Dataminr INTEL BRIEF

Cyber Intel Brief: Ransomware Impacts to Critical Infrastructure

INC Ransomware claims a data breach at Sangre de Cristo Electric Association, a rural Colorado electric cooperative serving roughly 15,000 customers, exposing PII and operational infrastructure details. The incident underscores a growing pattern of opportunistic ransomware and extortion targeting under-resourced municipal and cooperative utilities across the US critical infrastructure sector.

Cyber Intel Brief: Ransomware Impacts to Critical Infrastructure
DATE October 5, 2026
AUTHOR Joseph Slowik, Director Threat Research & Cyber Engineering
SHARE
  • Subscribe via RSS
CYBER DEFENSE

Key Takeaways

  • INC Ransomware impacted an electric utility cooperative in Colorado, United States, threatening a data leak and unspecified future disruption after failing to secure payment from the victim.
  • Cyber incidents across cooperatives and similar utilities are increasing, through both cyber criminal operations and state-sponsored attacks, as seen in summer 2026 targeting of the water and wastewater sector.
  • Defensive responses to these attacks will remain limited due to budgetary and related operational constraints, making municipal and cooperative utilities a continuing target of opportunity for a variety of malicious entities.
  • Authorities and governments must track these incidents to guide response, understanding the overall threat landscape and adversary actions to facilitate subsequent support and assistance to at-risk critical infrastructure entities.

INC Ransomware Impact Claim

On 01 October 2026, the INC Ransomware group posted a new claimed victim to their portal (note, sensitive information has been redacted):

The alleged incident involves Sangre de Cristo Electric Association (SDCEA), a rural electric utility cooperative operating in Colorado with approximately 15,000 consumers. The claim does not indicate disruptive ransomware deployment, but rather exfiltration of sensitive information including personally identifiable information (PII) and technical information on SDCEA operations.

INC Ransomware Background

INC Ransomware group emerged in 2023, initially only deploying ransomware, then evolving into an extortion group. Recent victims of INC Ransomware include organizations across multiple verticals and geographies, instead of a unique focus on particular sectors. The group is assessed to likely be a Russia-based entity with tradecraft evolving over time, from initial emphasis on exploiting significant vulnerabilities such as CVE-2023-4966 to more recent activity emphasizing credential harvesting and re-use to access victim environments.

The recent potential incident at SDCEA appears to be opportunistic as opposed to targeted activity against a critical infrastructure entity. However, the incident does reflect increasing cyber criminal impacts to critical infrastructure operators, especially under-resourced organizations such as municipal and cooperative utilities.

Ransomware Targeting Critical Infrastructure

Ransomware and other disruptive impacts targeting critical infrastructure operators are not new or novel, but have increased in volume and severity over the last few years. While state-directed, sponsored, or linked events generate the most coverage, such as the 2023 incident in Aliquippa, Pennsylvania or the summer 2026 widespread water system targeting across several US states, criminal operations can be just as impactful to overall operations.

Notably, there are no known cases of cyber criminal operations targeting or impacting operational technology (OT) systems directly. Such an action would have significant implications for ongoing critical infrastructure operations, and increase the risk of physical service disruption or impacts to safety. 

However, IT-focused network disruption or data loss can still carry significant risk. Most obviously, as observed in the potential SDCEA incident as well as the earlier “hacktivist” incident targeting a third-party service provider for California Water Service, is the loss of PII and related data associated with employees and customers. While not impactful to infrastructure operations, such data loss has follow-on risks for financial fraud and other action.

When data is exfiltrated and potentially posted online, the most interesting piece is the loss of utility and cooperative operating details. For example, in the claimed SDCEA incident, information related to distribution infrastructure, substations, and similar appears to have been accessed. If this information was deemed sensitive enough, it could be used by other threat actors, such as state entities or notional “hacktivist” organizations, to enable future operations. However, it is worth emphasizing that most leaks associated with critical infrastructure operations often encompass data that, while perhaps not easily obtained, is nonetheless available in publicly-available sources to some degree.

For smaller organizations such as municipal and cooperative utilities, the risk is magnified given the limited security and monitoring resources available. While not as lucrative a target as an investor-owned utility or major corporation, these entities are often relatively easy to compromise due to the mismatch between adversary and defender capabilities. These entities are also enticing for groups as a way to promote themselves for targeting “sensitive” infrastructure. As a result, while the payouts from such impacts may be smaller than other ransomware operations, breaches at these organizations are unlikely to go away.

Implications

Critical infrastructure impacts from ransomware have implications for the victim organizations, customers of those organizations, and local, state, and federal government authorities. Impacts to potential operations (largely focused on IT) are fairly obvious, as are the risks of data loss for cooperative customers. From a government perspective, continuity of essential services remains a critical issue for constituents on a local level. At the same time, these events, combined with increasing state-sponsored or directed activity against the sector, represent a national security risk for federal decision makers.

The previously mentioned resourcing issue drives the discussion at the level of municipalities and cooperatives, which provide services to a significant share of utility customers in the United States. These organizations have tight budgets, limited capability for overall IT investment (let alone security specific investment), and limited staff. This constrains their ability to defend critical services, which makes many common defensive recommendations inactionable without significant outside support. As a result, such organizations will remain targets of opportunity for both cybercriminals and state-nexus actors for the foreseeable future.

Recommendations & Defense

  • Municipal and cooperative utilities must leverage low-cost, high-efficacy solutions to minimize attack surface and reduce the likelihood of compromise. Understanding the organization’s network “footprint” and reducing it simply-necessary assets and hardening these to the appropriate level remains the best advice for resource-limited organizations. Outside assistance may be necessary to facilitate this.
  • Implement robust authentication mechanisms wherever possible across IT and potentially OT environments. Although the precise mechanism for INC ransomware group’s access to SDCEA remains unknown, many such intrusions have relied on captured credentials, via infostealer malware or credential capture webpages, to facilitate intrusions. Adopting authentication best practices, such as robust multifactor authentication mechanisms, can greatly reduce this risk and prevent potential intrusions.
  • Local, state, and federal authorities must continue to monitor the threat to under-resourced utilities to understand the scope of the threat and effective follow-on actions. Disruptive or other cyber actions against municipal and cooperative utilities have significant implications for society and national security overall, thus authorities must understand the threat landscape and how these intrusions take place. Doing so may enable follow-on coordinated support and action to boost security at organizations with limited availability to execute on this themselves.

2026 Mid-Year Cyber Threat Landscape Report

The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.

Download Report
Oct 5, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Intel Brief