zac amos

Why Hydropower Facilities Are Increasingly Targeted by Hackers

Hydroelectric power capacity is expanding due to its high reliability and domestic availability. However, this growth has been accompanied by an increase in attacks. Both hydropower and related water infrastructure have long been targets of physical conflicts and are now under threat from cyber warfare. Hostile actors exploit vulnerabilities to disrupt operations, steal data and spread fear. Here is why these facilities are such attractive targets and how they can strengthen their security.
Pixabay
Pixabay

The Current Hydropower Landscape

Reports show that hydropower is increasingly being targeted. One of the first notable, publicly documented attacks was on New York’s Bowman Dam. Iranian hackers infiltrated its control system as part of a broader cyber campaign against the United States' infrastructure. Though the access was limited, the incident was alarming. It highlighted that water and energy sites can be compromised digitally as well as physically.

More recently, in April 2025, Russian actors launched a cyberattack that had a significant impact on Norway’s Bremanger dam. They manipulated the control system to open the floodgates, releasing approximately 500 liters of water per second for four hours before the breach was contained. While no physical damage occurred, the incident remains one of the most significant threats. It was a clear, overt sabotage of vital infrastructure that raised safety and operational concerns.

Why Hydropower Facilities Are Attractive Targets

Hydropower sites have several qualities that make them particularly lucrative and strategic targets for adversaries.

  • Critical infrastructure role: Hydropower supplies a large share of renewable electricity and water management functions. It accounts for over 50% of renewable electricity generation. Infiltration can cause outages that affect energy grids and water supplies alike.
  • High operational impact: Manipulating industrial control systems (ICS) or Supervisory Control and Data Acquisition (SCADA) networks can disrupt generators, alter water flows or halt turbines. The effects can cascade on communities, agriculture and navigation.
  • Expanding attack surface: Increased adoption of the Internet of Things and remote access capabilities creates more points of entry for attackers.
  • Legacy systems and weak controls: Older systems often rely on default passwords and lack robust segmentation. More than 500 hydroelectric facilities in the U.S. and Canada are over 100 years old, raising their vulnerability.
  • Geopolitical signaling: State‑linked actors use attacks as psychological or geopolitical tools to showcase their advanced capabilities and instill fear.

How Hydropower Plants Can Improve Cybersecurity

Understanding why criminals target hydroelectric infrastructure is only half the equation. The more pressing question is how operators can respond and what practical steps will meaningfully improve security.

1. Prioritize Cyber Risk Assessment

Protection begins with a comprehensive cyber risk assessment. By identifying assets and mapping out vulnerabilities across IT and OT connections, facilities can direct investments where they matter most.

2. Segment, Harden and Control Network Access

Firewalls and control systems remain foundational preventions against break-ins, but they are insufficient as stand-alone tools. ICS/OT networks should be isolated from enterprise and internet-facing programs using strict segmentation. Unidirectional gateways allow data flow from critical OT channels to monitoring platforms without allowing external traffic back in.

Password reuse has become a widespread practice, but its convenience also creates vulnerabilities. Facility leaders should enforce strong access controls by replacing default credentials. Implementing multi-factor authentication further strengthens defenses by preventing unauthorized entry to important systems, even when credentials are compromised.

3. Secure and Maintain Industrial Systems

Outdated components remain one of the most common entry points for attackers, with 32% of incidents exploiting unpatched software vulnerabilities. To reduce this risk, hydropower operators should prioritize regular firmware and software updates. For remote sites, secure over-the-air update capabilities are also essential to prevent transmissions from being intercepted or exploited.

4. Monitor Continuously to Detect Early

Facilities should deploy real-time monitoring and anomaly detection tools designed for hydropower OT environments, capable of identifying unusual activity within SCADA systems, turbine controls and dam operations. AI-driven platforms can flag deviations from normal flow and flag behavior early, so operators can contain intrusions before they escalate into operational disruption or safety risks.

5. Prepare Through Training and Response Planning

Facility leaders should develop and routinely test incident response plans tailored to hydropower operations that cover both IT and OT. Combining this with ongoing staff training can minimize human error, boost awareness of phishing and social engineering threats, and ensure swift, coordinated action when attacks occur.

Strengthen Hydropower, Safeguard Communities

As hydropower remains the largest source of green energy, it remains a prime target for malicious actors seeking to cause disruption and sow fear. With increasingly sophisticated attack methods, defense systems must evolve to keep pace. By combining modern risk assessment practices with ongoing operational vigilance, facilities can lessen their vulnerability surface and ensure the grid remains resilient even amid rising digital threats.

Baterías con premio en la gran feria europea del almacenamiento de energía
El jurado de la feria ees (la gran feria europea de las baterías y los sistemas acumuladores de energía) ya ha seleccionado los productos y soluciones innovadoras que aspiran, como finalistas, al gran premio ees 2021. Independientemente de cuál o cuáles sean las candidaturas ganadoras, la sola inclusión en este exquisito grupo VIP constituye todo un éxito para las empresas. A continuación, los diez finalistas 2021 de los ees Award (ees es una de las cuatro ferias que integran el gran evento anual europeo del sector de la energía, The smarter E).