United States: Cyber attacks on energy infrastructure on the rise

Cyberattacks on US energy infrastructure rose sharply in 2024. New studies reveal an upsurge in ransomware and data breaches, highlighting the growing vulnerability of these critical systems.

Share:

Power grid control center in Pennsylvania

U.S. energy infrastructures face intensifying cyber threats in 2024, marked by a series of targeted attacks.
According to Thales’ “Data Threat” 2024 report, 42% of critical infrastructure companies, including those in the energy sector, suffered data breaches this year.
These attacks, often orchestrated by state actors or organized criminal groups, highlight the increased vulnerability of systems using increasingly interconnected technologies and obsolete equipment.

Growing threats to critical infrastructures

The data shows a sharp rise in ransomware attacks against energy infrastructure, with a quarter of organizations reporting this type of attack in the last 12 months.
The motivation behind these attacks is clear: malicious actors know that companies in the energy sector are more likely to pay ransoms to avoid costly disruptions to their operations.
Furthermore, the complexity and diversity of the technologies used in this sector create a wide range of risks, from human error to the exploitation of known vulnerabilities, to the lack of multi-factor authentication.
The Thales report also highlights the growing threat of insider threats, with 30% of companies reporting incidents linked to employees or contractors.
This highlights the need to improve access management and strengthen security awareness programs within organizations.

Coordinated attacks and vulnerabilities in industrial control systems

Between November 2023 and April 2024, 29 cyberattacks specifically targeting the industrial control systems of US energy infrastructures were reported.
These attacks, including ransomware and intrusions, were aimed at compromising critical security systems.
Rapid digitization and the growing integration of new technologies into energy infrastructures are increasing the number of potential entry points for cyber attacks, exposing more systems to the risk of intrusion.
Experts stress that securing industrial control systems, often built on old, interconnected technologies, has become a priority.
The challenge is made all the more complex by the fact that the sector struggles to find and retain qualified cybersecurity professionals, which weakens its ability to respond.

New guidelines and greater resilience

In response to these growing threats, the U.S. Department of Energy (DOE) issued new cybersecurity guidelines for electric distribution systems and distributed energy resources (DER) in 2024.
These guidelines, developed in collaboration with the National Association of Regulatory Utility Commissioners (NARUC), aim to provide a common framework for reducing risk and improving the cyber resilience of critical infrastructure.
The aim is to encourage the voluntary adoption of uniform cybersecurity practices, and to strengthen defense against sophisticated threats from state actors or criminal groups.
Industry players are called upon to strengthen their cybersecurity strategy by focusing on improving cyber resilience, reducing human error, and effectively managing internal threats.
By adopting a more proactive and coordinated approach, the energy sector can hope to mitigate the risk of future attacks, while protecting America’s critical infrastructure from potentially devastating disruptions.

RTE and Nexans announce the creation of a recycling chain dedicated to aluminium from electrical cables, targeting 600 tonnes annually and covering the entire industrial cycle from collection to production.
Three scientists from China, the United States and Russia are laureates of the 2025 Global Energy Prize, honoured for their work on high-voltage power lines, fuel-cell catalysts and pulsed energy technologies.
Rio Tinto’s new CEO inherits a significant stock market discount and will need to overcome major regulatory, operational, and financial hurdles to swiftly restore the company's appeal to international investors, according to a Wood Mackenzie analysis.
Westbridge Renewable Energy enters digital infrastructure market with Fontus, a 380 MW data centre campus in Colorado, positioned to meet strong growth in US cloud and artificial intelligence services.
Offshore drilling company Borr Drilling Limited announced the completion of an initial tranche issuance of 30 million ordinary shares out of the planned 50 million, raising $61.5mn towards the total goal of $102.5mn.
EDF announces a new internal organization with key executive appointments to enhance decision-making efficiency and expedite the revival of nuclear and hydroelectric projects central to its industrial strategy.
Rubis announces half-year results of its liquidity agreement managed by Exane BNP Paribas, totalling 241,328 shares exchanged for an aggregate amount of €6.5mn in the first half of 2025.
Chinese oil giant CNOOC Limited appoints Zhang Chuanjiang as chairman, entrusting this experienced engineer to head the group's board of directors, strategic committee, and sustainability committee from July 8.
PTT Oil and Retail Business announces a 46% increase in net profit for the first quarter of 2025, driven by regional expansion in its energy and non-energy activities, alongside an integrated ESG strategy.
Shell revises downward its forecasts for the second quarter of 2025, anticipating notably a decline in Integrated Gas and Upstream segments, impacted by reduced volumes and lower profitability in several major activities.
The Luxembourg-based group will handle engineering, procurement, commissioning and installation of flexible pipelines and umbilicals to link a new field to Egypt’s existing offshore infrastructure, with offshore work scheduled for 2026.
British firm Octopus Energy is considering a £10 billion spin-off of Kraken Technologies, involving an upcoming minority stake sale, and has initiated preliminary discussions with banks to oversee the strategic operation within the next year.
Investment fund Ardian finalises its takeover of Akuo and appoints former Électricité de France executive Bruno Bensasson to steer the renewable-energy developer’s growth towards five gigawatts of installed capacity by 2030.
TotalEnergies acquires 50% of AES' renewable portfolio in the Dominican Republic following a previous purchase of 30% of similar assets in Puerto Rico, consolidating 1.5 GW of solar, wind, and battery storage capacities in the Caribbean.
TotalEnergies is selling half of a 604 MW Portuguese energy portfolio to the Japanese consortium MM Capital, Daiwa Energy and Mizuho Leasing for €178.5mn, retaining operation and future commercialisation of the assets concerned.
Q ENERGY France secures a bank financing of €109 million arranged by BPCE Energeco to build four new energy production facilities, totalling 55 MW of wind and solar capacity by the end of 2024.
Shell announces amendment of two annual reports after notification by Ernst & Young of non-compliance with SEC auditor partner rotation rules; however, financial statements remain unchanged.
The Financial Superintendency of Colombia approves an amendment to Ecopetrol’s local bonds and commercial paper program, enabling issuance of sustainable, indexed, or in-kind repayable instruments.
ABO Energy is selling its subsidiary ABO Energy Hellas and an energy project portfolio of approximately 1.5 gigawatts to HELLENiQ ENERGY Holdings, thus refocusing its strategic resources towards other markets, notably Germany, without major financial impact anticipated for 2025.
Iberdrola announces a supplementary dividend of €0.409 per share for 2024 under the "Iberdrola Retribución Flexible" programme, bringing the total annual remuneration to €0.645 per share, representing a year-on-year increase of 15.6%.