El Paso Electric disclosed a cybersecurity incident in November 2023 affecting customer and employee records. Administrative systems were impacted, though operational technology infrastructure was reported unaffected.
Ransomware targeting administrative IT systems. Operational technology infrastructure reported isolated and unaffected. Initial vector under investigation — phishing or exposed service suspected based on TTPs.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| NERC CIP | CIP-003-8 | Security management controls — administrative systems lacked documented cybersecurity management program |
| TDPA | Tex. B&C Code §521.053 | 25,000 TX customer and employee notifications required |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.