Semperis reports that more than three-fifths of US and UK water and electricity companies were hit by cyberattacks in 2024. In fact, most companies suffered serious disruption.

The researchers surveyed IT and security professionals at 350 water treatment and power utilities to compile their report, “The State of Critical Infrastructure Resilience.”
Of the 62% who said they had been hit by a cyberattack in the past year, 80% had suffered more than one attack. Also, in 59% of cases the attack disrupted normal business operations, while in 54% the organization suffered permanent data or systems damage.
See also: Beware! New attacks with Outlaw malware
According to Semperis, the systems that power electricity grids and clean drinking water are the most important things and strong protection measures to ensure they remain safe.
The vast majority (82%) of recorded attacks targeted “Tier 0”, such as Active Directory, Entra ID, and Okta. Such a breach could lead to complete control of the targeted network.
Recent cyberattacks highlight the challenge facing water and electricity companies. Last month, it was revealed that the Chinese group Volt Typhoon had managed to maintain access to the Littleton Electric Light and Water Departments (LELWD) OT network in Massachusetts from February to November 2023.
The same group had infiltrated critical US infrastructure networks last year, with the aim of potentially securing devastating attacks in the event of a military conflict.
See also: AiTM attacks: What they are and how to avoid them
Also last year, Britain's Southern Water was hit by the Russian ransomware group Black Basta. While operations were not affected, it is believed that personal data of hundreds of thousands of employees and customers was stolen.

Steps to improve cybersecurity
To avoid the potentially devastating consequences of cyberattacks, water and electricity companies must take steps to improve their cybersecurity:
- Conduct regular risk assessments: Companies should regularly assess their systems and networks for vulnerabilities and proactively address any potential risks.
- Employee training: Employees should be trained in cybersecurity best practices ,including identifying and reporting potential threats.
- Implement multi-factor authentication: This adds an extra layer of security by requiring users to provide additional verification before accessing systems or data.
- Regularly update software and systems: Companies should ensure that their systems, software, and equipment are regularly updated with the latest security patches.
- Partner with cyber experts: Companies can benefit from working with experienced cybersecurity professionals who can help identify vulnerabilities and implement effective defense strategies against cyberattacks.
See also: Pass-the-hash attacks: Learn how to protect yourself
In today’s digital landscape, water and electricity companies must prioritize cybersecurity to protect their operations, customers, and the public. By understanding the risks and implementing strong security, they can mitigate the threat of cyberattacks and continue to provide safe and reliable services to their communities.
Source: www.infosecurity-magazine.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
