Home Blog TX Electric Co-op Ransomware 2026

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →
Threat Intelligence Brief — June 2026

Texas Electric Cooperative Ransomware: Why Co-ops Are in the 2026 Crosshairs

Karnes EC and San Bernard EC were listed on Qilin ransomware leak site. Volt Typhoon has pre-positioned inside TX utility networks. NERC CIP-015-1 enforcement is live. Here is what every TX electric co-op needs to know — and do.

Karnes EC
Qilin ransomware victim — member PII confirmed exfiltrated
Sep 2025
NERC CIP-015-1 INSM effective — $1.54M/day max penalty
5 forces
converging on TX co-ops in 2026
Volt Typhoon NERC CIP-015 OT/IT Convergence SCADA Qilin Ransomware ERCOT TDPSA RUS

Research verified across 23+ source citations. Sources include CISA, DOJ, FBI, Dragos, Federal Register, NERC, FERC, ERCOT, USDA RUS, Industrial Defender, Darktrace, and published incident reports. Last updated June 26, 2026. CoreRecon analysts with ERCOT-native operational context.

Why TX Electric Co-ops Are Now in the Ransomware Crosshairs

Five forces converged in 2025–2026 to make Texas electric cooperatives a priority ransomware target — not by coincidence, but by structural design. If you manage cybersecurity for a TX co-op and haven't mapped these five forces to your own exposure, you are operating blind.

1. Nation-state pre-positioning is confirmed and ongoing

Volt Typhoon — a PRC state-sponsored APT — has been inside U.S. critical infrastructure networks since at least 2021 using Living-off-the-Land (LOTL) techniques that generate no malware signatures. The FBI disrupted its KV botnet in December 2023 via court-authorized operation, but eradication is incomplete. CybelAngel confirmed in June 2026 that Volt Typhoon nodes have been revived and re-leveraged by mid-2024. CybelAngel, June 2026.

FBI Director Christopher Wray told the House Select Committee on Strategic Competition in January 2024: Volt Typhoon is "the defining threat of our generation." Congress.gov CRS IF12798. CISA's CI Fortify Initiative (2025–2026) was launched specifically to enable critical infrastructure to "operate offline during cyberattacks" — the scenario Volt Typhoon is designed to enable.

Sandworm — Russian GRU Unit 74455 — has been attributed by Mandiant to an April 2024 OT attack on a Texas water facility that caused a tank overflow. The same unit executed the 2015 and 2016 Ukraine blackouts (1.4M and 700K customer outages respectively). Cyber Defense Review, Army War College.

2. Co-op OT/IT exposure is structurally different from IOU exposure

Unlike an IOU with dedicated OT security teams and segmented network architecture, a typical TX distribution co-op operates with:

  • The same control center for IT and OT functions
  • 2–5 IT staff managing both corporate systems and SCADA environments
  • The same corporate internet connection used for billing, email, and SCADA vendor support
  • The same Active Directory forest for authentication across both IT and OT

Dragos Q2 2025 reported 101 ICS/OT ransomware incidents — Qilin was the most active group. The SimpleHelp RMM exploitation chain used by Qilin directly targets the consultant/PSA supply chain that co-ops depend on. Dragos Q2 2025. This is not theoretical: Karnes EC and San Bernard EC are confirmed victims.

3. Ransomware economics have shifted to co-op scale

Dragos Q1 2025 reported 80% of ICS/OT-targeting ransomware incidents targeted organizations with fewer than 1,500 employees. Resecurity / Dragos Q1 2025. A 30,000-member distribution co-op fits this profile perfectly: enough member PII to generate high-value extortion leverage, enough IT/OT convergence to create a credible grid-disruption threat, and typically enough security underinvestment to make initial access relatively easy.

4. NERC CIP-015-1 has created a compliance cliff with enforcement teeth

CIP-015-1 (Internal Network Security Monitoring) became effective September 2, 2025 for High/Medium Impact BES Cyber Systems. The standard mandates east-west traffic monitoring — detecting lateral movement inside the network, not just perimeter traffic. This is specifically designed to counter Volt Typhoon-style LOTL attacks. NERC 2025 enforcement is up 20% year-over-year; maximum penalty per day per violation reached $1.54M. ThinkPower Solutions.

5. TDPSA exemption is being confused with protection

TDPSA (effective July 1, 2024) explicitly exempts electric utilities. Bracewell TDPSA analysis. This exemption removes TDPSA breach notification obligations — but does not remove Texas Business & Commerce Code Chapter 521 obligations, NERC CIP-003 BCSI obligations, or the fundamental risk that member PII exfiltration creates. The exemption is a compliance simplification, not a threat reduction.

The 2023–2025 Utility-Sector Wave: Named Incidents and Dollar Impact

🚨
Karnes Electric Cooperative (TX) and San Bernard Electric Cooperative (TX) — 2024–2025 Qilin ransomware gang listed both TX co-ops on dark-web leak site. Karnes EC data samples confirmed: financial documents (income/expense balance reports, daily financial operation documents), member names, addresses, zip codes. Cybernews | Today's General Counsel.

Volt Typhoon — Persistent Access Confirmed, 2021–2026

CISA AA24-038A confirmed Volt Typhoon compromised IT environments of multiple critical infrastructure organizations, primarily in Communications, Energy, Transportation Systems, and Water sectors. CISA AA24-038A. Early 2024: Littleton Electric Light & Water Departments (Massachusetts, small public utility) confirmed as first named Volt Typhoon OT network compromise — attackers maintained access for nearly a year via FortiGate CVE-2022-42475. Unit 42 Threat Brief.

"Volt Typhoon is the defining threat of our generation."

— FBI Director Christopher Wray, House Select Committee on Strategic Competition, January 2024

Delta-Montrose Electric Association (Colorado) — November 7, 2021

DMEA discovered breach on internal network; 90% of enterprise network functions lost. Lost 25 years of historical data (saved documents, spreadsheets, forms). Phone, email, payment processing, billing, and member account management systems down for weeks. Utility Dive | ZDNet. DMEA CEO: "a large percentage of smaller distribution-level electric co-ops are immune from cyber-attack since they don't use automation for their operational technology." This assumption is now demonstrably false — Karnes EC and San Bernard EC show it.

S16/Z-Pentest — TX SCADA Attack January 2025

Resecurity documented a confirmed cyber attack targeting SCADA systems at a Texas utility in January 2025, attributed to threat actors designated S16/Z-Pentest, with confirmed operational technology impact. Resecurity. Resecurity also documented an 80% year-over-year increase in energy sector cyber threats driven by geopolitical tensions.

Sandworm — Texas Water Facility OT Attack, April 2024

Mandiant confirmed Russian GRU cyber activity targeting a Texas water facility, causing system malfunction and a water tank overflow. This was not an IT system compromise — it was a direct OT attack using ICS/SCADA interaction. Cyber Defense Review, Army War College. The same GRU unit that executed the Ukraine blackouts.

Halliburton / RansomHub — August 2024

RansomHub ransomware at Halliburton caused $35M in losses (SEC 8-K confirmed). While Halliburton is upstream O&G rather than a distribution co-op, the attack chain — compromise of IT systems → attempt to pivot to OT → SEC disclosure of financial impact — is the template that ransomware groups are now attempting against smaller utilities.

Pedernales, CoServ, and Bluebonnet: Scale and the OT/IT Convergence Problem

Understanding the co-op landscape matters because scale creates specific attack surface patterns that generic MSSPs do not see.

Cooperative Meters Counties / Territory OT Infrastructure
Pedernales Electric Cooperative (PEC) ~410,000 meters Central TX, 13 counties, ~81,000 sq mi ERCOT member; smart grid modernization ongoing
CoServ Electric and Gas ~330,000 electric + 500K combined Denton, Collin, Cooke, Grayson, Wise counties Base Power partnership (March 2026), 100 MW residential battery
Bluebonnet Electric Cooperative ~133,000–142,000 meters 14 Central TX counties, 12,800 mi lines, 47 substations SurvalentONE ADMS with SCADA, FLISR, Rotational Load Shedding
Karnes Electric Cooperative ~6,000 meters Karnes, Wilson, Atascosa counties (South TX) Qilin ransomware victim — member PII confirmed
San Bernard Electric Cooperative ~8,000 meters Austin, Colorado, Waller, Washington counties Qilin ransomware victim — member PII confirmed

SCADA and the Co-op OT Surface

Co-ops typically operate SCADA (Supervisory Control and Data Acquisition) systems for real-time grid monitoring, switching, and load management. Key attack vectors:

  • Legacy SCADA protocols: DNP3, Modbus, and IEC 61850 were designed for reliability, not security — no encryption, no authentication on some legacy implementations. Discovery Alert.
  • Remote access paths: Co-ops frequently rely on vendor-installed remote access paths for SCADA maintenance — dial-up legacy circuits still active, VPN tunnels maintained by third-party integrators. These are the primary Volt Typhoon and Sandworm entry vectors. CISA AA24-038A.
  • IT/OT segmentation failures: FERC's 2025 Lessons Learned from CIP audits found entities operating DERs and transmission-connected BES generation from the same control center using the same personnel — violating CIP-002-5.1a physical segmentation principles. Industrial Cyber FERC 2025.
  • Internet-connected PLCs: Iranian APT actors have directly targeted internet-connected PLCs (Rockwell Automation Allen-Bradley CompactLogix, Micro850) with intent to cause disruptions through project file manipulation and HMI display data manipulation. Industrial Cyber.

AMI Head-End Systems

Advanced Metering Infrastructure (AMI) head-end systems are the command-and-control center for smart meters, distribution automation, and prepay systems. Providers include Itron, Landis+Gyr, Honeywell, Oracle Utilities, and Tantalus. AMI attack vectors include head-end server compromise (remote disconnect/reconnect commands, interval data harvesting, firmware manipulation), mesh network infiltration (RF-based 900MHz FHSS vulnerable to replay attacks), and the billing system chain (AMI data flows to NISC/SEDC/Milsoft — a compromise chain from head-end to billing equals member PII exfiltration).

Member Portal Supply Chain

Co-op member portals are high-yield PII targets. Key providers:

  • NISC SmartHub: Bluebonnet Electric Cooperative operates SmartHub (bluebonnet.smarthub.coop). NISC provides billing, CIS, member portal, and meter data management for hundreds of rural co-ops.
  • SEDC / Milsoft: Provides billing, member portal, and outage management. Gulf Coast and South Texas co-ops. Daffron & Associates (now Milsoft) systems still in use at smaller co-ops — patched infrequently due to billing system stability requirements.
  • Prepay metering: Co-ops offering prepay metering have additional attack surface — the prepaid balance system can be disrupted to cause service termination for thousands of members simultaneously.

SCADA-Aware Monitoring for TX Co-ops

CoreRecon's OT-aware SOC covers SCADA, AMI head-end, and member portal exposure — the three vectors that generic MSSPs cannot see. SDVOSB team. TX residency. 30-min SLA.

Co-op Solutions →

NERC CIP, ERCOT, and TDPSA: The Regulatory Triple-Stack

NERC CIP-015-1: The New Standard That Changes Everything

Effective September 2, 2025, CIP-015-1 requires registered entities to implement Internal Network Security Monitoring (INSM) for High Impact and Medium Impact BES Cyber Systems with External Routable Connectivity (ERC). The standard mandates east-west traffic monitoring — detecting lateral movement inside the network, not just north-south perimeter traffic. Federal Register.

CIP-015-1 is specifically designed to counter Volt Typhoon-style LOTL attacks. The standard's requirements — flow collection, analysis, anomaly detection, incident response — require OT-aware technology that most co-ops do not have. Generic MSSPs cannot package compliance evidence for CIP-015 because they do not have OT-specific traffic capture. Darktrace INSM.

Standard Effective Date Max Penalty
CIP-015-1 (INSM)Sep 2, 2025 (High/Medium)$1.54M/day per violation
CIP-003-9 (Low Impact BES expansions)January 2026$1.54M/day per violation
CIP-003-11 NOPR (Remote Auth)FERC filed Dec 20, 2024Pending approval
CIP-005-8 (Logical Isolation)FERC approved 2025$1.54M/day per violation

Why TX Co-ops Face a Triple-Stack

  • NERC CIP: Applies to co-ops registered as Balancing Authority, Transmission Operator, or Distribution Provider with BES impact. For G&T co-ops (Brazos, Golden Spread, ETEC), CIP applies across the full chain.
  • ERCOT context: ERCOT has no FERC jurisdiction over wholesale rates, but NERC registration still applies via TRE (Texas Reliability Entity). FERC ERCOT Overview.
  • TDPSA: Exempts electric utilities — but Texas Business & Commerce Code Chapter 521 still applies. Mandatly TDPSA guide.
  • RUS/USDA covenants: RUS loan agreements include cybersecurity covenants requiring documented programs, risk assessments, incident reporting, and business continuity planning. RUS Bulletin 1730-1.

IRS 501(c)(12) adds a fifth layer: a major uninsured loss not recovered through rates could degrade reserves, risk the 85% member income test, and trigger corporate tax liability — an underappreciated breach consequence.

Attack Vectors Specific to Co-ops: SCADA, AMI, Member Portals, Contractor VPN

The Co-op Attack Chain (Dragos-documented)

Compromise a co-op IT consultant's PSA tool (ConnectWise, Halo) → use legitimate RMM access to deploy payload inside co-op network → pivot to SCADA from inside the corporate LAN. This is the attack chain Dragos documented in Q2 2025. Dragos Q2 2025. KPMG 2024 analysis: nearly half of cyber breaches in the energy sector come from third-party platforms. Cooperative.com / KPMG 2024.

FERC 2025 Lessons Learned: Third-Party Cloud Compliance Risk

FERC's 2025 Lessons Learned document identified inadequate third-party vendor due diligence (CIP-003-8, CIP-006-6, CIP-010-4) and compliance risks associated with cloud services as top audit findings. Industrial Cyber FERC 2025.

The Voltage Typhoon Co-op Attack Path

  1. Phish co-op CEO email → harvest cached credentials
  2. Move laterally into corporate domain using LOTL tools (WMI, PowerShell, netsh)
  3. Use same VPN credentials to access SCADA environment
  4. Establish persistent OT foothold — no custom malware deployed, EDR sees nothing
  5. Wait for grid stress event (storm, heat wave, ERCOT market anomaly)
  6. Execute disruptive or destructive cyber activity

The Texas-specific signal: Volt Typhoon targeting included Texas and Guam specifically as pre-positioning for military/logistics disruption scenarios. CybelAngel.

Why a Generalist MSP Can't Cover a Co-op's Threat Surface

The IT/OT Gap

Generic MSSPs — including the major national providers co-op IT directors find when searching "managed security" — operate SOCs staffed primarily with IT security analysts. These analysts have no training on DNP3, Modbus, or IEC 61850 protocols, no tools for SCADA-specific traffic analysis, and no experience reviewing CIP-010 change management evidence or CIP-007 patch logs for control systems. An MSSP SOC that sees SCADA traffic in its SIEM will typically alert on it as anomalous or block it as suspicious — not recognize it as legitimate OT traffic.

The NERC CIP Evidence Gap

NERC CIP compliance is demonstrated through documentation: asset identification, change logs, incident response plans, security awareness training records, personnel risk assessments. Generic MSSPs do not know how to generate CIP-010-4 vulnerability assessment evidence from OT environments, package CIP-007 patch management documentation for SCADA systems (which cannot be patched on standard schedules due to operational constraints), document remote access controls for CIP-005 compliance, or prepare evidence for a TRE CMEP audit.

The 30-Minute SLA Gap

MSSP service level agreements typically specify 15–60 minute response times during business hours and 2–4 hour response times after hours. For a co-op in hurricane season or winter storm conditions, this is functionally useless. Grid events happen at 2am on a Sunday in December. An MSSP that cannot staff an analyst to respond until 8am the next business day has provided no protection during the window when damage is most likely to occur.

Pricing Benchmark

Vendor Type Typical Pricing Co-op Coverage
Big-4 Consulting (Deloitte, Accenture, PwC)$250K–$2M+ annually for NERC retainerNo OT detection, no co-op pricing sensibility
OT-Native MSSP (Dragos, Claroty)$500K–$5M+ annuallyOT-native, but priced for IOUs and large G&Ts
National Consumer MSSP$500–$5,000/monthNo OT coverage, no NERC CIP packaging, no storm SLA
CoreRecon$89–$129/endpoint/monthOT-aware monitoring, NERC CIP evidence, 30-min SLA, SDVOSB, TX residency

A 40,000-member distribution co-op with 200 endpoints (servers, workstations, OT interfaces) pays $17,800–$25,800/month for CoreRecon vs. $250,000+/year for a Big-4 NERC retainer alone.

What 30-Minute SOC Response Looks Like During an OT Incident

CoreRecon's 30-minute SLA is specifically designed for the co-op threat environment where incidents occur during weather events, after hours, and on weekends. The conditions that create the highest probability of attack (grid stress, staff distraction, communication disruption) are exactly the conditions under which most MSSPs cannot provide timely response.

The 30-Minute Window

Time Action Grid Context
0–5 minAlert acknowledgment + initial triage. Analyst confirms whether alert coincides with ERCOT grid stress event (summer peak, winter storm, market anomaly). Alerts during active outage events are escalated immediately — not queued.Distinguish grid stress from cyber incident: a SCADA anomaly during a summer peak demand event requires immediate OT context
5–15 minContainment decision. Can OT segmentation be enforced without disrupting grid ops? SCADA-aware analysts know the difference between a legitimate control command and an attacker's attempt to manipulate grid state. Generic MSSP can't make this call.Co-op IT staff are distracted by storm response — cannot make this call without guidance
15–30 minIR engagement. CoreRecon analyst initiates incident response workflow, engages E-ISAC (Electricity ISAC) structure, documents RUS notification requirements. RUS Bulletin 1730-1 requires incident reporting — having a SOC that documents this in real-time matters for loan covenant compliance.ERCOT grid context: analyst knows if event is affecting ERCOT dispatch or settlement

The contrast: a generic MSSP with a 6-hour response SLA means the attacker has a 5.5-hour head start before the co-op even gets an analyst on the phone. For a co-op with a single IT staff member managing both billing systems and SCADA during a storm event, that gap is the difference between recovery in days and recovery in months.

The 5-Step Posture Assessment for TX Electric Co-ops

CoreRecon offers a no-cost 2-week posture assessment for qualifying TX electric cooperatives — delivered by SDVOSB team with ERCOT-native operational context. Here is what the assessment covers:

1

OT Asset Inventory Verification

Identify all SCADA/EMS components, AMI head-end servers, RTUs, PLCs, and network segments. This is the prerequisite for CIP-002 compliance and the foundation of all OT security. Gap analysis against NERC CIP baseline.

2

Remote Access Path Audit

Identify vendor VPN credentials, dial-up circuits still active, and any remote desktop access to SCADA systems. Disable or rotate everything not provably needed. Volt Typhoon and Sandworm both use remote access paths as primary entry vectors.

3

Tested Air-Gapped Backups

Confirm offline/air-gapped backups of SCADA configurations, member data, and billing systems. DMEA's primary lesson was "backup integrity matters more than backup existence." Recovery time objective analysis included.

4

Board-Approved IR Plan with RUS + Chapter 521 Notification

Cyber incident response plan documented, current, and assigned to specific personnel — not just "the IT person." Includes RUS loan covenant notification requirements and Texas Business & Commerce Code Chapter 521 member notification process.

5

CIP-015-1 INSM Readiness Assessment

Gap analysis against CIP-015-1 INSM requirements. East-west traffic monitoring baseline. OT-aware traffic capture feasibility assessment. CIP-003/007/010 evidence readiness score.

What You'll Receive

  • OT asset inventory gap analysis against NERC CIP baseline
  • AMI head-end and member portal exposure scan (external perspective)
  • SCADA remote access path audit
  • CIP-003/007/010/015 evidence readiness score
  • Ransomware resilience score (backup integrity, RTO analysis)
  • Written findings report with remediation priority ranking

Free Posture Assessment — TX Electric Co-ops

2-week assessment. SCADA-aware team. SDVOSB. ERCOT-native context. 30-minute SLA. No obligation.

Book Your Assessment →

CoreRecon is a Service-Disabled Veteran-Owned Small Business (SDVOSB). OT-aware SOC coverage for electric cooperatives and critical infrastructure. TX residency. 30-minute SLA. Contact corerecon@polsia.app or (800) 955-2596.