · https://breachnews.com/breaches/kodak-and-deep-well-services-added-to-shinyhunters-leak-site/ · Sources: [HookPhish] · [ransomware.live] · [BreachNews]
Jun 05
Trican Well Service
Qilin
Ransomware · oilfield services · Canada
Sources: ransomware.live DLS
Jun 01
Energy Action
SafePay
Ransomware · energy management · Australia
~470GB claimed; under investigation · Sources: SafePay DLS
← All industries · Victim database →