Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us
Logo

Sangre de Cristo Electric Association


Discovered 2026-10-02 01:33 UTC
Est. attack date 2026-10-01
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Sangre de Cristo Electric Association (SDCEA) has been informed that a substantial volume of sensitive information has been compromised. The affected information includes customer personally identifiable information, financial and payment data, utility account information, and information associated with the organization’s energy infrastructure and operational technology environment. The information includes details concerning electrical distribution infrastructure, substations, transformers, feeders, operational systems, renewable-generation assets, outage information, and SCADA/EMS-related environments. The compromise data also include highly sensitive authentication and security information, including control-system credentials, API keys, and OT security configurations. We previously proposed resolving the incident through a peaceful and confidential process. According to our account, negotiations were subsequently discontinued after SDCEA CEO Jon Beyer indicated that the organization had decided to end discussions. As a result, we are issuing this public statement concerning the incident. In addition, we will take further disruptive actions to ensure that, in the future, those responsible for making these decisions approach the security of the resources entrusted to them—including the people within their area of responsibility—with greater awareness and seriousness.


Leak Screenshot:

Leak Screenshot