Home Blog TX Oil & Gas Threat Brief

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →

Energy / OT  ·  June 2026  ·  CoreRecon Threat Intelligence

Texas sits at the center of the US energy economy. The Permian Basin alone produces more than 6 million barrels per day — 81% of the top 50 US E&P operators' combined output. That concentration of critical infrastructure makes the state the highest-priority target in the country for ransomware groups, nation-state actors, and opportunistic hacktivists.

In 2024 alone, ransomware attacks against oil and gas operators increased 935% year-over-year (Zscaler, April 2024–April 2025). Three Texas-headquartered companies — Halliburton, Newpark Resources, and ENGlobal — disclosed cybersecurity incidents to the SEC between August and November 2024. All three involved operational disruption. Halliburton's confirmed $35M direct loss is now the precedent-setting number every TX operator's board is aware of.

This brief covers the four incidents that define the current threat environment, the regulatory obligations that create compliance urgency, the OT/IT convergence vulnerabilities that persist across mid-market operators, and what a 90-day hardening roadmap looks like for a Permian Basin independent E&P or oilfield services firm.

$35M
Halliburton direct loss — RansomHub, Aug 2024 (SEC 8-K confirmed)
935%
YoY surge in oil & gas ransomware attacks (Zscaler, Apr 2025)
30,000+
TX oil & gas operators registered with TRRC — largest energy jurisdiction in the US

Four Incidents Defining the 2024–2025 TX O&G Threat Environment

These aren't theoretical scenarios. All four incidents below involved Texas-headquartered or Texas-operating companies, with confirmed financial impact and regulatory filings. They represent the attack patterns most likely to affect your organization.

Halliburton — RansomHub Ransomware (Aug 2024)
$35M DIRECT LOSS
📍 Houston, TX 👥 ~48,000 employees 📋 SEC 8-K filed Aug 23, 2024

On August 21, 2024, Halliburton — the world's second-largest oilfield services company — detected unauthorized access to its systems and began taking infrastructure offline. RansomHub, using double-extortion tactics (encryption + data theft), disrupted invoice and purchase order processing globally. The North Belt campus in Houston was directly affected.

Halliburton engaged Mandiant for incident response and notified the FBI. The company filed an SEC Form 8-K under the new Item 1.05 rule within 48 hours of discovery — a timeline every public TX operator's legal team now benchmarks against. Total confirmed impact: $35M in direct charges, as disclosed in subsequent SEC filings.

The supplier notification Halliburton sent on August 26 contained IoCs including "maintenance.exe" — the RansomHub encryptor — demonstrating how quickly a major operator's supply chain can become an attack intelligence source for the same group targeting their vendors.

Colonial Pipeline — DarkSide Ransomware (May 2021)
EAST COAST FUEL CRISIS
📍 Houston, TX (origin) 🛢️ 5,500 miles — 45% East Coast fuel 💸 $4.4M ransom paid

Colonial Pipeline originates in Houston, TX. On May 6, 2021, a compromised VPN credential — on a legacy VPN account without MFA — allowed DarkSide to exfiltrate 100GB of data before deploying ransomware on May 7. Colonial proactively shut down all 5,500 miles of pipeline operations. The resulting fuel crisis caused the White House to declare a state of emergency and DOT to issue emergency fuel transport authorizations.

The $4.4M ransom (75 BTC) was paid. The DOJ subsequently recovered $2.3M of it. The FBI confirmed attribution to DarkSide, a Russia-based RaaS group. The direct trigger: a single compromised password with no MFA on a legacy VPN account.

This incident directly created TSA Security Directive Pipeline-2021-01 (issued May 27, 2021) and all subsequent SD-02 versions now in force. The current mandatory requirement — SD-02F (effective May 3, 2025) — exists because of this Texas-origin incident.

Newpark Resources — Ransomware (Oct 2024)
BUSINESS APPS OFFLINE
📍 The Woodlands, TX 📋 NYSE: NR 📅 Discovered Oct 29, 2024

Newpark Resources — a Woodlands-based oilfield equipment supplier serving E&P operators across the Permian Basin and Eagle Ford — discovered a ransomware attack on October 29, 2024. Financial and operating reporting applications were taken offline. Manufacturing and field operations continued using established downtime procedures, which limited direct operational impact.

The significance: Newpark is not a small operator. It's a NYSE-listed, $500M+ market cap oilfield services company with established IT infrastructure. If Newpark's systems were disrupted, the ICP tier below it — private OFS companies with 50–500 employees — is almost certainly running on weaker security posture. The attack actor was not publicly attributed.

ENGlobal — Data Exfiltration (Nov 2024–Jan 2025)
6-WEEK DISRUPTION
📍 Houston, TX 📋 NASDAQ: ENG 🔐 Sensitive personal data stolen

ENGlobal Corporation — a Houston-based engineering and professional services firm serving energy sector defense contractors — detected unauthorized access to its IT systems in November 2024. Business applications were disrupted for approximately six weeks. In a January 27, 2025 SEC update, the company confirmed that sensitive personal information had been stolen and that notifications to affected individuals and regulatory agencies were underway.

ENGlobal's profile — engineering services firm with DoD contracts — makes this case particularly relevant for oilfield service companies that have indirect federal contract exposure. If your company holds any DoD fuel supply, logistics, or base services contracts, the CMMC 2.0 framework applies to your CUI environment — and an attack like ENGlobal's would trigger DFARS obligations on top of the SEC and Texas reporting requirements.

The Regulatory Stack: What TX Operators Are Obligated to Do

Three regulatory frameworks — TSA SD-02F, SEC Form 8-K Item 1.05, and CMMC 2.0 — create immediate compliance deadlines for different segments of the TX oil and gas ICP. Texas TDPSA adds a fourth layer for all operators processing personal data of Texas residents.

TSA SD-02F
Effective May 3, 2025. Mandatory for TSA-designated critical pipeline operators. Requires: Cybersecurity Implementation Plan (submitted to TSA for approval), Cybersecurity Incident Response Plan (5 objectives, tested annually), and Cybersecurity Assessment Program (minimum 30% of controls per year).
Up to $11,904/day per violation
SEC 8-K Item 1.05
Effective December 18, 2023. All public companies must disclose material cybersecurity incidents within 4 business days of determining materiality. Halliburton's Aug 2024 8-K (filed within 48 hours) is the precedent. Applies to every publicly-traded TX E&P, midstream MLP, or OFS company.
SEC enforcement (CETU unit active)
CMMC 2.0
Final rule effective Nov 10, 2025 (Phase 1). Any TX operator with DoD contracts involving Federal Contract Information or Controlled Unclassified Information must achieve CMMC Level 1 at contract award. Level 2 (110 NIST SP 800-171 controls) requires C3PAO third-party certification from Nov 2026.
Contract loss on non-compliance
Texas TDPSA
Effective July 1, 2024. Applies to all Texas businesses processing personal data of Texas residents — including oil and gas operators above the SBA small business threshold. Requires breach response plans, consumer notification, and 30-day cure period before AG enforcement.
Up to $7,500 per violation
⚠ TRRC Advisory

The Texas Railroad Commission issued a joint advisory with EPA, FBI, CISA, and NSA warning TX oil and gas operators to remove PLCs from direct internet exposure via secure gateway and firewall. This advisory establishes a de facto cybersecurity standard — operators with internet-facing PLCs are operating out of alignment with TRRC-adjacent expectations. Most mid-market Permian Basin operators have not completed a PLC exposure audit.

OT/IT Convergence: Why Traditional IT Security Misses the Real Risk

The primary attack surface for TX oil and gas operators is not email or cloud applications — it's the convergence of IT and OT networks that most mid-market operators have never formally audited. Colonial Pipeline's attack vector was a corporate VPN account. The ransomware never touched the pipeline control systems directly — Colonial shut down operations as a precaution because their IT/OT boundary wasn't well enough defined to risk it.

The six highest-priority OT/IT convergence vulnerabilities for TX operators:

  1. 01 Unsegmented IT/OT networks — The most common gap. Ransomware enters via phishing or VPN compromise, spreads across the flat network to SCADA/HMI workstations, and forces operational shutdown as a precaution. Most mid-market TX operators have not implemented a proper DMZ between corporate IT (Level 3) and SCADA/HMI (Level 2) per ISA/IEC 62443 zone-and-conduit architecture.
  2. 02 Internet-facing PLCs and HMIs — Iranian-affiliated actors explicitly targeted internet-exposed PLCs in the joint EPA/FBI/CISA/NSA advisory (referenced by TRRC). CyberArmyofRussia_Reborn demonstrated in 2024 that even basic HMI manipulation causes tangible OT disruption — no nation-state TTPs required.
  3. 03 Vendor remote access — 45% of energy sector breaches in 2024 were third-party related (SecurityScorecard/KPMG). Halliburton's own Aug 26 supplier notification demonstrated how vendor compromise at a major operator creates IoC data that can be used to target the vendor's clients. TeamViewer, RDP to SCADA, and proprietary OT remote access platforms are all commonly deployed without session recording or just-in-time provisioning.
  4. 04 Legacy Windows-based HMI workstations — Permian Basin operators running Windows 7 / Server 2008-era SCADA workstations with no patching cycle. Unpatched HMIs are directly targetable by commodity ransomware that would never reach an air-gapped OT environment.
  5. 05 Protocol exposure (Modbus/DNP3/OPC-UA) — Modbus/TCP and DNP3 have no native encryption or authentication. Devices that communicate in plaintext on a network segment reachable from corporate IT are one lateral move away from attack.
  6. 06 Drilling rig telemetry — Real-time MWD (Measurement While Drilling) data transmitted from wellsite to corporate over cellular/satellite with minimal security controls. Bidirectional data flow creates an ingress point. Remote rigs are rarely hardened to the same standard as corporate infrastructure.

Nation-State Actors: The Threat Beyond Ransomware

The ransomware incidents above represent the financially motivated tier of the threat landscape. The nation-state tier is operating with different objectives — and is already inside US energy infrastructure.

Volt Typhoon (China PRC) has been confirmed by CISA, FBI, and NSA as actively pre-positioning on US critical infrastructure IT networks since at least 2021, with the assessed purpose of enabling sabotage capability — not espionage. CISA explicitly named Texas pipeline operators and ERCOT as targets. Volt Typhoon's subgroup "Voltzite" maintained unauthorized access to a New England utility's OT network for approximately 10 months (Feb–Nov 2024) before detection, exfiltrating GIS data, network diagrams, and operating instructions. The group uses living-off-the-land (LotL) techniques that bypass traditional signature-based detection.

Iranian-affiliated actors targeted oil and gas PLCs and internet-facing OT devices in a joint EPA/FBI/CISA/NSA advisory, with the Texas Railroad Commission issuing a supplementary warning to TX operators. Some Texas critical infrastructure organizations had already experienced disruptions related to Iranian-affiliated threats at the time of the advisory.

Dragos Assessment — Feb 2025

Volt Typhoon is "arguably the most crucial threat group to track in critical infrastructure." The group rebuilt its KV botnet within weeks of the FBI-disrupted Jan 2024 takedown. Assume pre-positioning is ongoing, including in Texas energy networks.

90-Day Hardening Roadmap

The following actions are prioritized by regulatory urgency and risk reduction value. Operators with existing Sentinel-tier coverage can move directly to Fortress. Those starting from zero should complete Day 1–30 actions before scheduling an OT assessment.

Phase Priority Action Regulatory Driver Est. Cost
Day 1–30 MFA enforcement on all remote access (VPN, SCADA, cloud) TSA SD-02F; cyber insurance $5K–$15K
Day 1–30 OT asset inventory — SCADA servers, PLCs, RTUs, HMI workstations TSA SD-02F CIP $8K–$20K
Day 1–30 Remove all internet-facing PLCs; implement secure gateway TRRC advisory; CISA guidance $10K–$30K
Day 1–30 IT/OT segmentation audit — identify flat network segments TSA SD-02F; NERC CIP $5K–$15K
Day 31–60 DMZ implementation between corporate IT and OT network ISA/IEC 62443; TSA SD-02F $15K–$50K
Day 31–60 HMI workstation hardening — patch or virtualize legacy Windows TSA SD-02F; CISA advisory $10K–$40K
Day 31–60 OT-native monitoring (Modbus/DNP3/OPC-UA protocol awareness) TSA SD-02F continuous monitoring $20K–$60K
Day 61–90 TSA Cybersecurity Implementation Plan — submit to TSA TSA SD-02F (mandatory) $15K–$40K
Day 61–90 CMMC gap assessment + SPRS submission (if DoD contracts exist) CMMC 2.0 (Nov 2025 deadline) $10K–$30K
Day 61–90 Board cybersecurity briefing — SEC 10-K Item 106 governance SEC Form 10-K Item 106 Internal

CoreRecon Coverage for TX Oil & Gas Operators

Three tiers, mapped to the three compliance bands TX operators face:

CoreRecon is SDVOSB-certified. For operators with DoD contract exposure, that matters for small business set-aside contracts and confirms federal procurement eligibility alongside the CMMC services delivered.

📄 Full Threat Brief — 59 Sources

The TX Oil & Gas Threat Brief 2026 includes the complete 8-section intelligence package: all four incident writeups with SEC filing references, the full regulatory crosswalk (TSA SD-02F, SEC Item 1.05, CMMC 2.0, TDPSA, TRRC, CISA CIRCIA), OT/IT convergence vulnerability map, prospect profiles by company segment, 90-day hardening roadmap, and 7 outreach hooks with subject lines. 59 verified sources. Download the PDF brief →

Sources
Halliburton SEC Form 8-K (Aug 23, 2024); Reuters; Infosecurity Magazine; The Record (Recorded Future); CISA/FBI Joint Advisory (Colonial Pipeline, May 2021); TSA Security Directive Pipeline-2021-02F (May 2025); SEC Final Rule 33-11216 (July 26, 2023); CMMC 2.0 Final Rule (32 CFR Part 170, Oct 2024); Texas TDPSA (HB 4, July 2024); Dragos OT-ICS Report 2024; Dragos Volt Typhoon Case Study (Feb 2025); Zscaler Ransomware Report (oil/gas +935% YoY, Apr 2025); SecurityScorecard/KPMG (45% energy breaches third-party); TRRC Pipeline Safety Program; ENGlobal SEC Form 8-K (Dec 2, 2024; Jan 27, 2025 update); CISA/FBI/EPA/NSA Joint Advisory (Iranian-affiliated OT targeting).
Free · No Obligation · $2,500 Value
Request Your OT Security Assessment
We assess your IT/OT segmentation, SCADA exposure, vendor remote access architecture, and TSA SD-02F compliance posture. 30 minutes. Specific findings, not a sales pitch.
Questions? john@corerecon.com · (800) 955-2596 · CoreRecon for Oil & Gas →