Critical Infrastructure Under Siege: Cybercriminals Escalate Attacks on North American Systems
Cybercriminals have intensified attacks on North America's critical infrastructure, targeting power grids, water systems, and healthcare sectors, posing a critical threat to national security.
Encrygma is selling the entire Full Cyber Weapon Research of Critical Infrastructure Under Siege: Cybercriminals Escalate Attacks on North American Systems for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, cybercriminal activities targeting North America's critical infrastructure have escalated, with significant incidents affecting power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These attacks underscore the urgent need for enhanced cybersecurity measures to safeguard essential services.
Recent Incidents
-
Power Grids: On December 29, 2025, the Polish power grid experienced a cyberattack attributed to the Russian state-sponsored group Sandworm. The attack targeted both IT and industrial devices, affecting renewable energy plants and a combined heat and power plant. (en.wikipedia.org)
-
Water Systems: In Canada, hacktivist groups have breached water and energy facilities, manipulating water pressure valves and triggering false alarms in oil and gas companies. These actions highlight vulnerabilities in ICS and the potential for widespread disruption. (techradar.com)
-
Healthcare Sector: The healthcare industry has been a prime target for ransomware attacks. In Q3 2025, Kaspersky ICS CERT reported that cybercriminals used spear-phishing emails to deliver malware, leading to data breaches and operational disruptions in healthcare organizations. (ics-cert.kaspersky.com)
Emerging Threat Actors and Tactics
The threat landscape has evolved with the emergence of new cybercriminal groups targeting ICS and OT systems:
-
Sylvanite: Acting as a "rapid exploitation broker," Sylvanite facilitates access for groups like Voltzite to critical infrastructure, including the U.S. electric grid. (securityweek.com)
-
Azurite and Pyroxene: These groups have been identified as active in targeting ICS and OT systems, indicating a growing trend of cybercriminals focusing on critical infrastructure sectors. (securityweek.com)
Additionally, the Werewolves ransomware group has been active since 2023, employing double extortion techniques and utilizing tools like Anydesk, Netscan, CobaltStrike, Meterpreter, and Lockbit to compromise organizations across various sectors, including healthcare. (ics-cert.kaspersky.com)
Implications and Recommendations
The increasing sophistication and frequency of cyberattacks on critical infrastructure necessitate immediate and comprehensive cybersecurity measures:
-
Enhanced Monitoring and Detection: Implement advanced intrusion detection systems to identify and respond to anomalous activities promptly.
-
Regular Vulnerability Assessments: Conduct frequent security audits to identify and mitigate potential vulnerabilities in ICS and OT systems.
-
Employee Training: Provide ongoing cybersecurity training to staff to recognize and respond to phishing attempts and other social engineering tactics.
-
Collaboration and Information Sharing: Engage in information-sharing initiatives with industry peers and government agencies to stay informed about emerging threats and best practices.
By adopting a proactive and collaborative approach, organizations can bolster their defenses against cybercriminals targeting critical infrastructure, thereby ensuring the continuity and security of essential services.
Sources
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate

Industrial Sector Faces Record Ransomware Surge as Qilin Group Targets Critical Infrastructure

