VORANT. Threat Intelligence Research Sign in Create a free account

INC Ransom claims Colorado electric co-op breach

high threat energy

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

INC Ransom claims to have stolen customer, financial, and OT/SCADA data from Sangre de Cristo Electric Association after negotiations collapsed.

Ransomware group INC Ransom has publicly listed Sangre de Cristo Electric Association (SDCEA), a Colorado electric utility, as a victim after what it describes as failed negotiations following a data compromise. The group claims to have exfiltrated customer PII, financial and payment data, utility account information, and highly sensitive operational technology data, including details on electrical distribution infrastructure, substations, transformers, feeders, renewable-generation assets, outage systems, and SCADA/EMS environments. Most concerning for defenders is the claimed theft of control-system credentials, API keys, and OT security configurations, which if accurate could enable follow-on access to the utility's industrial control environment beyond the initial data theft.

According to the posting, SDCEA's CEO ended negotiations with the threat actor, prompting INC Ransom to issue a public extortion notice and threaten further disruptive action. No technical indicators, exploited vulnerability, or initial access vector are disclosed in this listing. This is a leak-site extortion notice rather than a technical writeup, so defenders at utilities and energy-sector organizations should treat any exposed OT credentials as compromised, prioritize rotation of control-system credentials and API keys, and review SCADA/EMS network segmentation and authentication logging for anomalous access.

Given the targeting of critical energy infrastructure and the claimed exposure of OT/SCADA credentials, this incident carries elevated risk beyond typical data-theft extortion, though no evidence of active exploitation of the stolen credentials or operational disruption has been reported at this time.

Mentioned in this report

Threat actors INC Ransom
Malware INC Ransom

Source reporting: https://www.ransomware.live/id/U2FuZ3JlIGRlIENyaXN0byBFbGVjdHJpYyBBc3NvY2lhdGlvbkBpbmNyYW5zb20=

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,584 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs