Ransom! Sangre de Cristo Electric Association (OCT-2026)

Ransom! Sangre de Cristo Electric Association (OCT-2026)
Incransom claims to have compromised a substantial volume of sensitive information belonging to Sangre de Cristo Electric Association (SDCEA), including US customer PII, financial/payment data, utility account details, and highly sensitive authentication and security information such as control-system credentials, API keys, and OT security configurations. The leaked data is also alleged to cover SDCEA’s energy infrastructure and operational technology environment, including electrical distribution systems, substations, transformers, outage information, and SCADA/EMS-related environments. #UnitedStates

Incident Details

  • Victim: Sangre de Cristo Electric Association
  • Sector: Energy & Utilities
  • Country: US
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6abef8ca9cd108bf26b10242
  • Discovered: 2026-10-02T01:33:07.817519+00:00
  • Published: 2026-10-01T00:00:00+00:00

Information

  • A substantial volume of sensitive information has been compromised, including customer personally identifiable information, financial and payment data, and utility account information.
  • The exposed material also includes information related to energy infrastructure and operational technology environments.
  • Compromised details cover electrical distribution infrastructure, substations, transformers, feeders, operational systems, renewable-generation assets, outage information, and SCADA/EMS-related environments.
  • Highly sensitive authentication and security data were also taken, including control-system credentials, API keys, and OT security configurations.
  • Negotiations were reportedly discontinued after the organization decided to end discussions.
  • Further disruptive actions were threatened to pressure responsible parties to treat security of entrusted resources with greater seriousness.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live