April 25, 2025

Resecurity warns of increased cyber threats to energy and nuclear facilities from hacktivists and nation-states

Resecurity's latest report reveals a sharp rise in cyberattacks targeting critical energy infrastructure across North America, Asia, and the EU—including nuclear facilities. These attacks are driven by geopolitical tensions, with nation-state actors from China, Iran, North Korea, and Russia, as well as ransomware groups and hacktivists, playing key roles. The focus is largely on cyber-espionage, but ransomware is increasingly used to disrupt operational technology (OT) and demand large payouts.

Key Factors Increasing Risk:

  • IT-OT Convergence and Industrial IoT (IIoT) have expanded attack surfaces.
  • Cloud adoption and AI integration introduce new vulnerabilities.
  • Supply chain risk, highlighted by the MOVEit breach, exposes multiple tiers of vendors.
  • AI adoption in the nuclear sector is particularly concerning, adding complexity and risk.

Highlighted Threat Actors:

  • RansomHub, HellCat (ransomware)
  • Lazarus Group, Cyb3rAv3ngers (nation-state)
  • S16, Noname057(16) (hacktivist)

HellCat is noted for using Lumma infostealer malware and leaking energy firm data, including a major breach at Schneider Electric. Lazarus Group has specifically targeted nuclear sector personnel using deceptive job applications (Operation DreamJob).

Nuclear Sector Under Fire:

  • Multiple DDoS attacks, phishing campaigns, and data leaks have hit nuclear entities globally.
  • Resecurity’s HUNTER unit identified leaks from organizations like Qatar Gas, EPRI, and Framatome.
  • Dark web activity shows increased interest in nuclear access listings and stolen data.

Call to Action:

The U.S. DOE and NERC have issued new guidelines to bolster cybersecurity, but the report urges continued vigilance and stronger dark web monitoring. As energy firms become key targets in a new wave of cyberwarfare, the line between cybercrime and state-backed military operations continues to blur.

Source: https://industrialcyber.co/utilities-energy-power-water-waste/resecurity-warns-of-increased-cyber-threats-to-energy-and-nuclear-facilities-from-hacktivists-and-nation-states/

Explore More Insightful Articles: