Cybercriminals Intensify Attacks on North America's Critical Infrastructure
Cybercriminals are increasingly targeting North America's critical infrastructure, including power grids, water systems, and healthcare, posing significant threats to national security and public safety.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, cybercriminal activities targeting North America's critical infrastructure have escalated, with significant incidents affecting power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These attacks underscore the urgent need for enhanced cybersecurity measures to safeguard essential services and national security.
Recent Incidents and Trends
-
Power Grids: In December 2025, a sophisticated cyberattack targeted Poland's power grid, affecting renewable energy plants and a combined heat and power plant. The attack was attributed to the threat actor group known as Sandworm. (en.wikipedia.org)
-
Water Systems: The Canadian government reported multiple incidents where cybercriminals accessed ICS in water facilities, manipulating water pressure valves and triggering false alarms. These attacks highlight vulnerabilities in critical water infrastructure. (techradar.com)
-
Industrial Control Systems (ICS): In May 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about unsophisticated cyber actors targeting ICS/SCADA systems within U.S. critical infrastructure sectors, including energy and transportation. These attacks often involve basic intrusion techniques, leading to operational disruptions and potential physical damage. (cisa.gov)
-
Healthcare Sector: The FBI's 2025 Internet Crime Complaint Center (IC3) report condemned the increasing trend of cybercriminals targeting healthcare institutions. The report noted a surge in ransomware attacks, with over 200 variants being monitored, resulting in significant financial losses. (techradar.com)
-
Financial Sector: Between July and September 2024, BlackBerry detected 600,000 cyberattacks on critical infrastructure, with 45% targeting the financial sector. These attacks underscore the persistent threat to financial institutions and the broader economy. (blackberry.com)
Emerging Threat Actors and Tactics
Cybercriminal groups are increasingly targeting critical infrastructure sectors, employing sophisticated tactics such as ransomware, spear-phishing, and exploiting vulnerabilities in ICS/SCADA systems. Notably, the threat actor group Qilin was responsible for 13% of global ransomware attacks in 2025. (nccgroup.com)
Recommendations
To mitigate the risks associated with cybercriminal attacks on critical infrastructure, the following measures are recommended:
-
Enhanced Monitoring and Detection: Implement advanced monitoring systems to detect and respond to cyber threats in real-time.
-
Regular Vulnerability Assessments: Conduct periodic assessments of ICS/SCADA systems to identify and remediate vulnerabilities.
-
Employee Training: Provide comprehensive cybersecurity training to staff to recognize and respond to phishing attempts and other social engineering tactics.
-
Collaboration with Authorities: Establish strong partnerships with federal and local agencies to share threat intelligence and coordinate responses to cyber incidents.
Conclusion
The escalation of cybercriminal attacks on critical infrastructure in North America presents a significant threat to national security and public safety. Proactive measures, including enhanced monitoring, regular assessments, employee training, and inter-agency collaboration, are essential to bolster the resilience of critical infrastructure against evolving cyber threats.
Highlights:
- I can't think of anything that's off limits to them': FBI slams cybercriminals for attacking schools, hospitals, as crypto fraud soars, Published on Tuesday, April 07
- Canadian government claims hacktivists are attacking water and energy facilities, Published on Friday, October 31
- Why cyber attacks on critical national infrastructure are such a huge threat, Published on Wednesday, March 18
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Cyber Warfare: Iranian-Linked Actors Target Western Power and Water Infrastructure

Iranian Cyber Campaign Escalates: UK Power Plant Breach and US Water Infrastructure Attacks Confirmed

