News Releases

Trustwave Unveils 2025 Cybersecurity Threat Report for Energy and Utilities Sector, Highlights Surge in Ransomware Attacks

Written by | Jan 22, 2025 2:00:00 PM

Chicago – January 22, 2025 Trustwave, a leading cybersecurity and managed security services provider, today released a series of reports detailing the threats facing the energy and utilities sector, which is increasingly targeted due to its critical role in supporting national and global infrastructures.

In its annual research, the Trustwave SpiderLabs team highlights significant trends shaping the industry, including the rise of ransomware, the convergence of operational technology (OT) and information technology (IT), and evolving regulatory pressures. The research also addresses the growing sophistication of threat actors and provides a comprehensive overview of the tactics, techniques, and procedures (TTPs) they employ, categorized by attack stage.

Additionally, Trustwave SpiderLabs has produced two complementary in-depth write-ups on one of the most pressing threats in the sector: ransomware. Trustwave SpiderLabs’ supplemental research delves into ransomware trends as well as in-depth analysis of the major threat groups targeting the industry, including Hunters International and 8Base.

“Resilience to threats, both nefarious and incidental, is critical for the success of the energy and utilities sector. Any attacks on the energy sector’s supply chain of customers and partners can cause significant damage and harm, including to human life,” said Trustwave CISO Kory Daniels. “Continuous testing and cyber defense programs are challenged with the growing diversity of physical and digital environments. To achieve effective threat resilience, asset and exposure management, infrastructure and code testing, OT & IT cyber defense, and business continuity and disaster recovery programs, such cybersecurity measures will increasingly require innovative collaboration between public and private sectors.”

Cybersecurity in the energy and utilities sector is particularly challenging due to the heavy reliance on the integration of physical and infrastructure and digital systems, the increasing regulatory pressure, and aging legacy systems. Coupled with the sector’s geopolitical significance and the potential for widespread societal impact, these factors make the energy and utilities industry a prime target for malicious actors.

Trustwave SpiderLabs’ 2025 research series on the energy and utilities vertical includes:

Key findings from Trustwave SpiderLabs’ energy and utilities research series include:

  • 80% increase in ransomware activity YoY
  • 47% of ransomware attacks in the United States
  • 19% of ransomware attacks were conducted by Hunters International in H2 2024
  • 84% of attacks originated from phishing
  • 96% of attackers relied on remote services to move laterally
  • 67% of credential access techniques were brute force

To access this year’s research, please click here for the full energy and utilities threat research series.

 

About Trustwave

Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats.

Trustwave’s comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes its client’s cyber investment, and improves security resilience. Trusted by thousands of organizations worldwide, Trustwave leverages its world-class team of security consultants, threat hunters, and researchers, and its market-leading security operations platform to decrease the likelihood of attacks and minimize potential impact.

Trustwave is an analyst-recognized leader in managed detection and response (MDR), managed security services (MSS), cyber advisory, penetration testing, database security, and email security. The elite Trustwave SpiderLabs team provides industry-defining threat research, intelligence, and threat hunting, all of which are infused into Trustwave services and products to fortify cyber resilience in the age of inevitable cyber-attacks.

For more information about Trustwave, please visit: https://www.trustwave.com/en-us/.