United States: Cyber attacks on energy infrastructure on the rise

Cyberattacks on US energy infrastructure rose sharply in 2024. New studies reveal an upsurge in ransomware and data breaches, highlighting the growing vulnerability of these critical systems.

Share:

Power grid control center in Pennsylvania

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

U.S. energy infrastructures face intensifying cyber threats in 2024, marked by a series of targeted attacks.
According to Thales’ “Data Threat” 2024 report, 42% of critical infrastructure companies, including those in the energy sector, suffered data breaches this year.
These attacks, often orchestrated by state actors or organized criminal groups, highlight the increased vulnerability of systems using increasingly interconnected technologies and obsolete equipment.

Growing threats to critical infrastructures

The data shows a sharp rise in ransomware attacks against energy infrastructure, with a quarter of organizations reporting this type of attack in the last 12 months.
The motivation behind these attacks is clear: malicious actors know that companies in the energy sector are more likely to pay ransoms to avoid costly disruptions to their operations.
Furthermore, the complexity and diversity of the technologies used in this sector create a wide range of risks, from human error to the exploitation of known vulnerabilities, to the lack of multi-factor authentication.
The Thales report also highlights the growing threat of insider threats, with 30% of companies reporting incidents linked to employees or contractors.
This highlights the need to improve access management and strengthen security awareness programs within organizations.

Coordinated attacks and vulnerabilities in industrial control systems

Between November 2023 and April 2024, 29 cyberattacks specifically targeting the industrial control systems of US energy infrastructures were reported.
These attacks, including ransomware and intrusions, were aimed at compromising critical security systems.
Rapid digitization and the growing integration of new technologies into energy infrastructures are increasing the number of potential entry points for cyber attacks, exposing more systems to the risk of intrusion.
Experts stress that securing industrial control systems, often built on old, interconnected technologies, has become a priority.
The challenge is made all the more complex by the fact that the sector struggles to find and retain qualified cybersecurity professionals, which weakens its ability to respond.

New guidelines and greater resilience

In response to these growing threats, the U.S. Department of Energy (DOE) issued new cybersecurity guidelines for electric distribution systems and distributed energy resources (DER) in 2024.
These guidelines, developed in collaboration with the National Association of Regulatory Utility Commissioners (NARUC), aim to provide a common framework for reducing risk and improving the cyber resilience of critical infrastructure.
The aim is to encourage the voluntary adoption of uniform cybersecurity practices, and to strengthen defense against sophisticated threats from state actors or criminal groups.
Industry players are called upon to strengthen their cybersecurity strategy by focusing on improving cyber resilience, reducing human error, and effectively managing internal threats.
By adopting a more proactive and coordinated approach, the energy sector can hope to mitigate the risk of future attacks, while protecting America’s critical infrastructure from potentially devastating disruptions.

EDF and OpCore are converting a former thermal power plant south-east of Paris into one of Europe’s largest data centre campuses, backed by a €4 billion ($4.31bn) investment and scheduled to begin service in 2027.
Four companies completed a global series of secure remote additive manufacturing to locally produce certified parts for the oil and gas industry, marking a key industrial milestone for supply chain resilience.
BW Offshore and BW Group create BW Elara, a joint venture for floating desalination units, combining offshore engineering and water treatment to meet urgent freshwater needs.
Frontera Energy will separate its oil and infrastructure operations in Colombia to create two independent entities with distinct strategies, with completion expected in the first half of 2026.
TotalEnergies injects $100mn into Climate Investment’s Venture Strategy fund to accelerate the adoption of emissions reduction technologies within the oil industry under the OGDC framework.
Standard Lithium receives growing institutional backing in the United States to develop direct lithium extraction in Arkansas, a strategic area where the company positions itself against Exxon Mobil.
SBM Offshore reports year-to-date Directional revenue of $3.6bn, driven by Turnkey performance and the addition of three new FPSOs to its global fleet.
The European Commission is developing a scheme mandating a minimum share of EU-made low-carbon steel in public procurement, alongside a post-safeguard trade regime and targeted energy support to sustain the continental steel industry.
Sunsure Energy will supply Deepak Fertilisers with 19.36 MW of hybrid solar and wind power, delivering 55 mn units of electricity annually to its industrial facility in Raigad, Maharashtra.
IonQ will deploy a quantum computer and entanglement distribution network at the University of Chicago, strengthening its technological presence within the Chicago Quantum Exchange and accelerating its product roadmap.
Texas-based energy solutions provider VoltaGrid secures record mixed financing to expand its decentralised power generation portfolio, primarily targeting hyperscale data centres.
Kuwait's IMCC and Egypt's Maridive have formalised a joint venture based in Abu Dhabi to expand integrated offshore marine operations regionally and internationally.
In New York, Chevron outlines its long-term vision following the Hess integration, focusing on financial stability, spending reduction, and record production to consolidate investor confidence.
Facing surging computing needs, US tech leaders are hitting an energy wall that slows down data centre construction and revives demand for gas and coal.
NextNRG's monthly revenue reached $7.39mn in October, more than doubling year-over-year, driven by the expansion of its technology platforms and energy services across the United States.
The Canadian group posted record Q3 EBITDA, sanctioned $3bn worth of projects, and confirmed its full-year financial outlook despite a drop in net income.
OMS Energy is accelerating investments in artificial intelligence and robotics to position itself in the growing pipeline inspection and maintenance sector, a strategic segment with higher margins than traditional equipment manufacturing.
Duke Energy is set to release its third-quarter results on November 7, with earnings forecasts pointing upward, supported by strong electricity demand, new rate structures and infrastructure investments.
Engie maintains its 2025 earnings guidance despite falling energy prices and weaker hydro output, relying on its performance plan and a stronger expected fourth quarter.
The funding round led by Trident Ridge and Pelion Ventures will allow Creekstone Energy to launch construction of its hybrid-generation site designed for AI-optimised data centres.

All the latest energy news, all the time

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.