Major Cyber Attacks on Critical Infrastructure (2021–2026)

By George Mutune   Published: 12/01/21   Updated: 09/24/26   11 min read

Updated September 2026. Cyber attacks on critical infrastructure target the technologies, networks, and facilities that keep fuel flowing, water clean, food processed, patients treated, and goods moving. When those systems fail—even briefly—the impact shows up at gas stations, pharmacies, ports, and hospital wards, not just on a SOC dashboard.

The threat is not theoretical. Since 2021, ransomware crews and nation-state operators have repeatedly hit energy, water, food, healthcare, and transportation. Some incidents were IT ransomware that forced operators to shut OT as a precaution. Others reached programmable logic controllers (PLCs) and industrial protocols directly. The common thread: weak remote access, flat networks, and internet-exposed operational technology (OT) turn local compromises into national headaches.

This article walks through eight well-documented cases from 2021 through 2025, then covers what defenders and policymakers are doing in 2026—and what operators should prioritize now.

Why critical infrastructure stays fragile

Most critical systems mix decades-old industrial controls with newer IT, cloud, and remote-access tooling. That mix improves efficiency and remote support—and expands the attack surface.

CISA, sector agencies, and allies have warned for years that water/wastewater, pipelines, healthcare clearinghouses, and ports are attractive targets precisely because downtime is expensive and politically visible.

Eight major cyber attacks on critical infrastructure (2021–2025)

1. Oldsmar, Florida water treatment plant (February 2021) — Water

What happened: On February 5, 2021, an intruder remotely accessed the City of Oldsmar’s water-treatment SCADA environment (reported via TeamViewer) and briefly raised the sodium hydroxide (lye) setpoint from about 100 ppm to 11,100 ppm. A plant operator watched the change happen live and reversed it. Drinking water was not contaminated.

Impact: No public health harm, but a clear demonstration that remote-desktop access into treatment controls can become a life-safety issue within minutes.

Lesson: Shared passwords, internet-exposed operator workstations, missing firewalls, and outdated OS builds on SCADA PCs are not “small town” problems—they are systemic OT hygiene failures. Monitor setpoints, require MFA for remote access, and keep engineering tools off the public internet.

2. Colonial Pipeline (May 2021) — Energy / pipelines

What happened: On May 7, 2021, DarkSide ransomware hit Colonial Pipeline’s corporate IT environment. Operators shut down roughly 5,500 miles of refined-products pipeline as a precaution while investigating and recovering. Colonial later confirmed a ransom payment of about $4.4 million for a decryptor; pipeline operations restarted around May 12.

Impact: Fuel distribution disruptions and panic buying across parts of the U.S. East Coast. The event became a kitchen-table cybersecurity moment and accelerated federal attention on pipeline OT security (including TSA security directives) and CISA’s broader critical-infrastructure posture.

Lesson: You do not need malware in the PLC to halt a pipeline. Compromised IT billing/operations systems—and the decision to isolate OT—can still create real-world shortages. Segment IT from OT, rehearse OT islanding, and treat identity and remote access as safety-critical controls.

3. JBS Foods (May–June 2021) — Food and agriculture

What happened: In late May 2021, REvil ransomware disrupted JBS, one of the world’s largest meat processors. U.S. plants were temporarily halted; operations in other countries were also affected. JBS later said it paid about $11 million to resolve the incident after restoring systems.

Impact: Short production outages and public concern about meat supply. The case showed how a concentrated agribusiness processor can become a single point of friction for national food logistics.

Lesson: Food and agriculture are critical infrastructure. Ransomware playbooks that ignore plant-floor recovery, cold-chain logistics, and subsidiary interconnectivity leave gaps. Backup integrity and cross-site containment matter as much as endpoint tools.

4. Industroyer2 against Ukrainian energy (April 2022) — Energy / OT-ICS

What happened: In April 2022, Sandworm operators attempted to disrupt a Ukrainian energy provider using Industroyer2—malware designed to issue IEC-104 commands against high-voltage substations—alongside destructive wipers intended to hinder recovery. Defenders detected and stopped the operation before a large blackout.

Impact: No mass outage from this attempt, but a high-confidence example of purpose-built ICS attack tooling in wartime, building on earlier Industroyer/CrashOverride lineage.

Lesson: Nation-state actors invest in protocol-aware OT malware and combine it with IT destruction. Protocol monitoring, engineering-workstation hardening, and recovery plans that assume wiped Windows environments are part of modern energy defense—not niche ICS research topics.

5. DP World Australia ports (November 2023) — Transportation / ports

What happened: On November 10, 2023, DP World Australia detected unauthorized access to its Australian corporate network and disconnected systems from the internet to contain the incident. Landside operations at terminals in Melbourne, Sydney, Brisbane, and Fremantle stopped. The company resumed port operations on November 13 and reported clearing a backlog of about 30,137 containers by November 20. DP World stated it found no ransomware deployment or ransom demand, but confirmed limited employee data exfiltration.

Impact: Multi-day disruption to roughly 40% of Australia’s container freight movement—enough to stress national supply chains even without encryption malware.

Lesson: Containment choices (pulling the plug) can be correct and still costly. Port operators need resilient landside systems, tested manual workarounds, and crisis coordination with government and shippers. “No ransomware” does not mean “no critical-infrastructure impact.”

6. CyberAv3ngers / Unitronics PLCs (November 2023–January 2024) — Water / OT

What happened: IRGC-affiliated actors using the CyberAv3ngers persona compromised internet-facing Unitronics Vision Series PLCs that used default or no passwords. CISA’s joint advisory (AA23-335A, updated December 2024) assessed at least 75 compromised devices in the U.S., including at least 34 in the Water and Wastewater Systems sector. A widely reported U.S. case involved a Municipal Water Authority of Aliquippa (Pennsylvania) booster-station PLC defaced in November 2023; operators switched to manual control and reported no impact on water quality or delivery.

Impact: Localized OT disruption and a sector-wide scramble to find and lock down exposed PLCs. The campaign underlined how commodity industrial HMIs become geopolitical targets when left on the public internet.

Lesson: Never expose PLCs/HMIs directly to the internet. Change default passwords, place devices behind VPN/firewall with MFA where possible, inventory internet-reachable assets, and treat “secure by default” vendor gaps as an enterprise risk.

7. Change Healthcare (February 2024) — Healthcare

What happened: On February 21, 2024, UnitedHealth Group disclosed a cyberattack on subsidiary Change Healthcare. Public testimony and reporting described ALPHV/BlackCat affiliates using stolen credentials against a Citrix remote-access portal that lacked multifactor authentication, dwelling for days before deploying ransomware. Change took major platforms offline; pharmacies, providers, and hospitals faced weeks of claims, eligibility, and payment disruption. Sector groups described it as among the most disruptive cyber events in U.S. healthcare history.

Impact: Nationwide friction in prescriptions, prior authorizations, and provider cash flow—evidence that a concentrated clearinghouse is critical infrastructure even when it is not a hospital bedside system.

Lesson: MFA on every remote-access path is non-negotiable. Third-party concentration risk belongs in board-level resilience planning. Healthcare organizations need contingency workflows for claims and Rx when a major intermediary fails.

8. Poland energy-sector incidents (December 29, 2025) — Energy / OT

What happened: On December 29, 2025, coordinated cyberattacks hit Poland’s energy sector, including numerous renewable facilities and combined heat and power (CHP) plants, as documented by CERT Polska. A follow-up analysis described a smaller CHP plant where attackers reached OT via a misconfigured private APN path and abused a WAGO PFC200 controller, briefly interrupting a steam turbine and process-water treatment. Operators limited customer impact; heat and electricity supplies to end users were preserved.

Impact: Short operational interruptions and a fresh warning about cellular/APN-connected industrial devices—attack paths that sit outside classic “IT firewall” mental models.

Lesson: Treat private APNs and cellular OT links as hostile networks unless tightly segmented and monitored. Default credentials on edge controllers remain an open door in 2025–2026, not a 2010s problem.

What is being done in 2026

Public- and private-sector defenses have matured since Colonial and JBS, even as attackers keep adapting.

Frameworks do not patch PLCs by themselves. They do give boards and plant managers a shared language for funding MFA, segmentation, and incident drills before the next headline.

What operators should do now

Practical priorities that map to the incidents above:

  1. Kill default and shared passwords on HMIs, PLCs, remote-access tools, and vendor accounts. Rotate credentials after staff or integrator changes.
  2. Enforce phishing-resistant MFA on every remote path into IT and OT (VPN, Citrix, cloud admin, jump hosts). Change Healthcare’s Citrix foothold is the cautionary tale.
  3. Remove OT from the public internet. If remote engineering is required, put it behind VPN/firewall with allowlists and logging—not a raw PLC port.
  4. Segment IT and OT (Purdue-style zones, proxies, tightly controlled historians). Rehearse operating in island mode when IT is on fire.
  5. Patch and inventory internet-exposed services aggressively; use free cyber hygiene scans where available. Know every cellular/APN-connected controller.
  6. Back up PLC logic and configurations offline, and test restores. Keep cold-standby hardware where downtime equals public-safety risk.
  7. Monitor for abnormal OT behavior—setpoint changes, unexpected engineering protocols, logins from odd places—not only antivirus alerts.
  8. Plan for third-party concentration risk (clearinghouses, port terminals, cloud SaaS). Manual or alternate workflows matter when a vendor goes dark.
  9. Report early to CISA, FBI, and sector ISACs. CIRCIA will formalize more of this; sharing IOCs still helps the next operator today.
  10. Use CSF 2.0 Govern + CISA CPGs as the board checklist: owners, risk decisions, and funding—not just a binder of policies.

For broader context on attack patterns, see our overview of types of cyber attacks and practical notes on ransomware.

Bottom line

From Oldsmar’s water plant to Colonial’s pipeline, Change Healthcare’s claims network, and 2025 energy OT incidents in Poland, the pattern is consistent: adversaries go where downtime hurts, and they often start with weak identity and exposed remote access—not exotic zero-days. Defenders who treat MFA, OT internet exposure, IT/OT segmentation, and governance as safety controls—not IT nice-to-haves—are far better positioned for 2026 and beyond.

Sources

FAQ

Which sectors count as critical infrastructure?

Energy, water, transportation, healthcare, communications, financial services, and government systems — plus the IT/OT vendors that keep them running.

Why do ransomware crews target OT environments?

Downtime is existential for operators, so payment pressure is high. Flat networks and aging HMIs still show up in post-incident reports.

Is air-gapping still realistic?

True air gaps are rare. Assume remote access, vendors, and update channels exist — then monitor and constrain them.

What should defenders do after a sector advisory?

Map the advisory to your assets within 24 hours, patch or compensate, and verify detection coverage. Frameworks help prioritize; the brief flags what just became urgent.

Stay Current

Newer CyberExperts coverage on this topic

This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.

Latest Daily Brief

Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

The fastest way to catch up on what changed after this article was published.

Read Today's Brief

George Mutune

I am a cyber security professional with a passion for delivering proactive strategies for day to day operational challenges. I am excited to be working with leading cyber security teams and professionals on projects that involve machine learning & AI solutions to solve the cyberspace menace and cut through inefficiency that plague today's business environments.