Skip to main content
Back to overview
High

Electrica Group in Romania Hit by LYNX Ransomware Attack

Lynx ransomware behind Electrica energy supplier cyberattack ​The Romanian National Cyber Security Directorate (DNSC) says the Lynx ransomware gang breached Electrica Group, one of the largest electricity suppliers in…

Key points

  • Ransomware attack by the LYNX ransomware cybercrime group reported on December 9, 2024.
  • Critical power supply systems remained operational.
  • Company's primary focus was on protecting personal data managed and operational data.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Dec 9, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
4 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

ElectricaData DisclosureElectrica GroupRomania HitLYNX Ransomware Attack LynxElectricaDirectorateDNSCLynxNational Electricity Company

Quick context

Questions about this signal

What happened in this signal?

Lynx ransomware behind Electrica energy supplier cyberattack ​The Romanian National Cyber Security Directorate (DNSC) says the Lynx ransomware gang breached Electrica Group, one of the largest electricity suppliers in the country. Electrica became an independent company in 2000 after it was established as a division of the National Electricity Company (CONEL) in 1998. Since 2014, Electrica has been listed on the London and Bucharest stock exchanges. The company now provides electricity supply, maintenance, and other energy services to over 3.8 million users across Muntenia and Transylvania. Electrica warned investors on Monday that it was investigating an "ongoing" ransomware attack in collaboration with national cybersecurity authorities. Romania's Energy Minister Sebastian Burduja added that the company's SCADA and other critical systems were isolated and unaffected by the attack. Today, DNSC, one of the authorities involved in the investigation, revealed that the Lynx ransomware operation was responsible for the incident. It also provided a YARA script to help other security teams detect signs of compromise on their networks. "Based on available data, critical power supply systems have not been affected and are operational, and the investigation is currently ongoing. In the event of a ransomware infection, the Directorate strongly recommends that no one pay the ransom requested by the attackers," DNSC said . "DNSC recommends that all entities, especially those in the field of energy, whether or not they were affected by the ransomware attack, supported by the cybercrime group LYNX Ransomware, scan their own IT&C infrastructure for malicious binary (encryptor) using the YARA scan script. Lynx ransomware has been active since at least July 2024, adding over 78 victims to its clear web data leak site since August. According to the Center for Internet Security (CIS) , the list of claimed victims includes multiple U.S. facilities and over 20 entities from the energy, oil, and gas sectors, added between July 2024 and November 2024. Lynx operators have been using an encryptor likely based on the source code of INC Ransom malware allegedly put up for sale on the Exploit and XSS hacking forums for $300,000 in May. ​However, this could also be a rebranding effort to help INC RANSOM operate under less law enforcement scrutiny. BleepingComputer confirmed in August that Lynx ransomware and recent INC encryptors were mostly the same based on a string analysis. Since it emerged as a ransomware-as-a-service (RaaS) operation in July 2023, INC Ransom has also breached many education, healthcare, government, and industrial entities, including Yamaha Motor Philippines , Scotland's National Health Service (NHS), and the U.S. division of Xerox Business Solutions (XBS). The Lynx ransomware gang has not officially claimed the attack or added Electrica as a victim on its data leak site, suggesting that the attackers haven't yet made contact or are already pressuring the company into meeting their ransom demands. The Electrica ransomware attack comes after Romania's Constitutional Court (CCR) annulled this year's presidential elections based on extensive information that a massive Russia-linked TikTok influence campaign affected the results of the first round of elections. Romania's Intelligence Service (SRI) also declassified a report revealing that over 85,000 cyberattacks targeted the country's election infrastructure between November 19 and November 25, the night after the first presidential election round. In February, a Backmydata ransomware attack forced over 100 hospitals across Romania to take their systems offline after disrupting their healthcare management system. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. FortiBleed credential-theft campaign linked to Lynx ransomware Critical Palo Alto VPN bug now exploited by Qilin ransomware gang Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak JadePuffer agentic attacks now target AI model data with ransomware JadePuffer ransomware used AI agent to automate entire attack Critical wp2shell WordPress flaws exploited to install webshells Microsoft shares manual fix for WSUS sync delays and timeouts Windows LegacyHive zero-day flaw gets free, unofficial patches SonicWall SMA1000 flaws exploited as zero-days to push custom malware CISA orders urgent action on actively exploited Langflow RCE flaw Stop renting storage space — this lifetime 2TB plan is yours for $59 Microsoft to stop Exchange 2016 / 2019 security updates in October Chick-fil-A discloses data breach after credential stuffing attacks How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to backup and restore the Windows Registry How to remove a Trojan, Virus, Worm, or other Malware Lynx ransomware behind Electrica energy supplier cyberattack ​The Romanian National Cyber Security Directorate (DNSC) says the Lynx ransomware gang breached Electrica Group, one of the largest electricity suppliers in the country. Romanian energy supplier Electrica hit by ransomware attack Electrica Group, a key player in the Romanian electricity distribution and supply market, is investigating a ransomware attack that was still "in progress" earlier today. Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes Hugging Face warns an autonomous AI agent hacked its network Critical ServiceNow code execution flaw now exploited in attacks

When was this signal reported?

Shadow Tier lists Dec 9, 2024 as the signal date.

Which organization is connected to this signal?

Electrica is the organization connected to this public signal.

Explore Electrica
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence