There are several components to the grid that powers the lights in North America. Its three interconnected regional networks—Eastern, Western, and Texas—share digital communications and power flows over thousands of miles of transmission infrastructure owned by hundreds of different businesses, are governed by a patchwork of federal and state authorities, and are increasingly under the scrutiny of adversaries who are more familiar with its architecture than many of the people tasked with safeguarding it.
Before its actions were made public, the U.S. Cybersecurity and Infrastructure Security Agency verified that the Chinese state-sponsored hacker outfit Volt Typhoon had hacked the IT environments of several American critical infrastructure companies. According to intelligence assessments, the group’s stated objective is to pre-position—embed access that can be activated to perform “disruptive or destructive cyberattacks” in the event of a significant conflict between the United States and China—rather than steal data. That threat is not the same as ransomware driven by financial gain. Money is what ransomware actors desire. Volt Typhoon desires reserve capability.

In contrast to years of regulatory compliance exercises, the timing of that disclosure, against the backdrop of growing geopolitical tension, focused minds in the utility sector. According to NERC’s own data, utilities reported about 1,162 cyberattacks in 2024 alone, a 70% increase over the year before. The majority of them were unsuccessful. However, as digitization grows, NERC’s tracking also reveals that the grid is creating about 60 additional susceptible locations every day. Smart meters, remote sensors, software-defined substations, solar and wind inverters powered by networked chips instead of mechanical relays—all of these constitute a surface that was absent from the grid twenty years ago, and they all carry some risk of assault.
Security experts see the greatest risk where information technology and operational technology blend together. In the past, a utility’s power plant management systems and business email network were entirely distinct. They were linked via modernization, which included cloud dashboards displaying real-time generation data, predictive maintenance, and remote monitoring. Depending on network architecture, an attacker who obtains access via a phishing email sent to a procurement officer may be able to access systems that manage real physical equipment. It’s not speculative. It is the known path in several verified invasions.
The ownership structure is what makes this difficult to justify. The private sector owns more than 80% of the energy infrastructure in the United States, which is distributed across investor-owned utilities, municipal power systems, and rural electric cooperatives with wildly disparate cybersecurity capabilities. NERC implements the requirements imposed by FERC for the bulk power system, which includes major generators and transmission lines. However, FERC has no jurisdiction over the distribution layer, which is the last mile of infrastructure that provides power directly to homes and businesses. Theoretically, a coordinated attack that targets both distribution and transmission may take advantage of that regulatory gap and target the area of the system where resources are scarce and standards are weakest.
Another significant threat to the current situation was the escalation of Iran’s dispute with the United States and Israel in the spring of 2026. Hackers with ties to Iran were deliberately targeting programmable logic controllers used in energy operations, according to a warning from CISA. In response, NERC publicly declared that it was keeping a close eye on the grid. The advise, which was sent to the energy industry with sufficient specificity to indicate verified reconnaissance action rather than broad worry, is not a speculative warning.
