OT Cyberattacks: Energy Sector Faces $329 Billion in Risks

A Dragos report reveals the scale of cyber vulnerabilities in global energy infrastructures. Potential losses reach historic highs.

Share:

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25€/month*

*billed annually at 99€/year for the first year then 149,00€/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2€/month*
then 14.90€ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

The global energy sector faces an unprecedented cyber threat that could generate up to $329.5 billion in losses in an extreme scenario. This estimate comes from the 2025 OT Security Financial Risk Report published by Dragos Inc., the global leader in cybersecurity for operational technology (OT) environments. The study, conducted by Marsh McLennan’s Cyber Risk Intelligence Center, represents the first statistical analysis quantifying the financial risks of OT cyber incidents. Indirect losses, often overlooked in traditional models, affect up to 70% of OT-related breaches, with $172.4 billion attributed to business interruptions alone.

Critical vulnerabilities exploited at scale

Recent incidents confirm the severity of these financial projections. The ransomware attack against Halliburton in August 2024 generated $35 million in direct losses and forced the partial shutdown of systems at this $23 billion valued company. RansomHub, the group allegedly responsible for this cyberattack, demonstrated malicious actors’ ability to paralyze global oil giants. In January 2024, the FrostyGoop malware struck a Ukrainian municipal energy company, depriving more than 600 apartment buildings of heating for two days during sub-zero temperatures. This attack illustrates how Modbus TCP industrial control systems can be compromised with immediate physical consequences for civilian populations.

American water infrastructures have become prime targets for state-sponsored groups. The Cyber Army of Russia Reborn (CARR), linked to the Russian GRU military intelligence’s Sandworm group, caused a water tank overflow in Muleshoe, Texas in January 2024. The intrusion was facilitated by a password unchanged for ten years, revealing basic negligence in critical infrastructure security. The cities of Abernathy, Hale Center, and Lockney suffered similar attacks, demonstrating a coordinated campaign against American water distribution systems.

A geopolitical escalation with major economic consequences

Analysis of 2024 data reveals a qualitative transformation in OT cyber threats. While the number of attacks increased only marginally, from 72 in 2023 to 76 in 2024, the physical impact exploded with 1,015 disrupted sites versus 412 the previous year, a 146% increase. Nation-state attacks with physical consequences tripled, driven by Chinese, Russian, and Iranian campaigns. Three new malware strains specific to industrial control systems (ICS) were discovered in 2024, equaling half the total discovered during the previous fourteen years.

The Forescout report reveals that industrial automation protocols have become preferred attack vectors. Attacks on these protocols climbed from 71% to 79% between 2023 and 2024, with Modbus dominating at 40% of incidents, followed by Ethernet/IP at 28%. Threat actors increased their presence by 93% in the energy sector, 71% in manufacturing, and 55% in healthcare. This exponential progression is accompanied by increased sophistication in attack methods and unprecedented physical disruption capability.

Quantified security controls to reduce exposure

The Dragos report identifies three priority OT cybersecurity controls with their potential for financial risk reduction. Incident response planning enables average risk reduction up to 18.5%. Defensible architecture can reduce exposure by 17.09%, while ICS network visibility and monitoring offer protection up to 16.47%. These percentages, based on tens of thousands of simulations and a decade of breach data, provide executives with concrete metrics to justify OT cybersecurity investments.

Regulatory implications intensify with the European NIS2 and CER directives coming into force in late 2024, imposing cybersecurity measures on more than 400,000 companies. In the United States, the Transportation Security Administration (TSA) issued binding directives for the pipeline sector following the 2021 Colonial Pipeline attack that disrupted 45% of the East Coast’s fuel supply. Energy companies must now quantify their cyber risks to meet Securities and Exchange Commission (SEC) reporting requirements, notably the 8-K rule on cyber incident disclosure. This regulatory evolution transforms OT cybersecurity from a technical cost center into a financially measurable strategic imperative, redefining investment priorities for the global energy sector.

South African state utility Eskom expects a second consecutive year of profit, supported by tariff increases, lower debt levels and improved operations.
Equans Process Solutions brings together its expertise to support highly technical industrial sectors with an integrated offer covering the entire project lifecycle in France and abroad.
Zenith Energy centres its strategy on a $572.65mn ICSID claim against Tunisia, an Italian solar portfolio and uranium permits, amid financial strain and reliance on capital markets.
Ivanhoe Mines expects a 67% increase in electricity consumption at its copper mine in DRC, supported by new hydroelectric, solar and imported supply sources.
Q ENERGY France and the Association of Rural Mayors of France have entered a strategic partnership to develop local electrification and support France's energy sovereignty through rural territories.
ACWA Power, Badeel and SAPCO have secured $8.2bn in financing to develop seven solar and wind power plants with a combined capacity of 15 GW in Saudi Arabia, under the national programme overseen by the Ministry of Energy.
Hydro-Québec reports a 29% increase in net income over nine months in 2025, supported by a profitable export strategy and financial gains from an asset sale.
Antin Infrastructure Partners is preparing to sell Idex in early 2026, with four North American funds competing for a strategic asset in the European district heating market.
EDF could sell up to 100% of its US renewables unit, valued at nearly €4bn ($4.35bn), to focus on French nuclear projects amid rising debt and growing political uncertainty in the United States.
Norsk Hydro plans to shut down five extrusion plants in Europe in 2026, impacting 730 employees, as part of a restructuring aimed at improving profitability in a pressured market.
The City of Paris has awarded Dalkia the concession for its urban heating network, a €15bn contract, ousting long-time operator Engie after a five-year process.
NU E Power Corp. completed the purchase of 500 MW in energy assets from ACT Mid Market Ltd. and appointed Broderick Gunning as Chief Executive Officer, marking a new strategic phase for the company.
Commodities trader BB Energy has cut over a dozen jobs in Houston and will shift some administrative roles to Europe as part of a strategic reorganisation.
Ferrari has entered into an agreement with Shell for the supply of 650 GWh of renewable electricity until 2034, covering nearly half of the energy needs of its Maranello site.
By divesting assets in Mexico, France and Eastern Europe, Iberdrola reduces exposure to non-strategic markets to strengthen its positions in regulated networks in the United Kingdom, the United States and Brazil, following a targeted capital reallocation strategy.
Iberdrola offers to buy the remaining 16.2% of Neoenergia for 32.5 BRL per share, valuing the transaction at approximately €1.03bn to simplify its Brazilian subsidiary’s structure.
Paratus Energy Services collected $38mn via its subsidiary Fontis Energy for overdue invoices in Mexico, supported by a public fund aimed at stabilising supplier payments.
CrossBoundary Energy secures a $200mn multi-project debt facility, backed by Standard Bank and a $495mn MIGA guarantee, to supply solar and storage solutions for industrial and mining clients across up to 20 African countries.
Mercuria finalises an Asian syndicated loan refinancing with a 35% increase from 2024, consolidating its strategic position in the region.
Sixty Fortune 100 companies are attending COP30, illustrating a growing disconnect between federal US policy and corporate strategies facing international climate regulations.

All the latest energy news, all the time

Annual subscription

8.25€/month*

*billed annually at 99€/year for the first year then 149,00€/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2€/month*
then 14.90€ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.