CiberLATAMbywhalemate
Intelligence report

Energy, Electricity, and Utilities (Critical

August ended with ransomware and OT/ICS alerts in Latin American energy, plus regulatory consultations and focus on Oldelval, Colombia.

Sep 1, 202629 min read
Energy, Electricity, and Utilities (CriticalwhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with the verified dated facts from the period. Each one states its source base and counting criteria, so the figures reconcile across modules. They are the recurring month-to-month reading, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 57 dated facts in August 2026 · 1 from previous months (comparative frame, not month volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal panel August 2026 · Latin America Leading threat: Ransomware (21 of 52 events). Coverage: 57 dated events in August 2026 · 1 from earlier months… VERIFIED EVENTS 52 period base: all counts below is measured against this total RANSOMWARE / EXTORTION 21 2 encrypted assets confirmed · 2 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 15 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns REGULATION 3 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Monthly verified signal panel — Base: 52 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat axis distribution August 2026 · Latin America Each incident is counted in just one axis, so the total is exactly 52. "Unclassified incidents" is the remainder. Ransomware 21 Incidents 15 Unclassified 8 Vulnerabilities 4 Regulation 3 Fraud 1
Threat axis distribution — Each incident is assigned to a single axis based on its classification; the total reconciles with the 52 incidents in the period.
MONTHLY FIXED MODULE Sector breakdown of signals August 2026 · Latin America Base: 52 incidents in the period · total 88 because 27 incidents are classified in more than one sector. Public sector / OIV 30 Energy 23 Telecom 13 Other / unidentified sector 10 Finance 5 Technology 5 Retail / consumer 2
Sector breakdown of signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signal August 2026 · Latin America Each item is assigned to a single country or to regional coverage, so the total is exactly 52 out of 52 items of… Brazil 16 Regional 16 Argentina 15 Chile 5
Geographic Distribution of Signal — Verified items from the period grouped by country or regional coverage; each item is counted once.

Executive summary

The end of August 2026 shows a mixed picture for energy, electricity, and utilities in Latin America. On one hand, the exposure surface keeps expanding: the sector appears repeatedly in ransomware campaigns, industrial vulnerability alerts, and regulatory debates over critical infrastructure cybersecurity. On the other hand, not every reported event had direct operational impact. In several cases, the available material confirms administrative system compromise, data theft, or claims posted on extortion sites, but does not prove outages or damage to physical operations. That distinction matters, both to avoid overstating the risk and to avoid minimizing it. An intrusion that reaches corporate systems, credentials, technical documentation, or employee data can later escalate into control systems, affect continuity, or trigger regulatory and reputational pressure.

The most visible case in the period was Oldelval in Argentina. The company notified the National Securities Commission of a cybersecurity incident in its administrative systems, which it classified as a ransomware attack under a RaaS scheme. The company said crude transport was not interrupted and that administrative systems were restored. However, monitoring sources and later analysis indicated that the actor Incransom may have posted Oldelval on its leak site, with claims of exfiltrated internal documents, human resources material, financial information, and regulatory records. At the same time, another attribution line linked the case to The Gentlemen. From an operational standpoint, the episode illustrates two risks at once, pressure on nonindustrial corporate assets and the possibility that an apparently contained incident is amplified by exposure of sensitive data.

The second dominant theme was industrial infrastructure and Siemens S7 controllers. A joint advisory from US agencies described an active threat against the full S7 series, with internet scanning, exploitation of weak configurations, and AI-generated scripts. No confirmed incidents were reported among Latin American operators, but the signal matters for the regional energy sector because these devices appear in substations, water, wastewater, and other essential services. The message for CISOs and operational technology leaders is clear, even without a confirmed intrusion, exposure of PLCs and communications test sets remains a priority risk vector, especially if outdated versions, open ports, or incomplete inventories persist.

The month also showed broader pressure across the region. Brazil continued to show a high volume of malicious activity and ransomware in general sector tallies, with the energy and utilities vertical among the most affected in July 2026 according to the cited reports. In Chile, the discussion centered on the draft cybersecurity regulation for the electricity sector and on critical vulnerabilities in ASE2000 V2, a substation control system used in energy and water infrastructure. Meanwhile, Colombia faced an institutional alert after an attack on a transmission tower in Tolima, underscoring that service continuity depends on more than the digital perimeter, it also requires physical protection of critical assets and coordination with territorial authorities.

The overall reading leaves three takeaways. First, the Latin American energy sector remains attractive to digital extortion and to combined pressure on data, reputation, and operational continuity. Second, incidents with confirmed impact on physical operations were limited in the material analyzed, but administrative events and industrial vulnerabilities can spread into more sensitive layers. Third, regulatory maturity is advancing, although unevenly, Chile is accelerating rules, Brazil is strengthening diagnostics and committees, and other countries are responding with point alerts or after the fact. For executive management, the focus is no longer only on preventing encryption, it is on reducing exposure, segmenting, monitoring credentials, hardening remote access, controlling PLCs and test sets, and improving coordination among cybersecurity, operations, legal, and crisis communications.

Panorama

The regional picture in August 2026 is marked by a mix of opportunistic criminal activity, industrial exposure, and regulatory pressure. The attack surface in energy and utilities cannot be read separately from the rest of the digital economy. Ransomware actors continue to prioritize victims with high extortion value, while findings on PLCs and substation systems point to a second risk layer that is more technical but potentially more disruptive. That mix helps explain why the sector appears so often in extortion narratives, industrial security advisories, and regulatory consultations.

On the ransomware front, Oldelval stands out as the most important signal because it is a key operator in the transport of crude from Vaca Muerta. The incident began as a regulatory notice involving administrative systems and then became a case of public and analytical exposure after the alleged publication of data on leak sites. That progression is typical of double-extortion campaigns: systems are compromised first, then pressure follows through the threat or release of data, as the threat actor tries to maximize visibility and urgency. For the energy sector, the lesson is that administrative systems, even if they do not control valves or turbines, are high-value assets because they concentrate identities, contracts, finances, operational documentation, and regulatory evidence.

On the industrial side, the Siemens S7 advisory underscores a persistent risk. Attackers no longer depend only on sophisticated exploits or deep protocol knowledge. US agencies describe the use of AI-generated scripts and legitimate tools adapted to speak S7comm, locate exposed controllers, and read configuration or ladder logic. That lowers the barrier to entry and expands the pool of potential attackers. In Latin America, where heterogeneous OT environments, legacy integrations, and often only partial inventory visibility remain common, the risk is not theoretical. Exposed devices, outdated software, and insufficient segmentation make substations and other control assets accessible targets if basic gaps are not fixed.

On the regulatory front, Chile again moved the needle with the public consultation on the draft Technical Standard for Cybersecurity and Information Security for the electric sector. Beyond the final content, the fact that the CNE is moving ahead with this framework signals greater demands on governance, reporting, incident handling, and operational standards. The sectoral instruction to remove the reference to the electric CSIRT and respond to prior comments suggests the debate is no longer about whether to regulate, but about how to distribute functions, responsibilities, and coordination mechanisms. For companies, that shift means adapting internal processes, defining owners for controls, and preparing compliance evidence.

Brazil, meanwhile, combines a critical mass of incidents and telemetry with signs of institutionalization. Fortinet data and press tallies show a country under heavy cyber pressure. That telemetry should not be confused with confirmed incidents affecting energy and utilities. Even so, the sector's appearance among the most targeted in July suggests utilities remain a priority for reconnaissance, phishing, credential stuffing, remote access exploitation, and ransomware campaigns. The risk is not limited to technical damage. It also includes service interruptions for customers, impacts on billing and contracts, and erosion of public trust.

Colombia adds another dimension, physical risk. Reported events in Tolima show that electric infrastructure also faces sabotage or material violence, with impacts on transmission towers and circuits. That forces a broader view of critical security as an integrated discipline. Segmenting OT networks is not enough if a tower, substation, or transmission corridor can be physically attacked. Coordination with security forces, local governments, and network operators is part of resilience. August 2026 confirms that the energy and utilities sector is under simultaneous pressure from cyberextortion, technical vulnerabilities, and physical risk, with regulatory responses still uneven across the region.

Indicators

The quantitative indicators for the period point to a high-pressure environment, but they should be read with methodological discipline. In general telemetry, Brazil shows very high volumes of attack attempts and malicious activity in vendor sources, but those figures do not equal confirmed incidents against the energy sector. Sector counts and ransomware data also help size exposure, not count successful intrusions. On confirmed events, the period does show relevant incidents in Argentina, Chile, and Colombia, with different levels of impact.

On the exposure front, the cited report on Brazil says that "Energia e Serviços Públicos" was the second most attacked sector in July 2026, with 2,759 attacks and a 20% year-over-year increase. That figure should not be read as a tally of operational incidents, but as pressure detected by a sector analytical source. Likewise, references to 249.3 billion attack attempts in the first half of 2026 correspond to telemetry on attempts and malicious activity, not to successful compromises. The value of that data is that it shows background noise against Brazilian systems remains extraordinarily high, which raises the odds that utility operators will face opportunistic campaigns or exploitation of exposed services.

On the ransomware front, the material on Brazil also places the country high in 2026 global rankings, with 123 accumulated attacks according to a cited press count. Again, that does not mean all of those cases belonged to the energy or utilities sector. Even so, it confirms that the regional ecosystem is facing a volume of aggression that makes hardening and response measures a priority. For CISOs and continuity teams, the right reading is not "how many attacks my peers suffered," but "which intrusion and extortion patterns are becoming more common, and which of our own assets remain exposed."

On the regulatory and vulnerability side, the indicators do not show a long list of regional CVEs affecting energy in the material reviewed, but they do highlight one specific focus, ASE2000 V2 with critical severity, affecting versions 2.25 to 2.37 and fixed in 2.38. The value of that finding is not just technical, it is operational. When a communication test set for IEC 60870-5-104 with TLS has flaws that allow arbitrary read and write access or interception of encrypted connections, the risk crosses the boundary between IT and OT. For substations and electrical networks, a vulnerable testing or maintenance component can become a backdoor into sensitive communications.

As for confirmed incidents, the period includes the Oldelval case, which affected administrative systems without interrupting crude oil transport, as well as the attack on electrical infrastructure in Tolima. The first illustrates a digital intrusion with corporate impact and potential leakage, while the second is a physical attack with continuity risk for the service. Both matter for the critical infrastructure agenda, but they belong to different categories and should not be added together as if they were comparable. That distinction is essential for accountability and for prioritizing controls.

Key indicators

Incidents

Argentina: Oldelval, ransomware, cross-claims, and exfiltration risk

The most significant incident in Latin American energy during the period was the attack on Oleoductos del Valle (Oldelval) in Argentina. The company told the Comisión Nacional de Valores that it had suffered a cyberattack that affected some of its administrative systems. It also said crude oil transport was not interrupted and that the affected systems were restored. That notice makes the case a material event for corporate governance and the stock market, but it does not by itself amount to an impact on the pipeline’s physical operation.

What matters from a risk perspective is how the case evolved. At first glance, it appears to have been a corporate IT attack with containment and recovery. However, later breach monitoring and leak-site sources indicated that Incransom had listed Oldelval and published samples of internal documentation that allegedly included sensitive employee, HR, finance, tax, and regulatory data. While the only primary source for that attribution is the threat actor itself, the convergence of several reports suggests the case had an exfiltration component, at least as consistently claimed by the group.

Operationally, that has three implications. First, even if the company restored its administrative systems, the incident does not end there. A data leak can keep the damage going for weeks or months. Second, the exfiltration of internal documents from an hydrocarbons transport company can expose network diagrams, access hierarchies, contracts, emails, or regulatory details useful for more precise future attacks. Third, if the leaked data is partially or fully authentic, the regulatory exposure expands to privacy, labor relations, compliance, and potential litigation.

Attribution also deserves caution. Some sources linked the case to Incransom, while others pointed to The Gentlemen. The Rio Times reported that The Gentlemen claimed the attack days after taking responsibility for an incident against Ecopetrol, and later pieces stressed that this was the group’s own claim with no independent official confirmation. This kind of attribution crossfire is not unusual in the ransomware ecosystem. Groups may post names to gain visibility, increase pressure, or ride the news cycle. For a CISO, the lesson is not to pick a narrative, but to assume that a public claim and an alleged leak already create reputational and operational risk, even without evidence of OT intrusion.

Timing is also relevant. The case was reported to the CNV in late July and began circulating publicly in the first days of August. After that, leak-site activity amplified the episode with new mentions. This is a typical sequence, internal detection, regulatory notice, media coverage, and then exploitation of the information by the threat actor. In the energy sector, where public scrutiny is high, that sequence can affect negotiations with customers, suppliers, and authorities even if core operations do not stop.

From a defense perspective, Oldelval points to several practical steps. The first is to harden administrative systems, with real segmentation from the OT environment, least privilege, MFA for remote access, and lateral movement monitoring. The second is to prepare a response plan for exfiltration, not only encryption: identify what may have left, how to notify, which regulatory obligations are triggered, and how to preserve evidence. The third is to build a crisis strategy with separate messages for operations, markets, and security, because not every audience needs the same level of detail. The fourth is to treat third-party credentials and access with particular care, since ransomware cases in critical infrastructure often exploit vendors, maintenance, or shared services.

Chile: public consultation and tighter regulation for the power sector

Chile closed August with an important regulatory step, the Comisión Nacional de Energía opened the public consultation for the draft Technical Standard on Cybersecurity and Information Security for the power sector. According to additional coverage, the consultation period will run for 25 calendar days from the publication of the notice in the Diario Oficial, with background materials available on the CNE’s regulatory portal. In parallel, a sector note reported that the Ministry of Energy instructed the draft to be cleaned up, references to the sectoral electrical CSIRT removed, and the proposal submitted for consultation by August 31 at the latest.

Beyond the administrative detail, the political signal is clear, Chile’s power sector is entering a stricter phase of cybersecurity formalization. For companies, that means the discussion is no longer limited to best practices or voluntary recommendations. Expectations will include traceability, documentary evidence, response capacity, and interagency coordination. In other words, cybersecurity in the power sector is moving toward a more explicit compliance model, with potential impact on audits, investment, and project prioritization.

This shift should be read alongside the month’s technical context. The appearance of the advisory on ASE2000 V2, used in electrical substations and energy and water environments, reinforces the need for any new standard to include industrial asset inventory, vulnerability management, safe testing, and third-party component handling. In particular, Chile’s power sector should not assume that the biggest risk comes only from the IT perimeter or corporate email. Substation control systems, communications test sets, and diagnostic tools also deserve regulatory and operational attention.

The public consultation is also an opportunity to address a recurring tension in the region, how to regulate a heterogeneous environment without imposing controls detached from operational reality. If a standard requires response capabilities without accounting for maintenance windows, distributed topologies, or dependence on international vendors, it can end up producing weak paper compliance and insufficient real security. For that reason, from a CISO perspective, the response to the regulatory process should include concrete technical comments on OT segmentation, anomaly detection, vendor access management, restoration testing, and incident reporting criteria.

Colombia: attack on a transmission tower and service continuity

Colombia provided a stark reminder in August that critical power infrastructure also faces physical risk. The Procuraduría General de la Nación warned about the security of transmission infrastructure in Tolima after an attack on a tower in Planadas, an incident that put the continuity of power service at risk. The official communication asked local authorities to report on actions to protect critical infrastructure and prevent further incidents. Caracol Radio expanded the warning by noting damage to the structure of the Alférez, Tesalia 1 and 2 circuits.

This incident is not the same type of event as the Oldelval ransomware case. It is not digital extortion, but an act that compromises the physical layer of the network. That is precisely why it matters so much to sector analysis. It shows that energy resilience depends on a broader security layer that includes surveillance, territorial response, network redundancy, coordination with security forces, and the ability to recover transmission infrastructure.

For operators, the lesson is twofold. First, continuity is not protected only by firewalls and backups, it also requires protecting towers, corridors, substations, and access points. Second, physical and cyber events can interact. An operator already under pressure from a digital incident may be more exposed if it also faces sabotage or material vandalism. Crisis management must account for compound scenarios and coordinated communications with government, regulators, and the public.

The case also points to a governance priority, transmission security should be part of an integrated critical-risk matrix. When judicial or disciplinary authorities ask for stronger security, they are not only reacting to one event, they are setting an expectation of due diligence. Operators must be able to show risk assessments, patrols, monitoring, community coordination, and rapid-response protocols. In areas with a history of incidents, those measures are not optional.

Brazil: high exposure, persistent ransomware, and pressure on utilities

Brazil continues to serve as a regional barometer for cyber exposure. The material for the period shows very high attack telemetry figures and, at the same time, confirms that the energy and utilities sector is among the most heavily hit in the country. That combination should not be read as a mechanical link between the volume of attempts and confirmed incidents. Rather, it shows that Brazil’s ecosystem remains a heavily explored target for opportunistic attackers, and that utilities are among the sectors under the greatest relative pressure.

One important point is that several Brazil-related sources come from press reports that in turn cite security vendor data. It is therefore necessary to clearly separate telemetry from compromise. Saying there were 249.3 billion attempts in the half-year does not mean equivalent attacks materialized against energy, nor that those attempts translated into successful intrusions. It does, however, suggest that defensive hygiene must be continuous. Vulnerability management, email filtering, MFA, segmentation, and access monitoring should be treated as baseline controls, not as exceptional projects.

The report on the ‘Energia e Serviços Públicos’ sector with 2,759 attacks in July reinforces the idea that Brazilian utilities are facing sustained pressure. A figure like that may reflect malware, phishing, scanning, exploit attempts, or IPS blocks, depending on the source methodology. For that reason, the analytical value lies in the sector trend, not in a literal reading of "attacks" as intrusions. Even so, the message for the industry is consistent, the more a business is connected to customer service, billing, telemetry, and remote operations, the more exposed it becomes to credential abuse and extortion campaigns.

Brazil also offers a useful comparative reading. Ransomware figures in the country, cited by different sources, vary between 120, 123, and other nearby counts. That variation does not invalidate the core conclusion, Brazil is among the most affected countries. For a sector report, the consistency of the signal matters more than the absolute uniformity of each count. Even so, the differences should be spelled out to avoid false certainty. If an executive team makes investment or prioritization decisions, it should do so on the basis of robust patterns, not a single isolated number.

Industry and utilities: ASE2000 V2 and substation component risk

The advisory on ASE2000 V2 is one of the most relevant technical findings of the period for the power sector. The component is used as an IEC 60870-5-104 communications test set with TLS, is deployed in substations, and has critical vulnerabilities in versions 2.25 through 2.37. The technical descriptions cited in the material point to arbitrary read and write scenarios for local files and interception of encrypted connections. Version 2.38 was released to correct the flaws.

The importance of this case is not only the severity assigned, but the type of environment affected. Test sets and auxiliary tools often fall outside the radar of classic vulnerability management programs because they are not production assets in the strict sense. However, they are integrated with substation communications, IEC 60870-5-104 testing, and TLS validation, so they can become a path to sensitive information or control traffic. In an energy environment, that is a critical attack surface.

For CISOs, the main lesson is that the OT inventory cannot be limited to PLCs and SCADA. It must also include test equipment, engineering workstations, support components, reusable libraries such as log4net, and third-party tools. If a validation product uses vulnerable dependencies and is deployed in substations, the risk reaches the communications layer. For that reason, remediation should not wait for observed exploitation. An advisory with a 9.8 severity rating and widely deployed versions requires preventive action.

Countries

Argentina

Argentina faces two layers of risk in August 2026. The first is the Oldelval incident, whose systemic importance in moving crude from Vaca Muerta pushes it beyond the idea of a "company affected" and into the wider debate over critical energy infrastructure. The second is the cross-claiming by ransomware groups that are using the case’s visibility to reinforce their extortion narratives. In both cases, administrative systems are where the damage matters most, because even if physical operations were not interrupted, corporate and regulatory processes came under strain.

From a public policy and sector perspective, the case shows a recurring tension in Argentina. Corporate notifications to markets and regulators coexist with the absence of a sector-specific cybersecurity framework as developed as those in other countries in the region. That does not prevent a response, but it does mean the response depends more on each operator’s internal maturity. Energy companies with critical assets should urgently review reporting mechanisms, their relationship with the CNV, evidence preservation, and incident protocols that include exfiltration.

It also serves as a reminder that an attacker does not need to touch industrial systems to create broad impact. If the leak site publishes human resources, finance, or regulatory documents, the company can face privacy, negotiation, reputational, and market trust problems. Defense has to cover that dimension. In Argentina, where public debate over critical infrastructure often intensifies after visible events, the value of an orderly, technically grounded response is even greater.

Brazil

Brazil did not record in the material analyzed a confirmed energy infrastructure incident with direct operational impact comparable to Oldelval or the attack in Tolima, but it did show high exposure and sustained pressure across utilities as a whole. The country remains a benchmark environment for ransomware and malicious telemetry, with the energy and public utilities sector ranking high in sector exposure.

The correct reading is that Brazil combines scale, digitization, and operational heterogeneity. That mix increases the number of attack surfaces, including billing, customer portals, remote access, suppliers, identities, field devices, and industrial systems. In the absence of confirmed OT incidents during the period, the most visible risk remains IT compromises with the potential to spread or trigger reputational pressure. The emphasis should therefore be on identity, segmentation, continuous monitoring, and tested backups, along with early detection of exfiltration.

Chile

Chile is moving toward a more formal cybersecurity oversight framework for electricity. The public consultation on the regulatory draft is more than a formality, it points to obligations that are likely to affect risk management, documentation, and response capabilities. The Chilean power sector should use this moment to review its maturity level, especially in OT assets, substation communications, and supplier relationships.

The ASE2000 V2 case adds a concrete technical driver. If a critical substation component can present severe vulnerabilities, regulation cannot stop at general policies. It has to include live inventories, remediation cycles, restoration testing, and criteria for segregating test and production environments. For operators, the public consultation window is an opportunity to push for requirements that are realistic and still demanding.

Colombia

Colombia is facing material evidence of physical risk against transmission infrastructure in Tolima. The Prosecutor General’s call to reinforce protection for towers and circuits is a sign that energy resilience is also decided in the field. For the sector, the case calls for a review of surveillance protocols, coordination with authorities, and operational redundancy in exposed areas.

The analytical importance of the incident is that it should not be read as an isolated event. When electrical infrastructure is attacked, the question is not only who carried it out, but what level of resilience the system had before the attack and what active response capacity exists afterward. The focus has to go beyond immediate repair and include lessons on design, patrols, territorial control, and communications with the public.

The defining trend this period is the convergence of two worlds that were once analyzed separately, corporate IT extortion and industrial, OT risk. Oldelval represents the first front, Siemens S7 and ASE2000 V2 the second. In between are utilities, which operate with large data volumes, vendors, remote access, and, in many cases, legacy technology. The result is a threat map that no longer allows corporate cybersecurity and operational security to be treated as separate domains.

The second trend is the multi-vector nature of the threat. An energy operator can face ransomware, data theft, industrial vulnerability exploitation, and, in some countries, physical threats to infrastructure. That context requires crisis committees to work with integrated scenarios. If the response plan only covers server encryption, it will fall short. It must include exfiltration, disinformation, reputational impact, regulatory notification, operational continuity, and, where relevant, coordination with physical security.

The third trend is uneven regulatory maturity. Chile is advancing on technical standards, Brazil is strengthening diagnosis and a national committee, Colombia is responding to physical attacks and transmission alerts, and Argentina is still moving the case through corporate communications and media coverage. This unevenness matters because it creates different levels of pressure for companies with a regional footprint. A multinational operator cannot rely on a minimum standard by country, it needs a corporate baseline that exceeds the weakest local floor and makes it possible to align controls.

The fourth trend is the growing technical ease of attacking industrial environments. The advisory on Siemens S7 is especially concerning because it describes the use of AI to generate scripts and disguise them as legitimate tools, as well as the use of public scanning services to locate exposed PLCs. That suggests an attacker does not need to be an ICS specialist to achieve initial results. In practice, any organization with exposed devices, weak credentials, or outdated software is too close to the compromise threshold.

Across the region, the energy and utilities sector should assume pressure will not ease in the near term. The rise in ransomware, credential reuse, the sale of initial access, and the increasing sophistication of reconnaissance campaigns make high-value assets permanent targets. The answer is not just buying more tools, but doing the basics better, inventory, segmentation, hardening, backup, restoration, crisis exercises, and third-party management.

Recommendations for CISOs and Operational Technology Leaders

The immediate priority is to clearly separate risk domains. Administrative systems, user environments, engineering workstations, PLCs, substation test sets, and remote access channels should not be shared without strict controls. If Oldelval proves anything, it is that an attack on administrative systems can lead to extortion pressure and data leakage. If the Siemens S7 advisory proves anything, it is that exposed, misconfigured controllers can be found and exploited with relative ease.

In practice, CISOs in this sector should focus on seven concrete measures. First, conduct a comprehensive inventory of IT and OT assets, including testing components and critical libraries. Second, enforce strong MFA and sharply reduce privileged access, especially for third parties. Third, establish real segmentation between corporate and operational environments, with route and rule validation. Fourth, maintain offline or immutable backups, tested through periodic restores. Fifth, monitor for exfiltration, not just encryption, because data theft is now a central form of pressure. Sixth, review exposure of PLCs, remote services, and industrial ports such as TCP 102 where applicable. Seventh, run joint IT, OT, legal, communications, and continuity exercises for double-extortion or physical-event scenarios.

It also makes sense to strengthen ties with vendors and regulators. In many utilities, compromise paths run through third parties with remote access or through vendor support tools. Contracts should require minimum controls, rapid notification, log review, and the ability to revoke access. At the same time, legal teams need checklists for reporting to authorities, handling personal data, preserving evidence, and managing leak sites. Incident response can no longer be improvised on the day of the event.

Finally, the sector needs more preventive work with senior leadership. Risk committees often treat ransomware as a threat to availability, but the August material shows that data exposure, reputational damage, and regulatory pressure can be just as costly, or more so. If an energy company appears on a leak site, even if its network does not go down, the impact can show up in audits, contracts, access to capital, and public trust. That conversation needs to be established at board level.

Material limitations

This report is based exclusively on the research material provided and therefore reflects what was published or cited in those sources during the analyzed window. The absence of a fact in the material does not mean that fact is absent from the region. Likewise, the lack of a specific vulnerability in the material does not mean there are no active or exploited vulnerabilities in energy and utilities. In particular, when telemetry figures are mentioned, they refer to attempts, blocks, or malicious activity observed by vendors, not confirmed incidents.

A victim’s appearance on a leak site should not be taken as official confirmation of compromise, and neither should an attribution published by a group be treated as independently verified. In the case of Oldelval, the material includes corporate notices, third-party analysis, and threat actor claims, which means confirmed facts must be separated carefully from allegations. Finally, the data from Brazil on attack attempts, ransomware counts, and sector exposure helps frame pressure and prioritization, but it does not by itself support a number of operational incidents in energy or utilities.

Frequently Asked Questions

Were there any disruptions to electricity service or hydrocarbon transport?

In the material reviewed, no disruption to electricity service was confirmed in connection with the period's main incidents. At Oldelval, the company said crude transport was not interrupted. In Colombia, there was an attack on transmission infrastructure that put continuity at risk, but the available coverage focuses on the alert and protection of the asset, not on a prolonged outage.

What was the most relevant incident of the month?

By sector impact and regional reach, the Oldelval case in Argentina was the most relevant. It combined disruption to administrative systems, regulatory notification, ransomware claims, and later reports of possible data exfiltration. Even though transport was not interrupted, the case exposed a sensitive attack surface in critical oil infrastructure.

What should a CISO in the sector look at first?

They should prioritize full inventory, IT/OT segmentation, MFA, third-party controls, and tested recovery. They also need to prepare for data exfiltration response, not only encryption. The advisory on Siemens S7 and the ASE2000 V2 case show that industrial exposure remains a real risk.

Do the high attack numbers in Brazil mean the power sector was hit the hardest?

No. The figures cited for Brazil include telemetry and broad sector counts. They indicate high pressure on the digital ecosystem, and they do show that energy and utilities were among the most targeted sectors in July, but they do not, by themselves, show how many operational incidents each company or subsector suffered.

Is there a clear regional pattern?

Yes, the convergence of ransomware, data leakage, industrial vulnerabilities, and physical risk. Argentina shows the corporate extortion vector, Chile the regulatory maturity and substation vulnerabilities, Colombia the physical risk to transmission, and Brazil sustained, elevated pressure on utilities. The common challenge is integrating cybersecurity, continuity, and physical security into a single management model.

Sources