The ransomware crews moved on to the grid
Ransomware against hospitals and city governments was already a crisis. The same tooling is now aimed at power operators, and the target list is a signal about where the money believes the leverage is.
Ransomware against a county government is a bad week. Ransomware against a power grid is a different category of problem, and July's threat data shows the second one is no longer hypothetical.
The target list has shifted
Government agencies and electric power operators in Russia, Kazakhstan, and Brazil have been actively targeted by the Armored Likho group through spear-phishing exploiting Windows vulnerabilities. Separately, researchers have identified a modular malware framework — codenamed Avalon — that combines credential theft, lateral movement, remote access, backup destruction, and ransomware execution in a single toolkit built for exactly this kind of target. A new APT group has hit power grids in three countries using AI-crafted malware. None of that reads like an isolated incident. It reads like a market deciding critical infrastructure is where the leverage — and the ransom appetite — now lives.
Why the grid is a rational target
Attackers are economically rational actors, and hospitals proved the model: an operator that cannot afford downtime will pay faster and more than one that can absorb it. A power grid is the hospital logic taken to its natural conclusion — an operator for whom even a short outage cascades into a public emergency, and where a ransom looks cheap next to that alternative. The same toolkits (destroy backups, encrypt, extort) that worked against healthcare work the same way against utilities, with a payoff several orders larger.
Fundamentals still apply, at a different scale
The instinct with critical infrastructure attacks is to reach for exotic defenses — sector-specific detection, government partnerships, threat-intel feeds. Those all matter, but the entry vectors reported here are the same unglamorous ones that keep showing up everywhere: unpatched Windows vulnerabilities, spear-phishing, credential theft. The fundamentals — patching cadence, identity hygiene, backup integrity that survives an attacker actively trying to destroy it — do not become optional at grid scale. They become the entire defense, because there is no faster mitigation once a plant operator is mid-incident.
If your organization touches critical infrastructure, treat backup destruction resistance as a tested capability, not an assumption, and treat the patch backlog on operational technology as the security team's actual top priority — not the AI pilot competing for the same engineers' time. The attackers already decided where the leverage is. The defenders are the ones still debating it.