News Room
16
Share
highCritical Infrastructure

Surge in Cybercriminal Attacks on North American Critical Infrastructure

Cybercriminals have intensified attacks on North America's critical infrastructure, targeting power grids, water systems, and healthcare sectors, posing significant threats to national security.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Surge in Cybercriminal Attacks on North American Critical Infrastructure for ₿ 0.10 BTC. Contact us.

12 March 2026Last updated 12 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
High
Actor Type:
Cybercriminal
Geography:
North America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

In early 2026, cybercriminal activities targeting North America's critical infrastructure have escalated, with notable incidents affecting power grids, water systems, and healthcare sectors. These attacks underscore the vulnerabilities within essential services and highlight the pressing need for enhanced cybersecurity measures.

Recent Incidents

  • Power Grid Attacks: In December 2025, the Polish power grid experienced a cyberattack attributed to the threat actor group Berserk Bear. The attack targeted both IT and physical industrial devices, affecting renewable energy plants and a combined heat and power plant. (en.wikipedia.org)

  • Water System Breach: A hacker recently offered 139 GB of sensitive engineering data stolen from Pickett and Associates, a firm serving major utilities and mining companies across the U.S. and the Caribbean. The leaked data included files related to Tampa Electric Company, Duke Energy Florida, and American Electric Power, highlighting the potential risks to water and energy infrastructure. (itpro.com)

  • Healthcare Sector Targeted: The Agenda ransomware group, also known as Qilin, has been deploying a Linux-based ransomware binary on Windows hosts by exploiting legitimate remote management and file transfer tools. Since January 2025, Agenda has affected over 700 victims in 62 countries, primarily targeting organizations in the USA, France, Canada, and the UK, with manufacturing, technology, financial services, and healthcare sectors being the hardest hit. (ics-cert.kaspersky.com)

Emerging Threat Actors

Several cybercriminal groups have been identified as active threats to critical infrastructure:

  • Agenda (Qilin): This ransomware group has been active since January 2025, deploying sophisticated attacks across various sectors, including healthcare and energy. (ics-cert.kaspersky.com)

  • Z-Pentest: Emerging in late 2024, Z-Pentest has been targeting industrial control systems (ICS), including water utility systems in the U.S. and agricultural biotechnology SCADA systems in Taiwan. (cyble.com)

  • Berserk Bear: Attributed to the December 2025 cyberattack on the Polish power grid, this group has demonstrated capabilities to target both IT and physical industrial devices. (en.wikipedia.org)

Implications and Recommendations

The recent surge in cybercriminal attacks on critical infrastructure in North America poses significant risks to national security and public safety. To mitigate these threats, the following measures are recommended:

  • Enhanced Cybersecurity Protocols: Organizations should implement robust cybersecurity frameworks, including regular system updates, intrusion detection systems, and comprehensive incident response plans.

  • Cross-Sector Collaboration: Establishing information-sharing platforms among critical infrastructure sectors can facilitate timely threat intelligence dissemination and coordinated defense strategies.

  • Employee Training: Regular training programs on cybersecurity best practices can reduce the risk of social engineering attacks and improve overall organizational resilience.

By proactively addressing these vulnerabilities, stakeholders can strengthen the security posture of critical infrastructure and ensure the continued delivery of essential services to the public.

Sources

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo