News Room
16
Share
criticalCritical Infrastructure

Critical Infrastructure Under Siege: Cybercriminals Escalate Attacks on North American Systems

Cybercriminals have intensified attacks on North America's critical infrastructure, targeting power grids, water systems, and healthcare sectors, posing a critical threat to national security.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Critical Infrastructure Under Siege: Cybercriminals Escalate Attacks on North American Systems for ₿ 0.10 BTC. Contact us.

31 March 2026Last updated 31 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
North America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

In early 2026, cybercriminal activities targeting North America's critical infrastructure have escalated, with significant incidents affecting power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These attacks underscore the urgent need for enhanced cybersecurity measures to safeguard essential services.

Recent Incidents

  • Power Grids: On December 29, 2025, the Polish power grid experienced a cyberattack attributed to the Russian state-sponsored group Sandworm. The attack targeted both IT and industrial devices, affecting renewable energy plants and a combined heat and power plant. (en.wikipedia.org)

  • Water Systems: In Canada, hacktivist groups have breached water and energy facilities, manipulating water pressure valves and triggering false alarms in oil and gas companies. These actions highlight vulnerabilities in ICS and the potential for widespread disruption. (techradar.com)

  • Healthcare Sector: The healthcare industry has been a prime target for ransomware attacks. In Q3 2025, Kaspersky ICS CERT reported that cybercriminals used spear-phishing emails to deliver malware, leading to data breaches and operational disruptions in healthcare organizations. (ics-cert.kaspersky.com)

Emerging Threat Actors and Tactics

The threat landscape has evolved with the emergence of new cybercriminal groups targeting ICS and OT systems:

  • Sylvanite: Acting as a "rapid exploitation broker," Sylvanite facilitates access for groups like Voltzite to critical infrastructure, including the U.S. electric grid. (securityweek.com)

  • Azurite and Pyroxene: These groups have been identified as active in targeting ICS and OT systems, indicating a growing trend of cybercriminals focusing on critical infrastructure sectors. (securityweek.com)

Additionally, the Werewolves ransomware group has been active since 2023, employing double extortion techniques and utilizing tools like Anydesk, Netscan, CobaltStrike, Meterpreter, and Lockbit to compromise organizations across various sectors, including healthcare. (ics-cert.kaspersky.com)

Implications and Recommendations

The increasing sophistication and frequency of cyberattacks on critical infrastructure necessitate immediate and comprehensive cybersecurity measures:

  • Enhanced Monitoring and Detection: Implement advanced intrusion detection systems to identify and respond to anomalous activities promptly.

  • Regular Vulnerability Assessments: Conduct frequent security audits to identify and mitigate potential vulnerabilities in ICS and OT systems.

  • Employee Training: Provide ongoing cybersecurity training to staff to recognize and respond to phishing attempts and other social engineering tactics.

  • Collaboration and Information Sharing: Engage in information-sharing initiatives with industry peers and government agencies to stay informed about emerging threats and best practices.

By adopting a proactive and collaborative approach, organizations can bolster their defenses against cybercriminals targeting critical infrastructure, thereby ensuring the continuity and security of essential services.

Sources

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo