Fenestra TI's first sector-focused Threat Landscape examines the global energy and utilities sector across July to September 2026, and looks ahead to the winter. It draws on Fenestra's own collection and analysis across news, open-source channels, ransomware leak sites and vendor research to give security, risk and operations teams a grounded view of how the threat to energy has changed.
Key Findings
- Energy is now a primary target, not collateral. Russia and Ukraine striking each other's energy infrastructure accounted for around two-thirds of reported energy-attack days in July and August — refineries and export terminals on one side, power plants, substations and gas production on the other.
- The energy war is widening in the Gulf. The Gulf's share of reported energy-attack days rose from 27% in July to 37% in September as attacks moved ashore, culminating in the shutdown of Saudi Arabia's East–West pipeline and Brent crude above $108.
- Ransomware is concentrated on oil & gas. Oil & gas made up 48% of energy-sector ransomware victims, with contractors and suppliers a further 18%. Two related groups, TheGentlemen and Qilin, accounted for almost a third.
- Firewalls are the front door. The groups most active against energy repeatedly get in through firewall and VPN vulnerabilities — Fortinet above all, alongside Palo Alto, Cisco and WatchGuard — and through stolen logins.
- State-linked activity is reaching operational systems, from an Iran-linked attack that took a UK power plant offline for four days to an ongoing campaign against internet-exposed PLCs in energy and water facilities, and cyber incidents aboard tankers and an LNG carrier.
Inside the Report
- Physical & Geospatial Security — where attacks on energy infrastructure concentrated, month on month, across Russia and Ukraine, the Gulf, Libya and Europe.
- Maritime & Energy Supply Chain — attacks on tankers and LNG carriers at Hormuz and in the Red Sea, the emerging threat of cyber attacks on ships, and the shadow-fleet dimension.
- Ransomware — who was hit, by segment, group and country, and how the leading groups gain access.
- Cyber Threat Intelligence — state-linked activity against energy and water operational technology, and the vulnerabilities being exploited now.
- Winter 2026–27 Outlook — six key judgements on what to expect through March.
- Recommended Actions — where to spend effort before winter.
Download the full report (PDF)
Get in touch if you'd like to discuss how these trends apply to your organisation's energy exposure, supply chain or operating locations.
