United States: Cyber attacks on energy infrastructure on the rise

Cyberattacks on US energy infrastructure rose sharply in 2024. New studies reveal an upsurge in ransomware and data breaches, highlighting the growing vulnerability of these critical systems.

Share:

Power grid control center in Pennsylvania

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25£/month*

*billed annually at 99£/year for the first year then 149,00£/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2£/month*
then 14.90£ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

U.S. energy infrastructures face intensifying cyber threats in 2024, marked by a series of targeted attacks.
According to Thales’ “Data Threat” 2024 report, 42% of critical infrastructure companies, including those in the energy sector, suffered data breaches this year.
These attacks, often orchestrated by state actors or organized criminal groups, highlight the increased vulnerability of systems using increasingly interconnected technologies and obsolete equipment.

Growing threats to critical infrastructures

The data shows a sharp rise in ransomware attacks against energy infrastructure, with a quarter of organizations reporting this type of attack in the last 12 months.
The motivation behind these attacks is clear: malicious actors know that companies in the energy sector are more likely to pay ransoms to avoid costly disruptions to their operations.
Furthermore, the complexity and diversity of the technologies used in this sector create a wide range of risks, from human error to the exploitation of known vulnerabilities, to the lack of multi-factor authentication.
The Thales report also highlights the growing threat of insider threats, with 30% of companies reporting incidents linked to employees or contractors.
This highlights the need to improve access management and strengthen security awareness programs within organizations.

Coordinated attacks and vulnerabilities in industrial control systems

Between November 2023 and April 2024, 29 cyberattacks specifically targeting the industrial control systems of US energy infrastructures were reported.
These attacks, including ransomware and intrusions, were aimed at compromising critical security systems.
Rapid digitization and the growing integration of new technologies into energy infrastructures are increasing the number of potential entry points for cyber attacks, exposing more systems to the risk of intrusion.
Experts stress that securing industrial control systems, often built on old, interconnected technologies, has become a priority.
The challenge is made all the more complex by the fact that the sector struggles to find and retain qualified cybersecurity professionals, which weakens its ability to respond.

New guidelines and greater resilience

In response to these growing threats, the U.S. Department of Energy (DOE) issued new cybersecurity guidelines for electric distribution systems and distributed energy resources (DER) in 2024.
These guidelines, developed in collaboration with the National Association of Regulatory Utility Commissioners (NARUC), aim to provide a common framework for reducing risk and improving the cyber resilience of critical infrastructure.
The aim is to encourage the voluntary adoption of uniform cybersecurity practices, and to strengthen defense against sophisticated threats from state actors or criminal groups.
Industry players are called upon to strengthen their cybersecurity strategy by focusing on improving cyber resilience, reducing human error, and effectively managing internal threats.
By adopting a more proactive and coordinated approach, the energy sector can hope to mitigate the risk of future attacks, while protecting America’s critical infrastructure from potentially devastating disruptions.

Singapore’s Sembcorp Industries has entered the Australian energy market with the acquisition of Alinta Energy in a deal valued at AU$6.5bn ($4.3bn), including debt.
Potentia Energy has secured $553mn in financing to optimise its operational renewable assets and support the delivery of six new projects totalling over 600 MW of capacity across Australia.
Drax plans to convert its 1,000-acre site in Yorkshire into a data centre by 2027, repurposing former coal infrastructure and existing grid connections.
EDF has inaugurated a synchronous compensator in Guadeloupe to enhance the stability of an isolated power grid, an unprecedented initiative aiming to reduce dependence on thermal plants and the risk of prolonged outages.
NGE and the Agence Régionale Énergie Climat Occitanie form a partnership to develop a heating and cooling network designed to support economic activity in the Magna Porta zone, with locally integrated production solutions.
GEODIS and EDF have signed a strategic partnership to cut emissions from logistics and energy flows, with projects planned in France and abroad.
The American oil group now plans to invest $20 billion in low-emission technologies by 2030, down from the $30 billion initially announced one year earlier.
More than $80bn in overseas cleantech investments in one year reveal China’s strategy to export solar and battery overcapacity while bypassing Western trade barriers by establishing industrial operations across the Global South.
Exxaro increases its energy portfolio in South Africa with new wind and solar assets to secure power supply for operations and expand its role in independent generation.
Plenitude acquires full ownership of ACEA Energia for up to €587mn, adding 1.4 million customers to its portfolio and reaching its European commercial target ahead of schedule.
ABB invests in UK-based start-up OctaiPipe to strengthen its smart energy-saving solutions for data centre infrastructure.
Enbridge has announced a 3% increase in its annual dividend for 2026 and expects steady revenue growth, with up to CAD20.8bn ($15.2bn) in EBITDA and CAD10bn ($7.3bn) in capital investment.
Axess Group has signed a memorandum of understanding with ARO Drilling to deliver asset integrity management services across its fleet, integrating digital technologies to optimise operations.
South African state utility Eskom expects a second consecutive year of profit, supported by tariff increases, lower debt levels and improved operations.
Equans Process Solutions brings together its expertise to support highly technical industrial sectors with an integrated offer covering the entire project lifecycle in France and abroad.
Zenith Energy centres its strategy on a $572.65mn ICSID claim against Tunisia, an Italian solar portfolio and uranium permits, amid financial strain and reliance on capital markets.
Ivanhoe Mines expects a 67% increase in electricity consumption at its copper mine in DRC, supported by new hydroelectric, solar and imported supply sources.
Q ENERGY France and the Association of Rural Mayors of France have entered a strategic partnership to develop local electrification and support France's energy sovereignty through rural territories.
ACWA Power, Badeel and SAPCO have secured $8.2bn in financing to develop seven solar and wind power plants with a combined capacity of 15 GW in Saudi Arabia, under the national programme overseen by the Ministry of Energy.
Hydro-Québec reports a 29% increase in net income over nine months in 2025, supported by a profitable export strategy and financial gains from an asset sale.

All the latest energy news, all the time

Annual subscription

8.25£/month*

*billed annually at 99£/year for the first year then 149,00£/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2£/month*
then 14.90£ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.