United States: Cyber attacks on energy infrastructure on the rise

Cyberattacks on US energy infrastructure rose sharply in 2024. New studies reveal an upsurge in ransomware and data breaches, highlighting the growing vulnerability of these critical systems.

Share:

Power grid control center in Pennsylvania

Comprehensive energy news coverage, updated nonstop

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access • Archives included • Professional invoice

OTHER ACCESS OPTIONS

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

FREE ACCOUNT

3 articles offered per month

FREE

*Prices are excluding VAT, which may vary depending on your location or professional status

Since 2021: 35,000 articles • 150+ analyses per week

U.S. energy infrastructures face intensifying cyber threats in 2024, marked by a series of targeted attacks.
According to Thales’ “Data Threat” 2024 report, 42% of critical infrastructure companies, including those in the energy sector, suffered data breaches this year.
These attacks, often orchestrated by state actors or organized criminal groups, highlight the increased vulnerability of systems using increasingly interconnected technologies and obsolete equipment.

Growing threats to critical infrastructures

The data shows a sharp rise in ransomware attacks against energy infrastructure, with a quarter of organizations reporting this type of attack in the last 12 months.
The motivation behind these attacks is clear: malicious actors know that companies in the energy sector are more likely to pay ransoms to avoid costly disruptions to their operations.
Furthermore, the complexity and diversity of the technologies used in this sector create a wide range of risks, from human error to the exploitation of known vulnerabilities, to the lack of multi-factor authentication.
The Thales report also highlights the growing threat of insider threats, with 30% of companies reporting incidents linked to employees or contractors.
This highlights the need to improve access management and strengthen security awareness programs within organizations.

Coordinated attacks and vulnerabilities in industrial control systems

Between November 2023 and April 2024, 29 cyberattacks specifically targeting the industrial control systems of US energy infrastructures were reported.
These attacks, including ransomware and intrusions, were aimed at compromising critical security systems.
Rapid digitization and the growing integration of new technologies into energy infrastructures are increasing the number of potential entry points for cyber attacks, exposing more systems to the risk of intrusion.
Experts stress that securing industrial control systems, often built on old, interconnected technologies, has become a priority.
The challenge is made all the more complex by the fact that the sector struggles to find and retain qualified cybersecurity professionals, which weakens its ability to respond.

New guidelines and greater resilience

In response to these growing threats, the U.S. Department of Energy (DOE) issued new cybersecurity guidelines for electric distribution systems and distributed energy resources (DER) in 2024.
These guidelines, developed in collaboration with the National Association of Regulatory Utility Commissioners (NARUC), aim to provide a common framework for reducing risk and improving the cyber resilience of critical infrastructure.
The aim is to encourage the voluntary adoption of uniform cybersecurity practices, and to strengthen defense against sophisticated threats from state actors or criminal groups.
Industry players are called upon to strengthen their cybersecurity strategy by focusing on improving cyber resilience, reducing human error, and effectively managing internal threats.
By adopting a more proactive and coordinated approach, the energy sector can hope to mitigate the risk of future attacks, while protecting America’s critical infrastructure from potentially devastating disruptions.

Le fonds souverain omanais a validé 141 projets en 2025 pour un engagement total de $1.2bn, visant à renforcer l’indépendance énergétique et l’industrialisation nationale à travers un programme d’investissement de $5.2bn.
The Norwegian energy group rejects the sanction imposed for illegal gas discharges at Mongstad, citing disagreement over maintenance obligations and the alleged financial benefit.
Alpine Power Systems announces the acquisition of Chicago Industrial Battery to expand its regional presence and support the growth of its PowerMAX line of used and rental batteries and chargers.
HASI and KKR strengthen their strategic partnership with an additional $1bn allocation to CarbonCount Holdings 1, bringing the vehicle’s total investment capacity to nearly $5bn.
EDF is considering selling some of its subsidiaries, including Edison and its renewables activities in the United States, to strengthen its financial capacity as a €5bn ($5.43bn) savings plan is underway.
French group Qair secures a structured €240 million loan to consolidate debt and strengthen liquidity, with participation from ten leading financial institutions.
Xcel Energy initiates three public tender offers totalling $345mn on mortgage bonds issued by Northern States Power Company to optimise its long-term debt structure.
EDF power solutions' Umoyilanga energy project has entered provisional operation with the Dassiesridge wind plant, marking a key milestone in delivering dispatchable electricity to South Africa’s national grid.
Indian group JSW Energy launches a combined promoter injection and institutional raise totalling $1.19bn, while appointing a new Chief Financial Officer to support its expansion plan through 2030.
Singapore’s Sembcorp Industries has entered the Australian energy market with the acquisition of Alinta Energy in a deal valued at AU$6.5bn ($4.3bn), including debt.
Potentia Energy has secured $553mn in financing to optimise its operational renewable assets and support the delivery of six new projects totalling over 600 MW of capacity across Australia.
Drax plans to convert its 1,000-acre site in Yorkshire into a data centre by 2027, repurposing former coal infrastructure and existing grid connections.
EDF has inaugurated a synchronous compensator in Guadeloupe to enhance the stability of an isolated power grid, an unprecedented initiative aiming to reduce dependence on thermal plants and the risk of prolonged outages.
NGE and the Agence Régionale Énergie Climat Occitanie form a partnership to develop a heating and cooling network designed to support economic activity in the Magna Porta zone, with locally integrated production solutions.
GEODIS and EDF have signed a strategic partnership to cut emissions from logistics and energy flows, with projects planned in France and abroad.
The American oil group now plans to invest $20 billion in low-emission technologies by 2030, down from the $30 billion initially announced one year earlier.
BHP sells a minority stake in its Western Australia Iron Ore power network to Global Infrastructure Partners for $2 billion, retaining strategic control while securing long-term funding for its mining expansion.
More than $80bn in overseas cleantech investments in one year reveal China’s strategy to export solar and battery overcapacity while bypassing Western trade barriers by establishing industrial operations across the Global South.
Exxaro increases its energy portfolio in South Africa with new wind and solar assets to secure power supply for operations and expand its role in independent generation.
Plenitude acquires full ownership of ACEA Energia for up to €587mn, adding 1.4 million customers to its portfolio and reaching its European commercial target ahead of schedule.

All the latest energy news, all the time

Annual subscription

8.25$/month*

*billed annually at 99$/year for the first year then 149,00$/year ​

Unlimited access - Archives included - Pro invoice

Monthly subscription

Unlimited access • Archives included

5.2$/month*
then 14.90$ per month thereafter

*Prices shown are exclusive of VAT, which may vary according to your location or professional status.

Since 2021: 30,000 articles - +150 analyses/week.