Cybersecurity firm Resecurity says hackers accessed 100+ computers of current and former staff at 21 major natural gas suppliers and exporters in mid-February
Context & Ripple Effects
Resecurity's disclosure extends a decade-long arc of intrusions into energy operators: Symantec flagged the Dragonfly group inside US and European power-grid networks back in 2017, and the 2017 Saudi petro-plant hacks showed attackers reaching industrial controllers with destructive intent. What is new here is the target set — commercial staff machines at gas suppliers and exporters, not control rooms.
The finding also surfaces through a private channel rather than a government one. Resecurity, which later reported stolen login credentials at customer-support portals used by Apple, Amazon and others ([[a:836334]]), is establishing itself as the discovery layer for infrastructure intrusions — a role agencies once held alone, as when DHS had to revise its own tally up to hundreds of hacked utility victims in 2018.
First-order effects
- The 21 named gas suppliers and exporters must now treat 100+ compromised staff computers as potential footholds, auditing what employee accounts could reach beyond email — the same IT-to-operational-networks question the Schneider Electric controller compromise made concrete.
- Current and former employees at those firms face direct credential and device exposure, forcing incident-response engagement across two dozen corporate environments simultaneously.
Second-order effects
- Counterparties buying gas from these exporters gain grounds to demand cyber-posture disclosures in supply contracts, a procurement lever sharpened after Colonial Pipeline's ransomware halt demonstrated that one compromised operator can take physical supply offline.
- Government cyber agencies and rival threat-intel vendors face pressure to match Resecurity's disclosure cadence, since a private firm now controls the timeline and framing of an infrastructure breach story.
Third-order effects
- If the sequence seen in the Saudi petro case holds — reconnaissance of staff systems preceding moves against industrial controls — regulatory oversight built around electric utilities after DHS counted hundreds of victims is likely to extend formally to natural gas supply chains.
- Breach detection for critical infrastructure migrating to private intelligence firms like Resecurity would shift the first-mover role in disclosure from states to vendors, reshaping who sets response priorities across the energy sector.
The trend: Targeting of energy infrastructure is widening from power grids to natural gas supply chains, with private threat-intelligence firms increasingly reaching public disclosure before government agencies do.