Data from multiple US electric utilities stolen in Black Basta ransomware attack

Data from multiple US electric utilities stolen in Black Basta ransomware attack

Multiple US electric utilities had their data stolen in an October Black Basta ransomware attack that targeted Chicago-based Sargent & Lundy, a US government contractor that handles critical infrastructure projects across the country, CNN reported.

Sargent & Lundy is an engineering company that has designed more than 900 power stations and thousands of miles of power systems and that holds sensitive data on those projects, and also handles nuclear security issues.

According to sources familiar with the matter, the incident was contained and remediated, and didn’t appear to have a broader impact on other power-sector firms. There is no evidence that the stolen data, which includes “model files” and “transmission data” the firm uses for utility projects, has been leaked on the dark web.

Sargent & Lundy’s spokeswoman told CNN that the incident had minimal impact on the company’s business, but provided no further information regarding the attack.

Black Basta is a ransomware group operating as ransomware-as-a-service (RaaS) that was initially spotted in April 2022. The group uses the double-extortion tactics and a number of tools, including the Qakbot trojan and PrintNightmare exploit. According to a recent report, Black Basta was one of the most prolific ransomware groups in Q3, 2022 along with LockBit, Hive, Alphv (aka BlackCat) and BianLian.


Back to the list

Latest Posts

Cyber Security Week in Review: May 23, 2025

Cyber Security Week in Review: May 23, 2025

In brief: Several major malware operations disrupted,  hackers exploit Ivanti and Cityworks zero-days, and more.
23 May 2025
Russian GRU hackers accused of massive espionage campaign across NATO and allied nations

Russian GRU hackers accused of massive espionage campaign across NATO and allied nations

The cyber offensive reportedly struck dozens of entities, spanning both government and private sectors.
22 May 2025
Chinese-speaking threat actors exploit Cityworks zero-day to hack into US govt agencies

Chinese-speaking threat actors exploit Cityworks zero-day to hack into US govt agencies

The attacks have been ongoing since at least January 2025.
22 May 2025