Surge in Cybercriminal Attacks on North American Critical Infrastructure
Cybercriminals have intensified attacks on North America's critical infrastructure, targeting power grids, water systems, and healthcare sectors, posing significant threats to national security.
Encrygma is selling the entire Full Cyber Weapon Research of Surge in Cybercriminal Attacks on North American Critical Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, cybercriminal activities targeting North America's critical infrastructure have escalated, with notable incidents affecting power grids, water systems, and healthcare sectors. These attacks underscore the vulnerabilities within essential services and highlight the pressing need for enhanced cybersecurity measures.
Recent Incidents
-
Power Grid Attacks: In December 2025, the Polish power grid experienced a cyberattack attributed to the threat actor group Berserk Bear. The attack targeted both IT and physical industrial devices, affecting renewable energy plants and a combined heat and power plant. (en.wikipedia.org)
-
Water System Breach: A hacker recently offered 139 GB of sensitive engineering data stolen from Pickett and Associates, a firm serving major utilities and mining companies across the U.S. and the Caribbean. The leaked data included files related to Tampa Electric Company, Duke Energy Florida, and American Electric Power, highlighting the potential risks to water and energy infrastructure. (itpro.com)
-
Healthcare Sector Targeted: The Agenda ransomware group, also known as Qilin, has been deploying a Linux-based ransomware binary on Windows hosts by exploiting legitimate remote management and file transfer tools. Since January 2025, Agenda has affected over 700 victims in 62 countries, primarily targeting organizations in the USA, France, Canada, and the UK, with manufacturing, technology, financial services, and healthcare sectors being the hardest hit. (ics-cert.kaspersky.com)
Emerging Threat Actors
Several cybercriminal groups have been identified as active threats to critical infrastructure:
-
Agenda (Qilin): This ransomware group has been active since January 2025, deploying sophisticated attacks across various sectors, including healthcare and energy. (ics-cert.kaspersky.com)
-
Z-Pentest: Emerging in late 2024, Z-Pentest has been targeting industrial control systems (ICS), including water utility systems in the U.S. and agricultural biotechnology SCADA systems in Taiwan. (cyble.com)
-
Berserk Bear: Attributed to the December 2025 cyberattack on the Polish power grid, this group has demonstrated capabilities to target both IT and physical industrial devices. (en.wikipedia.org)
Implications and Recommendations
The recent surge in cybercriminal attacks on critical infrastructure in North America poses significant risks to national security and public safety. To mitigate these threats, the following measures are recommended:
-
Enhanced Cybersecurity Protocols: Organizations should implement robust cybersecurity frameworks, including regular system updates, intrusion detection systems, and comprehensive incident response plans.
-
Cross-Sector Collaboration: Establishing information-sharing platforms among critical infrastructure sectors can facilitate timely threat intelligence dissemination and coordinated defense strategies.
-
Employee Training: Regular training programs on cybersecurity best practices can reduce the risk of social engineering attacks and improve overall organizational resilience.
By proactively addressing these vulnerabilities, stakeholders can strengthen the security posture of critical infrastructure and ensure the continued delivery of essential services to the public.
Sources
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Spanish Rail Infrastructure Breach: Adif Web Systems Exploited to Compromise Renfe Operations

Spanish Rail Operator Renfe Compromised via AI-Assisted Breach of Adif Infrastructure

