935% ransomware surge targeting Texas O&G operators. Volt Typhoon active inside TX energy OT networks. TSA SD02F active enforcement. SEC Item 1.05 4-day disclosure clock. The Permian Basin and Gulf Coast are the highest-concentration target corridor in North American energy.
Texas is the single highest-concentration target for cyber threats in the U.S. energy sector. The Permian Basin, Eagle Ford Shale, and Gulf Coast refining corridor represent critical infrastructure that — if disrupted — directly impacts national energy security, fuel supply, and petrochemical output. Three converging threat vectors make 2026 the most dangerous year yet for Texas O&G operators.
All incidents verified against primary sources: SEC 8-K filings, CISA advisories, company press releases, Dragos intelligence reports.
| # | Date | Victim | Threat Actor | Key Impact | TX Nexus |
|---|---|---|---|---|---|
| 01 | May 2021 | Colonial Pipeline Company | DarkSide / BlackMatter | 5,500-mile pipeline shut down 6 days; $4.4M ransom paid; East Coast fuel supply crisis; $15M IR costs | ✓ National pipeline; TX fuel supply impact |
| 02 | Aug 2024 | Halliburton (Houston, TX) | RansomHub | $35M direct charges; SEC 8-K filed; Mandiant engaged; financial/ops disrupted; 48K employees | ✓ TX HQ — largest TX oilfield services co. |
| 03 | Oct 2024 | Newpark Resources (The Woodlands) | Unknown | Financial/ops disrupted; SEC 8-K filed; manufacturing via downtime procedures | ✓ TX HQ — The Woodlands, TX |
| 04 | Nov 2024 | ENGlobal (Houston, TX) | Unknown | IT systems encrypted; essential ops maintained; SEC 8-K filed; SCADA vendor pathway risk | ✓ TX HQ — Houston engineering |
| 05 | 2022–2024 | BlackCat/ALPHV — energy sector targeting | BlackCat/ALPHV | Double/triple extortion; Rust-based encryption; 6–9 day dwell; multiple TX/international victims | ✓ Energy sector targeting confirmed |
| 06 | 2021–2025 | VOLTZITE — energy sector OT pre-positioning | Volt Typhoon / PRC MSS | 23 pipeline operators confirmed targeted; OT network reconnaissance; SCADA documentation exfil; DOJ disrupted Jan 2024 | ✓ Stage 2 confirmed; 23 TX pipeline operators |
| 07 | Ongoing | ONEOK (Tulsa/DFW, NYSE: OKE) | Context/Risk | 60,000-mile pipeline network; expanded Permian footprint; primary ransomware + nation-state target | ✓ TX operations — Permian/Gulf Coast |
| 08 | No confirmed incident | Encino Energy (Houston) | Target profile | Largest private E&P in Eagle Ford Shale; PE ownership = less SEC disclosure; ransomware targeting profile | ✓ TX HQ — Eagle Ford operator |
| 09 | 2024–2025 | Multiple Permian Basin small-cap operators | Various RaaS | Multiple undisclosed incidents; insurance payout dynamics driving targeting; underreporting significant | ✓ Permian Basin operators targeted |
| 10 | Dec 2024 (disclosed Mar 2025) | IKAV (German, TX operations) | DragonForce RaaS | 722 TX individuals notified of breach; SSN and PII exfiltrated; TX + MA disclosures confirmed | ✓ TX individuals notified; energy sector |
| 11 | SD02C/D/E/F period | TSA-designated critical TX pipeline operators | Various | Multiple TX operators subject to SD02F compliance, audit, and incident reporting obligations | ✓ TX pipeline operators under SD02F |
| 12 | 2021–2025 | Sandworm / FANCY BEAR — energy targeting | Sandworm / GRU Unit 74455 | Pipedream/INCONTROLLER malware for O&G/LNG; Ukraine grid attacks; Poland energy grid OT access Dec 2025 | ✓ TX Gulf Coast refining in targeting scope |
| 13 | 2024 | Schneider Electric / AVEVA — OT supply chain | Cl0p/MOVEit adjacent | EcoStruxure platform + AVEVA PI System used across TX refining and midstream; supply chain risk unconfirmed | ✓ TX refining/midstream OT supply chain |
| 14 | Nov 2023–ongoing 2026 | CyberAv3ngers (IRGC-CEC) — OT PLC targeting | IRGC Cyber-Electronic Command | Unitronics Vision Series compromise; IOCONTROL custom ICS malware; Rockwell Logix CVE-2021-22681; CISA AA26-097A (April 2026) | ✓ TX OT/PLC exposure at compressor stations |
| 15 | Apr 30, 2024 | Eni Libya JV / Mellitah O&G — SCADA precedent | RansomHub | First confirmed SCADA system targeting at energy facility — direct operational analog for TX OT attack | ✓ TX operators with OT exposure are next |
Sources: CISA AA24-038A, AA26-097A, AA23-136A, AA24-242A; Dragos VOLTZITE analysis; Dragos OT/ICS Year in Review 2025; Halliburton SEC Form 8-K (Aug 23, 2024); ENGlobal SEC Form 8-K (Nov 2024); Colonial Pipeline press release (May 2021); DOJ Jan 2024 press release; Rewards for Justice (CyberAv3ngers $10M); Comparitech March 2025; Resecurity CTI. Full sources at end of brief.
All actor data sourced from Dragos, CISA, Trustwave SpiderLabs, and confirmed incident records.[^27][^34][^35]
| Regulation | Applies To | Key Requirement | Penalty |
|---|---|---|---|
| TSA SD02F (Pipeline-2021-02F) | Critical pipeline operators (natural gas, hazardous liquid) | 24/7 Cybersecurity Coordinator; IT/OT network segmentation; MFA on all remote access; 12-hr incident reporting; annual IR plan testing; cybersecurity implementation plan; asset inventory; TSA audit cooperation | Up to $11,904/day/violation |
| SEC Item 1.05 (Form 8-K) | All public TX O&G companies (E&P, midstream, refiners) | Assess material cybersecurity incidents within 4 business days; file Form 8-K if material; annual 10-K Item 1C cyber risk management disclosure | SEC enforcement action; reputational risk |
| NERC CIP | O&G operators with Bulk Electric System (BES) assets | CIP-002 through CIP-014 for cyber assets: access control, config management, incident response, recovery planning, supply chain security | Up to $1M/day/violation |
| DOE CESER | Energy sector broadly (voluntary program) | C2M2 maturity assessment; incident response coordination; OT cybersecurity technical assistance; CESER cybersecurity advisories | Voluntary — advisory only |
| CISA CIRCIA | Critical infrastructure O&G (midstream, refining, petrochem) | Report covered cyber incidents to CISA within 72 hours; submit ransom payment reports within 24 hours | CIRCIA enforcement (2024 rule active) |
| Texas RRC | TX O&G operators (pipeline integrity) | 24/7 emergency reporting line: 844-773-0305; H-5 notification system (effective June 1, 2026); April 10, 2026 notice to operators referencing CISA AA26-097A and increased cyber attack possibility | Varied (pipeline safety enforcement) |
| OSHA PSM (cyber-physical overlap) | TX refinery and petrochemical operators (highly hazardous chemicals) | Mechanical integrity of PSM-covered systems including safety instrumentation and control systems. Cybersecurity incident that causes loss of SIS/PLC integrity is simultaneously a cyber incident AND a PSM violation. | OSHA PSM enforcement |
TX RRC issued a formal notice on April 10, 2026 (referencing CISA AA26-097A) warning operators of increased cyber attack possibility. View the TX Breach Tracker →
The single most critical and most underinvested control for TX O&G operators is air-tight IT/OT network segmentation. TSA SD02F explicitly mandates it. Volt Typhoon exploits flat IT/OT networks as the primary OT intrusion pathway. Dragos confirmed OT ransomware dwell time averages 42 days vs. 14 days IT-wide — precisely because OT visibility and segmentation gaps let attackers move undetected.
Censys (2026) identified 3,891 U.S.-internet-exposed Rockwell EtherNet/IP devices — many belong to TX O&G operators. Run a dedicated OT asset discovery scan against your IP ranges immediately.
| Vendor | Product Line | O&G Application | TX Exposure |
|---|---|---|---|
| Rockwell Automation | ControlLogix, CompactLogix, GuardLogix | PLC-based process control; compressor station automation; pipeline SCADA | Critical — 3,891 U.S. exposed |
| Schneider Electric | Modicon M580, Modicon Quantum, EcoStruxure/AVEVA | Refinery process control; DCS; historian | High |
| Siemens | SIMATIC S7, TIA Portal, PCS 7 | Pipeline telemetry; compressor automation; meter stations | High |
| Honeywell | Experion PKS, Safety Manager | Refinery control; SIS; fire/gas systems | High — SIS isolation required |
| Emerson | DeltaV, Ovation | Refinery DCS; upstream production control | High |
| Unitronics | Vision Series, Unistream | Smaller midstream/upstream; water injection; tank automation | Moderate — CyberAv3ngers primary target |
The most dangerous misconception in the Texas O&G market right now: "We're a small Permian operator — nobody would bother with us." This is wrong and it is costing operators money and operational capability.
The IBM energy sector average is $4.83M[^6] — but that's a data-breach metric. For TX O&G operators, OT downtime costs can dwarf breach response costs by an order of magnitude. Dragos, Honeywell, and independent OT research put the real daily downtime costs into seven figures.
| Operator Type | Daily OT Downtime Cost | Key Cost Drivers |
|---|---|---|
| Small independent E&P (<500 wells) | $250K – $1M/day | Deferred production, crew standby, take-or-pay penalties |
| Mid-cap E&P (500–5,000 wells) | $1M – $5M/day | Production revenue loss, contractor mobilization, regulatory notification |
| Large E&P / major integrated | $5M – $20M/day | Global supply chain disruption, JV partner penalties, commodity exposure |
| Midstream pipeline (system shutdown) | $2M – $10M/day | Take-or-pay commitments, shipper penalties, nomination disputes |
| Major refinery/petrochemical complex | $10M – $50M/day | Refining margin loss, feedstock disruption, product inventory collapse |
Sources: [^6] IBM CODB 2025 ($4.83M energy sector avg); Dragos OT/ICS Year in Review 2025 (49 ONG incidents); Honeywell 2025 report (46% Q4→Q1 industrial ransomware surge[^39]); Dragos Q4 2025 Industrial Ransomware Analysis (49 ONG incidents in Q4 2025[^34]).
The gap between $4.83M and $35M is OT downtime, business interruption, and operational disruption — not just forensics and notification. IBM CODB doesn't capture production revenue loss, JV penalties, or LNG cargo deferment.
| Capability | Sentinel | Fortress | Command |
|---|---|---|---|
| Designed for | Indepentents <$500M 1–4 IT staff |
Mid-cap $500M–$5B Growing TSA exposure |
Majors / publicly traded LNG / major midstream |
| SOC SLA | 30-min critical incident | 30-min critical incident | 30-min critical + OT isolation playbook |
| OT-aware monitoring | — | ✓ ICS protocol visibility | ✓ ICS + IT/OT correlation |
| IR retainer | — | Pre-negotiated, 30-min mobilization | ✓ Pre-authorized + tabletop |
| TSA SD02F compliance | CIP documentation alignment | Full CIP + annual CAP report | ✓ CIP + CIRP + full CAP |
| SEC Item 1.05 support | — | 8-K timeline documentation | ✓ Full 8-K coordination |
| Pen testing | Annual external scan | Annual pen test + OT-specific | ✓ Bi-annual + M&A due diligence |
| vCISO | — | Quarterly briefings | ✓ Assigned + board reporting |
| Tabletop exercises | TSA SD02F annual | Operator-specific scenarios | ✓ Bi-annual + regulator-ready docs |
| Pricing | $89/endpoint/mo | $109/endpoint/mo | $129/endpoint/mo |
Endpoint count is scoped to your IT footprint — IT endpoints, not OT PLCs. Most operators discover they need Fortress or Command once they see what IT-only MSSPs miss.
CoreRecon's Fortress and Command services are designed to help operators build and maintain a TSA-approved Cybersecurity Implementation Plan.
| Tool | What It Does | Use Case |
|---|---|---|
| SPRS Calculator | CMMC/NIST 800-171 self-assessment scoring | Defense-adjacent O&G contractors with CUI handling |
| Breach Cost Calculator | Estimates total breach cost for energy sector; factors in OT downtime, regulatory fines, business interruption | Pre-renewal cyber insurance conversations; Halliburton $35M benchmark comparison |
| Cyber Insurance Premium Estimator | Estimates cyber insurance premium based on security controls | Budget planning for 2026 renewals; pre-underwriting preparation |
| Free Security Assessment | 30-minute technical call with a CoreRecon security engineer; written gap summary | Where to start — map your exposure against the TX O&G threat landscape |