Energy / OT · June 2026 · CoreRecon Threat Intelligence
Texas sits at the center of the US energy economy. The Permian Basin alone produces more than 6 million barrels per day — 81% of the top 50 US E&P operators' combined output. That concentration of critical infrastructure makes the state the highest-priority target in the country for ransomware groups, nation-state actors, and opportunistic hacktivists.
In 2024 alone, ransomware attacks against oil and gas operators increased 935% year-over-year (Zscaler, April 2024–April 2025). Three Texas-headquartered companies — Halliburton, Newpark Resources, and ENGlobal — disclosed cybersecurity incidents to the SEC between August and November 2024. All three involved operational disruption. Halliburton's confirmed $35M direct loss is now the precedent-setting number every TX operator's board is aware of.
This brief covers the four incidents that define the current threat environment, the regulatory obligations that create compliance urgency, the OT/IT convergence vulnerabilities that persist across mid-market operators, and what a 90-day hardening roadmap looks like for a Permian Basin independent E&P or oilfield services firm.
Four Incidents Defining the 2024–2025 TX O&G Threat Environment
These aren't theoretical scenarios. All four incidents below involved Texas-headquartered or Texas-operating companies, with confirmed financial impact and regulatory filings. They represent the attack patterns most likely to affect your organization.
On August 21, 2024, Halliburton — the world's second-largest oilfield services company — detected unauthorized access to its systems and began taking infrastructure offline. RansomHub, using double-extortion tactics (encryption + data theft), disrupted invoice and purchase order processing globally. The North Belt campus in Houston was directly affected.
Halliburton engaged Mandiant for incident response and notified the FBI. The company filed an SEC Form 8-K under the new Item 1.05 rule within 48 hours of discovery — a timeline every public TX operator's legal team now benchmarks against. Total confirmed impact: $35M in direct charges, as disclosed in subsequent SEC filings.
The supplier notification Halliburton sent on August 26 contained IoCs including "maintenance.exe" — the RansomHub encryptor — demonstrating how quickly a major operator's supply chain can become an attack intelligence source for the same group targeting their vendors.
Colonial Pipeline originates in Houston, TX. On May 6, 2021, a compromised VPN credential — on a legacy VPN account without MFA — allowed DarkSide to exfiltrate 100GB of data before deploying ransomware on May 7. Colonial proactively shut down all 5,500 miles of pipeline operations. The resulting fuel crisis caused the White House to declare a state of emergency and DOT to issue emergency fuel transport authorizations.
The $4.4M ransom (75 BTC) was paid. The DOJ subsequently recovered $2.3M of it. The FBI confirmed attribution to DarkSide, a Russia-based RaaS group. The direct trigger: a single compromised password with no MFA on a legacy VPN account.
This incident directly created TSA Security Directive Pipeline-2021-01 (issued May 27, 2021) and all subsequent SD-02 versions now in force. The current mandatory requirement — SD-02F (effective May 3, 2025) — exists because of this Texas-origin incident.
Newpark Resources — a Woodlands-based oilfield equipment supplier serving E&P operators across the Permian Basin and Eagle Ford — discovered a ransomware attack on October 29, 2024. Financial and operating reporting applications were taken offline. Manufacturing and field operations continued using established downtime procedures, which limited direct operational impact.
The significance: Newpark is not a small operator. It's a NYSE-listed, $500M+ market cap oilfield services company with established IT infrastructure. If Newpark's systems were disrupted, the ICP tier below it — private OFS companies with 50–500 employees — is almost certainly running on weaker security posture. The attack actor was not publicly attributed.
ENGlobal Corporation — a Houston-based engineering and professional services firm serving energy sector defense contractors — detected unauthorized access to its IT systems in November 2024. Business applications were disrupted for approximately six weeks. In a January 27, 2025 SEC update, the company confirmed that sensitive personal information had been stolen and that notifications to affected individuals and regulatory agencies were underway.
ENGlobal's profile — engineering services firm with DoD contracts — makes this case particularly relevant for oilfield service companies that have indirect federal contract exposure. If your company holds any DoD fuel supply, logistics, or base services contracts, the CMMC 2.0 framework applies to your CUI environment — and an attack like ENGlobal's would trigger DFARS obligations on top of the SEC and Texas reporting requirements.
The Regulatory Stack: What TX Operators Are Obligated to Do
Three regulatory frameworks — TSA SD-02F, SEC Form 8-K Item 1.05, and CMMC 2.0 — create immediate compliance deadlines for different segments of the TX oil and gas ICP. Texas TDPSA adds a fourth layer for all operators processing personal data of Texas residents.
The Texas Railroad Commission issued a joint advisory with EPA, FBI, CISA, and NSA warning TX oil and gas operators to remove PLCs from direct internet exposure via secure gateway and firewall. This advisory establishes a de facto cybersecurity standard — operators with internet-facing PLCs are operating out of alignment with TRRC-adjacent expectations. Most mid-market Permian Basin operators have not completed a PLC exposure audit.
OT/IT Convergence: Why Traditional IT Security Misses the Real Risk
The primary attack surface for TX oil and gas operators is not email or cloud applications — it's the convergence of IT and OT networks that most mid-market operators have never formally audited. Colonial Pipeline's attack vector was a corporate VPN account. The ransomware never touched the pipeline control systems directly — Colonial shut down operations as a precaution because their IT/OT boundary wasn't well enough defined to risk it.
The six highest-priority OT/IT convergence vulnerabilities for TX operators:
- 01 Unsegmented IT/OT networks — The most common gap. Ransomware enters via phishing or VPN compromise, spreads across the flat network to SCADA/HMI workstations, and forces operational shutdown as a precaution. Most mid-market TX operators have not implemented a proper DMZ between corporate IT (Level 3) and SCADA/HMI (Level 2) per ISA/IEC 62443 zone-and-conduit architecture.
- 02 Internet-facing PLCs and HMIs — Iranian-affiliated actors explicitly targeted internet-exposed PLCs in the joint EPA/FBI/CISA/NSA advisory (referenced by TRRC). CyberArmyofRussia_Reborn demonstrated in 2024 that even basic HMI manipulation causes tangible OT disruption — no nation-state TTPs required.
- 03 Vendor remote access — 45% of energy sector breaches in 2024 were third-party related (SecurityScorecard/KPMG). Halliburton's own Aug 26 supplier notification demonstrated how vendor compromise at a major operator creates IoC data that can be used to target the vendor's clients. TeamViewer, RDP to SCADA, and proprietary OT remote access platforms are all commonly deployed without session recording or just-in-time provisioning.
- 04 Legacy Windows-based HMI workstations — Permian Basin operators running Windows 7 / Server 2008-era SCADA workstations with no patching cycle. Unpatched HMIs are directly targetable by commodity ransomware that would never reach an air-gapped OT environment.
- 05 Protocol exposure (Modbus/DNP3/OPC-UA) — Modbus/TCP and DNP3 have no native encryption or authentication. Devices that communicate in plaintext on a network segment reachable from corporate IT are one lateral move away from attack.
- 06 Drilling rig telemetry — Real-time MWD (Measurement While Drilling) data transmitted from wellsite to corporate over cellular/satellite with minimal security controls. Bidirectional data flow creates an ingress point. Remote rigs are rarely hardened to the same standard as corporate infrastructure.
Nation-State Actors: The Threat Beyond Ransomware
The ransomware incidents above represent the financially motivated tier of the threat landscape. The nation-state tier is operating with different objectives — and is already inside US energy infrastructure.
Volt Typhoon (China PRC) has been confirmed by CISA, FBI, and NSA as actively pre-positioning on US critical infrastructure IT networks since at least 2021, with the assessed purpose of enabling sabotage capability — not espionage. CISA explicitly named Texas pipeline operators and ERCOT as targets. Volt Typhoon's subgroup "Voltzite" maintained unauthorized access to a New England utility's OT network for approximately 10 months (Feb–Nov 2024) before detection, exfiltrating GIS data, network diagrams, and operating instructions. The group uses living-off-the-land (LotL) techniques that bypass traditional signature-based detection.
Iranian-affiliated actors targeted oil and gas PLCs and internet-facing OT devices in a joint EPA/FBI/CISA/NSA advisory, with the Texas Railroad Commission issuing a supplementary warning to TX operators. Some Texas critical infrastructure organizations had already experienced disruptions related to Iranian-affiliated threats at the time of the advisory.
Volt Typhoon is "arguably the most crucial threat group to track in critical infrastructure." The group rebuilt its KV botnet within weeks of the FBI-disrupted Jan 2024 takedown. Assume pre-positioning is ongoing, including in Texas energy networks.
90-Day Hardening Roadmap
The following actions are prioritized by regulatory urgency and risk reduction value. Operators with existing Sentinel-tier coverage can move directly to Fortress. Those starting from zero should complete Day 1–30 actions before scheduling an OT assessment.
| Phase | Priority Action | Regulatory Driver | Est. Cost |
|---|---|---|---|
| Day 1–30 | MFA enforcement on all remote access (VPN, SCADA, cloud) | TSA SD-02F; cyber insurance | $5K–$15K |
| Day 1–30 | OT asset inventory — SCADA servers, PLCs, RTUs, HMI workstations | TSA SD-02F CIP | $8K–$20K |
| Day 1–30 | Remove all internet-facing PLCs; implement secure gateway | TRRC advisory; CISA guidance | $10K–$30K |
| Day 1–30 | IT/OT segmentation audit — identify flat network segments | TSA SD-02F; NERC CIP | $5K–$15K |
| Day 31–60 | DMZ implementation between corporate IT and OT network | ISA/IEC 62443; TSA SD-02F | $15K–$50K |
| Day 31–60 | HMI workstation hardening — patch or virtualize legacy Windows | TSA SD-02F; CISA advisory | $10K–$40K |
| Day 31–60 | OT-native monitoring (Modbus/DNP3/OPC-UA protocol awareness) | TSA SD-02F continuous monitoring | $20K–$60K |
| Day 61–90 | TSA Cybersecurity Implementation Plan — submit to TSA | TSA SD-02F (mandatory) | $15K–$40K |
| Day 61–90 | CMMC gap assessment + SPRS submission (if DoD contracts exist) | CMMC 2.0 (Nov 2025 deadline) | $10K–$30K |
| Day 61–90 | Board cybersecurity briefing — SEC 10-K Item 106 governance | SEC Form 10-K Item 106 | Internal |
CoreRecon Coverage for TX Oil & Gas Operators
Three tiers, mapped to the three compliance bands TX operators face:
- Sentinel ($1,500–$5,000/month) — MFA, EDR, dark web monitoring, phishing training, basic SOC. Covers the cyber insurance minimums and TDPSA basic hygiene. Right-sized for OFS SMBs with 50–200 employees.
- Fortress ($4,000–$12,000/month) — IT/OT segmentation, OT-native ICS monitoring (Modbus/DNP3/OPC-UA), SCADA security, PAM, vendor remote access control, CMMC Level 1–2 gap assessment, TSA SD-02F compliance support. The core tier for independent E&Ps and midstream operators subject to the pipeline directive.
- Command ($10,000–$25,000/month) — 30-minute SLA, board-level governance, SEC 10-K Item 106 reporting, CISO-as-a-service, CMMC Level 2–3 full certification path, incident response with pre-authorized SCADA isolation playbook. For publicly traded operators and those with the highest regulatory exposure.
CoreRecon is SDVOSB-certified. For operators with DoD contract exposure, that matters for small business set-aside contracts and confirms federal procurement eligibility alongside the CMMC services delivered.
The TX Oil & Gas Threat Brief 2026 includes the complete 8-section intelligence package: all four incident writeups with SEC filing references, the full regulatory crosswalk (TSA SD-02F, SEC Item 1.05, CMMC 2.0, TDPSA, TRRC, CISA CIRCIA), OT/IT convergence vulnerability map, prospect profiles by company segment, 90-day hardening roadmap, and 7 outreach hooks with subject lines. 59 verified sources. Download the PDF brief →
Halliburton SEC Form 8-K (Aug 23, 2024); Reuters; Infosecurity Magazine; The Record (Recorded Future); CISA/FBI Joint Advisory (Colonial Pipeline, May 2021); TSA Security Directive Pipeline-2021-02F (May 2025); SEC Final Rule 33-11216 (July 26, 2023); CMMC 2.0 Final Rule (32 CFR Part 170, Oct 2024); Texas TDPSA (HB 4, July 2024); Dragos OT-ICS Report 2024; Dragos Volt Typhoon Case Study (Feb 2025); Zscaler Ransomware Report (oil/gas +935% YoY, Apr 2025); SecurityScorecard/KPMG (45% energy breaches third-party); TRRC Pipeline Safety Program; ENGlobal SEC Form 8-K (Dec 2, 2024; Jan 27, 2025 update); CISA/FBI/EPA/NSA Joint Advisory (Iranian-affiliated OT targeting).