/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cybersecurity firm Resecurity says hackers accessed 100+ computers of current and former staff at 21 major natural gas suppliers and exporters in mid-February

Bloomberg :

Bloomberg

Context & Ripple Effects

Resecurity's disclosure extends a decade-long arc of intrusions into energy operators: Symantec flagged the Dragonfly group inside US and European power-grid networks back in 2017, and the 2017 Saudi petro-plant hacks showed attackers reaching industrial controllers with destructive intent. What is new here is the target set — commercial staff machines at gas suppliers and exporters, not control rooms.

The finding also surfaces through a private channel rather than a government one. Resecurity, which later reported stolen login credentials at customer-support portals used by Apple, Amazon and others ([[a:836334]]), is establishing itself as the discovery layer for infrastructure intrusions — a role agencies once held alone, as when DHS had to revise its own tally up to hundreds of hacked utility victims in 2018.

First-order effects

  • The 21 named gas suppliers and exporters must now treat 100+ compromised staff computers as potential footholds, auditing what employee accounts could reach beyond email — the same IT-to-operational-networks question the Schneider Electric controller compromise made concrete.
  • Current and former employees at those firms face direct credential and device exposure, forcing incident-response engagement across two dozen corporate environments simultaneously.

Second-order effects

  • Counterparties buying gas from these exporters gain grounds to demand cyber-posture disclosures in supply contracts, a procurement lever sharpened after Colonial Pipeline's ransomware halt demonstrated that one compromised operator can take physical supply offline.
  • Government cyber agencies and rival threat-intel vendors face pressure to match Resecurity's disclosure cadence, since a private firm now controls the timeline and framing of an infrastructure breach story.

Third-order effects

  • If the sequence seen in the Saudi petro case holds — reconnaissance of staff systems preceding moves against industrial controls — regulatory oversight built around electric utilities after DHS counted hundreds of victims is likely to extend formally to natural gas supply chains.
  • Breach detection for critical infrastructure migrating to private intelligence firms like Resecurity would shift the first-mover role in disclosure from states to vendors, reshaping who sets response priorities across the energy sector.

The trend: Targeting of energy infrastructure is widening from power grids to natural gas supply chains, with private threat-intelligence firms increasingly reaching public disclosure before government agencies do.

Discussion

  • @annmarie @annmarie on x
    Resecurity spotted a small number of hackers, “including one linked to a wave of attacks in '18 against European orgs that MSFT attributed to Strontium, the company's nickname for a hacking group associated with Russia's GRU military intelligence service.” https://www.bloomberg.c…
  • @rory_johnston Rory Johnston on x
    And we were worried for a sec there that the US simply *not buying* Russian energy exports could be considered casus belli. L.O.L. https://twitter.com/...
  • @joshuasteinman Joshua Steinman on x
    We have two options: > We wake up *now* > We wake up “the day after” https://www.bloomberg.com/...
  • @sjcasey Simon Casey on x
    Big scoop: hackers targeted US LNG in run-up to Russia's invasion of Ukraine. -Nearly 2 dozen major natgas suppliers + exporters targeted -Hackers looked to pay on dark web for access to PCs of workers at large gas cos https://www.bloomberg.com/... via @jordanr1000+@SergioChapa