Power Grid Attacks Aren’t New. So Why Are They So Electric Right Now?

power grid cyber security attacks blog
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

In late July 2026, 36 municipal waste and water systems across Minnesota were targeted in a cyber attack. The attackers targeted Programmable Logic Controllers (PLCs) that were in control of pressure, pumps, and chemical dosing. When the news broke, it felt like it was everywhere. This was an attack on critical systems, systems that we require and use daily.

But cyberattacks on U.S. critical infrastructure systems like water, hospitals, sewage, gas, and electricity aren’t new. Attackers have been targeting adversarial countries’ critical infrastructure and key resources for a long time, it just doesn’t always make major headlines. 

What’s changing is the number of ways attackers can gain access. Sometimes the path leads directly to operational technology (OT) or industrial control systems (ICS). Other times, it starts with something smaller, like credentials or an unpatched vulnerability in a vendor’s network. And when you introduce AI, those paths can become a whole lot more complicated.

<$comment>  <$comment><$comment><$comment><$comment><$comment><$comment><$comment><$comment><$comment><$comment><$comment><$comment>Power grid operations The critical operation <$comment><$comment>Engineering workstation Runs the PLC control logic <$comment><$comment>Cellular modem / router Remote substation link <$comment><$comment>Identity provider Single sign-on credentials <$comment><$comment>Cloud dashboard Remote monitoring platform <$comment><$comment>Remote vendor maintenance tool Used by a third-party <$comment><$comment>Substation B Another utility site <$comment><$comment>Municipal water utility A separate customer

 

Routine access path

 

Compromised vendor path

Figure 1: The critical attack surface extends beyond the control system.

The threat to critical infrastructure isn’t new, but the environment around it is changing. The concern isn't just about whether an attacker can reach a critical system, that’s always been a concern. But, what about business continuity? Getting to work? Having access to HVAC or refrigeration? It’s imperative that organizations understand the systems and dependencies that keep critical operations running, where they are exposed, and how quickly they can recover when something goes wrong.

Critical infrastructure attacks aren’t new

Ukraine’s power grid is a stark example of a cyberattack moving from an IT foothold to a physical disruption. In December 2015, attackers used spearphishing, BlackEnergy malware, stolen credentials, and legitimate remote-administration tools before opening breakers and disrupting power to about 225,000 customers. While the actors used malware to get in, the more serious impact came from what happened once they were inside, where they were able to  reach the systems and credentials that controlled the grid. CISA documented the attack, and the U.S. Department of Justice later attributed the campaign to officers in Russia’s GRU Unit 74455.

The 2016 Industroyer attack was like the sophisticated evil stepbrother of the 2015 attack. The malware used in the attack could speak industrial protocols used in electric substations and send commands to switches and circuit breakers. In 2022, Ukrainian defenders stopped an attempted attack involving Industroyer2. Later that year, Sandworm used the target’s own MicroSCADA software to send unauthorized commands to substations, then deployed CaddyWiper against the IT environment.

The United States has had warnings, too:

  • In 2013, an Iranian actor repeatedly accessed the SCADA system at the Bowman Avenue Dam in New York. The access could normally have operated the sluice gate, but the gate was manually disconnected for maintenance. The Department of Justice disclosed the intrusion in 2016.
  • In 2021, Colonial Pipeline shut down its pipeline system in response to a ransomware attack on its business network. The attackers didn’t manipulate pipeline controls directly and they still successfully created fuel-supply disruption. The Department of Energy’s incident summary underscores how critical IT availability, billing, and operational confidence can be. In this instance, the downtime ended up costing the company more than the original ransom demand of $4.4 million USD. 
  • In 2023, the Iran-linked CyberAv3ngers APT compromised internet-connected Unitronics PLCs used by U.S. water utilities, including the Municipal Water Authority of Aliquippa in Pennsylvania. The campaign relied on exposed devices and default passwords, not some magical zero-day. CISA’s advisory said the activity affected multiple sectors in the United States and other countries.
  • In July 2026, malicious activity targeted remote monitoring and control technology at more than 30 Minnesota community water systems. Some systems experienced disruption, but officials reported no confirmed impact to drinking-water quality. The FBI investigation had not publicly attributed the campaign to a specific actor, while some suspect Iran or CyberAv3ngers was responsible it has not been confirmed. Minnesota IT Services published the state’s response, while CISA urged water operators to remove publicly exposed PLCs and OT from the internet.

My point in sharing all of this is to show that the attacker doesn’t necessarily need sophisticated tools — one attack relied on more sophisticated tooling while the other did not. It's more important that they understand the environment they are targeting. 

The threat to global critical infrastructure and key resources is not theoretical. So, who targets critical infrastructure? Threat actors are generally grouped into three buckets with different goals: financially motivated actors, including ransomware groups, politically or ideologically motivated hacktivists, and espionage or destructive activity conducted by advanced persistent threat groups and nation-state actors.

Although their goals and motivations differ, their attack pathways generally stay the same: find exposed technology, steal or bypass access, understand the environment, and reach something that will cripple or cause major outages for the intended victim(s).

The key to the destruction may be innocuous 

Take the power grid, for example. A key resource in taking down a power grid could be an engineering workstation, an identity provider, a cellular modem, a router, a cloud platform, or better yet, the vendor that remotely maintains the equipment. Utilities depend on equipment manufacturers, systems integrators, telecommunications providers, software vendors, fuel suppliers, and managed service providers. Those providers are critical to functionality, which also makes them attractive targets, in part due to their criticality and another part due to their potential for blast radius.

In 2024, Bitsight researchers found 10 zero-day vulnerabilities across six ATG systems from five vendors. The flaws included command injection, hardcoded credentials, and authentication bypass. Bitsight also found thousands of ATGs directly reachable from the internet, including 6,542 devices that answered without a security code during one month of the research. Access could allow an attacker to alter tank readings, disable alarms, change relay behavior, disrupt leak tests, or repeatedly reboot a device.

However, the findings weren’t all bleak; this year, Bitsight observed U.S. internet-exposed ATGs fall by more than 55% from March to June 2026, after government and industry warnings about active targeting. But hundreds of confirmed-vulnerable web-facing consoles and more than 800 U.S. devices on another monitored port remained exposed in June. This underscores the need to reduce exposure and address underlying vulnerabilities in the systems we aren't always thinking about.

Figure 1 U.S. ATG protocol internet exposure June 2025 to June 2026
Figure 2: U.S. ATG protocol internet exposure, June 2025 to June 2026.

I don’t expect organizations to know off the top of their heads where ATGs exist in their ecosystem, because they are generally installed and maintained by a fuel vendor or integrator. If that device supports a hospital generator or a power plant’s fuel supply, it is part of the organization’s critical attack surface and should be inventoried and tracked accordingly. 

Why are these systems still exposed?

OT is hard to secure for reasons that are very different from enterprise IT. PLCs and other control systems can remain in service for decades. They sometimes use proprietary or insecure-by-design protocols, have limited logging, and require physical access or a plant shutdown to patch. A simple routine scan can cause issues on these fragile devices, but their fragility doesn’t eliminate the need for visibility, nor does it eliminate their inherent security flaws.

Because water systems cover large geographic areas and grid equipment often sits in unmanned substations, they are usually monitored remotely. So organizations add cellular modems, remote desktop tools, VPNs, cloud dashboards, and vendor access. Each connection solves an operational problem and makes access more convenient, it also increases the available attack surface. A dramatic blackout is scary, and fear sells. But sometimes these attacks are more focused on causing cost issues, disruptions, and major downtime, and it can require a lot of manpower to rebuild these systems. 

AI makes a familiar problem faster

So how is AI complicating this already fragile attack surface? LLMs have shown their ability to  summarize public manuals, write or troubleshoot scripts, translate technical material, create phishing content, and sort through large amounts of scan or vulnerability data. All of these things can make access and an attack a lot simpler for a threat actor.

This is the bigger point behind the advancement of frontier AI models like Claude Mythos: AI is expanding the attack surface beyond vulnerabilities, but on the flip side, it can also help defenders. All that said, I don't think AI is the root problem, I think it's simply speeding up problems we already had. 

Regulation is raising the baseline, especially for supply chain risk

In North America, NERC Critical Infrastructure Protection standards apply to certain entities operating the Bulk Electric System. CIP-013-2 specifically requires supply chain cybersecurity risk-management plans for high- and medium-impact Bulk Electric System cyber systems. That includes vendor incident notification, vulnerability disclosure, software integrity, termination of vendor access, and controls for vendor-initiated remote access.

In the European Union, NIS2 brings energy and other critical sectors into a common risk-management and incident-reporting framework, implemented through national law. Compliance is not the same as resilience, but both frameworks reinforce the same point: third-party access and supply chain dependencies are operational risks, not procurement paperwork.

How to prepare for a cyber attack on the power grid

Start with the paths that can create an operational consequence.

Know what’s exposed. 

Inventory internet-facing IT and OT, including PLCs, HMIs, engineering workstations, cellular modems, remote-access gateways, routers, identity systems, and cloud consoles. Include assets operated by vendors and integrators.

Remove direct OT exposure. 

A PLC, ATG, or management interface has no business answering the open internet. Put required remote access behind controlled gateways or jump hosts with phishing-resistant MFA, least privilege, time-bounded access, and session logging.

Segment for consequence. 

Separate enterprise IT, vendor access, engineering workstations, and control networks. A compromised mailbox, browser, or router should not provide a direct route to a physical process.

Monitor the process, not just malware. 

Alert on changes to PLC logic and project files, new engineering sessions, altered DNS or DHCP settings, disabled alarms, unexpected OT protocol traffic, and discrepancies between digital displays and physical readings.

Treat vendors as part of the attack surface. 

Know who can connect, from where, with which account, and to what. Remove dormant access. Require rapid incident notification. Test whether one compromised supplier could reach multiple sites.

Prepare to operate manually. 

Keep known-good logic and configurations offline. Test restoration, communications, and manual operations. Know how long the physical process can remain safe when automation or enterprise IT is unavailable.

Conclusion

Critical infrastructure targeting is not suddenly new just because it made its way to bigger headlines. AI, however, has made these types of attacks more accessible to a wider variety of threat actors. We know — and we have known — that critical infrastructure is vulnerable and oftentimes too fragile for my liking. A fix is more complicated than a simple patch. In the meantime, it's important to understand where your vulnerabilities lie, how much an attack would affect the business, and what the backup plan is.

That starts with visibility across your own environment and the vendors you depend on. Bitsight helps organizations identify exposed assets, understand where risk is concentrated, and extend that visibility into the supply chain. The attack targets aren’t new, the paths to them have simply expanded.

Bitsight cta background color
2026 GigaOM TPRM Radar cover

See why GigaOm named Bitsight a Leader in TPRM

In GigaOm’s latest Radar report for Third-Party Risk Management, Bitsight was positioned as a Leader and Fast Mover for its externally sourced cyber risk ratings, continuous monitoring, API-first integrations, and vendor risk visibility.

 

Get the report

Bitsight cta background color