Toggle light / dark theme

National Security Priority: Securing America’s Electric Grid

Energy is a critical resource that powers our homes and businesses, and also supports every facet of the U.S. economy and our nation’s security. As technology advances and we become more connected, the likelihood that there will be a successful cyber or physical attack on critical infrastructure increases.

This month we recognize National Critical Infrastructure Security and Resilience Month, which is a great time to reinforce that our nation’s electric companies are working across the industry and with our government partners to protect the energy grid and ensure that customers have access to the safe and reliable energy they need. We also are focusing on strategies to mitigate the potential impact of an attack and to accelerate recovery should an incident occur.

We know that cyberattacks constantly are evolving and increasing in sophistication. As the vice president for security and preparedness at the Edison Electric Institute (EEI), the association that represents all U.S. investor-owned electric companies, I have a deep appreciation for how any threat to the energy grid endangers our communities and the national and economic security of our country.

Cowlitz County PUD among U.S. utilities targeted in cyberattacks

The Cowlitz County PUD is among more than a dozen utilities targeted in a recent cyberattack across the United States, according to an investigation by The Wall Street Journal published this week.

Cowlitz County PUD spokeswoman Alice Dietz confirmed Wednesday that the PUD’s firewall successfully blocked the only infected email that hackers sent.

“We’re proud of our IT department,” Dietz said. “They just continue to implement strong cybersecurity measures. This is a great example of why we take it so seriously.”

Microsoft says new Dexphot malware infected more than 80,000 computers

Microsoft security engineers detailed today a new malware strain that has been infecting Windows computers since October 2018 to hijack their resources to mine cryptocurrency and generate revenue for the attackers.

Named Dexphot, this malware reached its peak in mid-June this year, when its botnet reached almost 80,000 infected computers.

Since then, the number of daily infections has been slowly going down, as Microsoft claims it deployed countermeasures to improve detections and stop attacks.

Pemex Still Suffers Cyberattack Fallout

O.o…


The communications system of Mexico’s oil giant Pemex is still suffering the lingering effects of a cyberattack that occurred earlier this month, sources from the company told Bloomberg.

A ransomware attack caused administrative operations at Pemex to grind to a halt on November 10, with the company announcing the resumption of work soon after, saying the actual attack had been prevented.

The attackers used the Ryuk ransomware, which specifically targets companies with annual revenues of between $500 million and $1 billion. The Ryuk ransomware gets dropped into a network by another malware and soon after begins encrypting files. Yet the encryption begins with a delay, which gives the attackers time to study their target and how much money they could extort from it.

/* */