OT Cyberattacks: Energy Sector Faces $329 Billion in Risks

A Dragos report reveals the scale of cyber vulnerabilities in global energy infrastructures. Potential losses reach historic highs.

Share:

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

The global energy sector faces an unprecedented cyber threat that could generate up to $329.5 billion in losses in an extreme scenario. This estimate comes from the 2025 OT Security Financial Risk Report published by Dragos Inc., the global leader in cybersecurity for operational technology (OT) environments. The study, conducted by Marsh McLennan’s Cyber Risk Intelligence Center, represents the first statistical analysis quantifying the financial risks of OT cyber incidents. Indirect losses, often overlooked in traditional models, affect up to 70% of OT-related breaches, with $172.4 billion attributed to business interruptions alone.

Critical vulnerabilities exploited at scale

Recent incidents confirm the severity of these financial projections. The ransomware attack against Halliburton in August 2024 generated $35 million in direct losses and forced the partial shutdown of systems at this $23 billion valued company. RansomHub, the group allegedly responsible for this cyberattack, demonstrated malicious actors’ ability to paralyze global oil giants. In January 2024, the FrostyGoop malware struck a Ukrainian municipal energy company, depriving more than 600 apartment buildings of heating for two days during sub-zero temperatures. This attack illustrates how Modbus TCP industrial control systems can be compromised with immediate physical consequences for civilian populations.

American water infrastructures have become prime targets for state-sponsored groups. The Cyber Army of Russia Reborn (CARR), linked to the Russian GRU military intelligence’s Sandworm group, caused a water tank overflow in Muleshoe, Texas in January 2024. The intrusion was facilitated by a password unchanged for ten years, revealing basic negligence in critical infrastructure security. The cities of Abernathy, Hale Center, and Lockney suffered similar attacks, demonstrating a coordinated campaign against American water distribution systems.

A geopolitical escalation with major economic consequences

Analysis of 2024 data reveals a qualitative transformation in OT cyber threats. While the number of attacks increased only marginally, from 72 in 2023 to 76 in 2024, the physical impact exploded with 1,015 disrupted sites versus 412 the previous year, a 146% increase. Nation-state attacks with physical consequences tripled, driven by Chinese, Russian, and Iranian campaigns. Three new malware strains specific to industrial control systems (ICS) were discovered in 2024, equaling half the total discovered during the previous fourteen years.

The Forescout report reveals that industrial automation protocols have become preferred attack vectors. Attacks on these protocols climbed from 71% to 79% between 2023 and 2024, with Modbus dominating at 40% of incidents, followed by Ethernet/IP at 28%. Threat actors increased their presence by 93% in the energy sector, 71% in manufacturing, and 55% in healthcare. This exponential progression is accompanied by increased sophistication in attack methods and unprecedented physical disruption capability.

Quantified security controls to reduce exposure

The Dragos report identifies three priority OT cybersecurity controls with their potential for financial risk reduction. Incident response planning enables average risk reduction up to 18.5%. Defensible architecture can reduce exposure by 17.09%, while ICS network visibility and monitoring offer protection up to 16.47%. These percentages, based on tens of thousands of simulations and a decade of breach data, provide executives with concrete metrics to justify OT cybersecurity investments.

Regulatory implications intensify with the European NIS2 and CER directives coming into force in late 2024, imposing cybersecurity measures on more than 400,000 companies. In the United States, the Transportation Security Administration (TSA) issued binding directives for the pipeline sector following the 2021 Colonial Pipeline attack that disrupted 45% of the East Coast’s fuel supply. Energy companies must now quantify their cyber risks to meet Securities and Exchange Commission (SEC) reporting requirements, notably the 8-K rule on cyber incident disclosure. This regulatory evolution transforms OT cybersecurity from a technical cost center into a financially measurable strategic imperative, redefining investment priorities for the global energy sector.

NU E Power Corp. closed a first financing tranche of $625,003 to support interconnection projects in Alberta and international feasibility studies, marking a new phase in the deployment of its energy infrastructure network.
Octopus sells a minority stake in Kraken for $1 billion in a deal valuing the tech platform at $8.65 billion, initiating its spin-off and strengthening its position among international energy suppliers.
India’s public sector SECI seeks to outsource the design and management of an energy trading software platform, including technical support and human resources for five years at its New Delhi headquarters.
CB&I acquires Petrofac's Asset Solutions division, targeting revenue diversification and geographic expansion, with nearly 3,000 new employees expected to join the group.
French group Nexans initiates the sale of its Autoelectric subsidiary to India’s Motherson for €207mn ($227mn), marking its full exit from non-electrification activities.
Bourbon enters a new strategic phase following the arrival of Davidson Kempner and Fortress, who have become majority shareholders after a financial restructuring approved by the French courts.
US-based Armada has signed a memorandum of understanding with the Department of Energy to participate in the Genesis Mission, aimed at accelerating scientific research and reinforcing national energy and technology sovereignty.
Solar Energy Corporation of India signed a strategic agreement with Global Energy Alliance to strengthen grid resilience and support the expansion of storage and smart management technologies.
Le fonds souverain omanais a validé 141 projets en 2025 pour un engagement total de $1.2bn, visant à renforcer l’indépendance énergétique et l’industrialisation nationale à travers un programme d’investissement de $5.2bn.
The Norwegian energy group rejects the sanction imposed for illegal gas discharges at Mongstad, citing disagreement over maintenance obligations and the alleged financial benefit.
Alpine Power Systems announces the acquisition of Chicago Industrial Battery to expand its regional presence and support the growth of its PowerMAX line of used and rental batteries and chargers.
HASI and KKR strengthen their strategic partnership with an additional $1bn allocation to CarbonCount Holdings 1, bringing the vehicle’s total investment capacity to nearly $5bn.
EDF is considering selling some of its subsidiaries, including Edison and its renewables activities in the United States, to strengthen its financial capacity as a €5bn ($5.43bn) savings plan is underway.
French group Qair secures a structured €240 million loan to consolidate debt and strengthen liquidity, with participation from ten leading financial institutions.
Xcel Energy initiates three public tender offers totalling $345mn on mortgage bonds issued by Northern States Power Company to optimise its long-term debt structure.
EDF power solutions' Umoyilanga energy project has entered provisional operation with the Dassiesridge wind plant, marking a key milestone in delivering dispatchable electricity to South Africa’s national grid.
Indian group JSW Energy launches a combined promoter injection and institutional raise totalling $1.19bn, while appointing a new Chief Financial Officer to support its expansion plan through 2030.
Singapore’s Sembcorp Industries has entered the Australian energy market with the acquisition of Alinta Energy in a deal valued at AU$6.5bn ($4.3bn), including debt.
Potentia Energy has secured $553mn in financing to optimise its operational renewable assets and support the delivery of six new projects totalling over 600 MW of capacity across Australia.
Drax plans to convert its 1,000-acre site in Yorkshire into a data centre by 2027, repurposing former coal infrastructure and existing grid connections.

All the latest energy news, all the time

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.