How many cyberattacks hit the power grid
How many cyberattacks hit the power grid depends on who is counting. The Verizon 2026 Data Breach Investigations Report, an annual study built from more than 31,000 security incidents examined worldwide, counted 638 incidents against United States utilities between October 2024 and November 2025, and states that 597 had a confirmed data disclosure, meaning attackers were confirmed to have taken data rather than only attempted to. Over that same period, the North American Electric Reliability Corporation, the federal regulator that oversees the reliability of the power grid across North America, received exactly 1 mandatory cyber incident report from a utility for all of 2025. The 2 figures are not 1 fact 2 sources disagree about. Verizon counts security incidents across a worldwide research dataset under its own definition. The regulator counts only what its own legal reporting rule requires. This site calculates the gap at more than 600 to 1, a comparison neither source states directly.
What Verizon counted inside the utility sector
Inside the 638 figure, the report states that 3 named attack patterns, System Intrusion, Basic Web Application Attacks and Social Engineering, together made up 94% of utility breaches. External attackers caused 97% of them, against 3% from inside the organization. Espionage was a motive in 71% of utility breaches, more than double the 36% financial motive share, and higher than in any other industry the report tracks, though the 2 shares do not add to 100% since a breach can carry more than 1 motive. Internal data was taken in 85% of breaches, trade secrets in 68%, and a category the report calls Other in 21%, again not additive since 1 breach can expose more than 1 data type.
These 3 figures do not add to 100% because 1 breach can expose more than 1 type of data.
Show the numbers
| Internal data | 85 |
| Trade secrets | 68 |
| Other | 21 |
Why the federal regulator counted only 1
The regulator explains, in its own filing, why its count is so much smaller. A utility that owns equipment on the Bulk Electric System, the high voltage network that carries electricity over long distances, must report an attempt to compromise its systems under Reliability Standard CIP 008 6, a mandatory rule in effect since January 1, 2021. For 2025, only 1 utility, in the reliability region covering the southeastern United States, filed such a report, describing port scans from a single internet address that its own defenses blocked with no effect on grid reliability, down from 3 reports the year before. The filing does not claim only 1 attempt happened. An internal 2021 study found the wording of the rule caused utilities to report fewer real attempts than actually occurred, and an active project, Project 2022 05, aims to rewrite that wording.
Where utilities rank against other industries
The same 2026 report tracks incident counts across many industries, and utilities sits well below the volume in finance, public administration, manufacturing and retail, the 4 industries closest to it in scale.
Financial and insurance, public administration, manufacturing and retail all recorded more incidents than utilities in the same report.
Show the numbers
| Financial and insurance | 3809 |
| Public administration | 3634 |
| Manufacturing | 3627 |
| Retail trade | 997 |
| Utilities | 638 |
That does not mean the sector is safer. Both counts likely understate real activity, the research figure because it depends on which breaches become known to the company and its partners, and the regulator figure because of the narrow legal definition above. Daniel Lawson, Senior Vice President of Global Solutions at Verizon Business, speaking about the report as a whole since no utility specific person appears among the 5 sources, says fundamentals matter more than any single count.
While the velocity of cyber threats driven by AI and faster vulnerability exploitation is increasing, the foundational principles of security and strong risk management remain the most effective defense.
Daniel Lawson, Senior Vice President of Global Solutions at Verizon Business, speaking in a Verizon news release about the report. Source 2.
The comment applies to a sector where external attackers caused 97% of breaches and a mandatory legal report still counted only 1 incident all year.