# INC Ransom claims Colorado electric co-op breach

Published: 2026-10-02 · Severity: high · Sectors: energy
Canonical: https://vorant.io/reports/acdc0000-697c-50fe-8cc9-f3e6f8da5fa6/inc-ransom-claims-colorado-electric-co-op-breach

> INC Ransom claims to have stolen customer, financial, and OT/SCADA data from Sangre de Cristo Electric Association after negotiations collapsed.

Ransomware group INC Ransom has publicly listed Sangre de Cristo Electric Association (SDCEA), a Colorado electric utility, as a victim after what it describes as failed negotiations following a data compromise. The group claims to have exfiltrated customer PII, financial and payment data, utility account information, and highly sensitive operational technology data, including details on electrical distribution infrastructure, substations, transformers, feeders, renewable-generation assets, outage systems, and SCADA/EMS environments. Most concerning for defenders is the claimed theft of control-system credentials, API keys, and OT security configurations, which if accurate could enable follow-on access to the utility's industrial control environment beyond the initial data theft.

According to the posting, SDCEA's CEO ended negotiations with the threat actor, prompting INC Ransom to issue a public extortion notice and threaten further disruptive action. No technical indicators, exploited vulnerability, or initial access vector are disclosed in this listing. This is a leak-site extortion notice rather than a technical writeup, so defenders at utilities and energy-sector organizations should treat any exposed OT credentials as compromised, prioritize rotation of control-system credentials and API keys, and review SCADA/EMS network segmentation and authentication logging for anomalous access.

Given the targeting of critical energy infrastructure and the claimed exposure of OT/SCADA credentials, this incident carries elevated risk beyond typical data-theft extortion, though no evidence of active exploitation of the stolen credentials or operational disruption has been reported at this time.

## Mentioned in this report

- Threat actors: INC Ransom
- Malware: INC Ransom

Source reporting: https://www.ransomware.live/id/U2FuZ3JlIGRlIENyaXN0byBFbGVjdHJpYyBBc3NvY2lhdGlvbkBpbmNyYW5zb20=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/acdc0000-697c-50fe-8cc9-f3e6f8da5fa6/inc-ransom-claims-colorado-electric-co-op-breach.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
