New Rules for a Future Puerto Rico Microgrid Landscape


puerto rico cleanup

Substation Relay Protection Training

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 12 hours Instructor-led
  • Group Training Available
Regular Price:
$699
Coupon Price:
$599
Reserve Your Seat Today

Puerto Rico Microgrid Regulations outline renewable energy, CHP, and storage standards, enabling islanded systems, PREPA interconnection, excess energy sales, and IRP alignment to boost resilience, distributed resources, and community power across the recovering grid.

 

Key Points

Rules defining microgrids, requiring 75 percent renewables or CHP, and setting interconnection and PREPA fee frameworks.

✅ 75 percent renewables or CHP; hybrids allowed

✅ Registration, engineer inspection, and annual generation reports

✅ PREPA interconnection fees; excess energy sales permitted

 

The Puerto Rico Energy Commission unveiled 29 pages of proposed regulations last week for future microgrid installations on the island.

The regulations, which are now open for 30 days of public comment, synthesized pages of responses received after a November 10 call for recommendations. Commission chair José Román Morales said it’s the most interest the not-yet four-year-old commission has received during a public rulemaking process.

The goal was to sketch a clearer outline for a tricky-to-define concept -- the term "microgrid" can refer to many types of generation islanded from the central grid -- as climate pressures on the U.S. grid mount and more developers eye installations on the recovering island.

“There’s not a standard definition of what a microgrid is, not even on the mainland,” said Román Morales.

According to the commission's regulation, “a microgrid shall consist, at a minimum, of generation assets, loads and distribution infrastructure. Microgrids shall include sufficient generation, storage assets and advanced distribution technologies, including advanced inverters, to serve load under normal operating and usage conditions.”

All microgrids must be renewable (with at least 75 percent of power from clean energy), combined heat and power (CHP) or hybrid CHP-and-renewable systems. The regulation applies to microgrids controlled and owned by individuals, customer cooperatives, nonprofit and for-profit companies, and cities, but not those owned by the Puerto Rico Electric Power Authority (PREPA). Owners must submit a registration application for approval, including a certification of inspection from a licensed electric engineer, and an annual fuel, generation and sales report that details generation and fuel source, as well as any change in the number of customers served.

Microgrids, like the SDG&E microgrid in Ramona in California, can interconnect with the PREPA system, but if a microgrid will use PREPA infrastructure, owners will incur a monthly fee. That amounts to $25 per customer up to a cap of $250 per month for small cooperative microgrids. The cost for larger systems is calculated using a separate, more complex equation. Operators can also sell excess energy back to PREPA.

 

Big goals for the island's future grid

In total, 53 groups and companies, including Sunnova, AES, the Puerto Rico Solar Energy Industries Association (PR-SEIA), the Advanced Energy Management Alliance (AEMA), and the New York Smart Grid Consortium, submitted their thoughts about microgrids or, in many cases, broader goals for the island’s future energy system. It was a quick turnaround: The Puerto Rico Energy Commission offered a window of just 10 days to submit advice, although the commission continued to accept comments after the deadline.

“PREC wanted the input as fast as possible because of the urgency,” said AES CEO Chris Shelton.

AES’ plan includes a network of “mini-grids” that could range in size from several megawatts to one large enough to service the entire city of San Juan.

“The idea is, you connect those to each other with transmission so they can have a co-optimized portfolio effect and lower the overall cost,” said Shelton. “But they would be largely autonomous in a situation where the tie-lines between them were broken.”

According to estimates provided in AES’ filing, utility-scale solar installations over 50 megawatts on the island could cost between $40 and $50 per megawatt-hour. Those prices make solar located near load centers an economic alternative to the island’s fossil-fuel generating plants. The utility’s analysis showed that a 10,000-megawatt solar system could replace 12,000 gigawatt-hours of fossil generation, with 25 gigawatt-hours of battery storage leveling out load throughout the day. Puerto Rico’s peak load is 3,000 megawatts.

In other filings, PR-SEIA urged a restructuring of FEMA funds so they’re available for microgrid development. GridWise Alliance wrote that plans should consider cybersecurity, and AEMA recommended the commission develop an integrated resource plan (IRP) that includes distributed energy resources, microgrids and non-wires alternatives.

 

An air of optimism, though 1.5 million are still without power

After the commission completes the microgrid rulemaking, a new IRP is next on the commission’s to-do list. PREPA must file that plan in July, and regulators are working furiously to make sure it incorporates the recent flood of rebuilding recommendations from the energy industry.

Though the commission has the final say when it comes to approval of the plan, PREPA will lead the IRP process. The utility’s newly formed Transformation Advisory Council (TAC), a group of 11 energy experts, will contribute.

With that group, along with New York’s Resiliency Working Group, lessons from California's grid transition, the Energy Commission, the utility itself, and the dozens of other clean energy experts and entrepreneurs who want to offer their two cents, the energy planning process has a lot of moving parts. But according to Julia Hamm, CEO of the Smart Electric Power Alliance and a member of both the Energy Resiliency Working Group and the TAC, those working to establish standards for Puerto Rico’s future are hitting their stride.

“Certainly over the past three months, it has been a bit of a challenge to ensure that everybody has been coordinating efforts. Just over the past couple of weeks, we’ve seen some good progress on that front. We’re starting to see a lot more communication,” she said, adding that an air of optimism has settled on the process. “The key stakeholders all have a very common vision for Puerto Rico when it comes to the power sector.”

Nisha Desai, a PREPA board member who is liaising with the TAC, affirmed that collaborators are on the same page. “Everyone is violently in agreement that the future of Puerto Rico involves renewables, microgrids and distributed generation,” she said.

The TAC will hold its first in-person meeting in mid-January, and has already consulted with the utility on its formal fiscal plan submission, due January 10.

Though many taking part in the process feel the once-harried recovery is beginning to adopt a more organized approach, Desai acknowledges that “there are a lot of people in Puerto Rico who feel forgotten.”

Puerto Rico’s current generation sits at just 72.6 percent, in a nation facing longer, more frequent outages due to extreme weather. The government recently offered its first estimate that about half the island, 1.5 million residents, remains without power.

In late December and into January, 1,500 more crewmembers from 18 utilities in states as far flung as Minnesota, Missouri and Arizona will land on the island to aid further restoration through mutual aid agreements.

“The system is getting up to speed, getting to 100 percent, but there’s still some instability,” said Román Morales. “Right now it’s a matter of time.”

 

Related News

Related News

Windstorm Causes Significant Power Outages

Vancouver October 2024 Windstorm brought extreme weather to British Columbia, causing power outages, storm damage, and downed lines as BC Hydro crews led emergency response and restoration, highlighting climate change resilience and community preparedness.

 

Key Points

A severe storm with 100 km/h gusts that caused outages and damage in Vancouver, prompting wide power restoration.

✅ 100 km/h gusts toppled trees and downed power lines

✅ Over 200,000 BC Hydro customers lost electricity

✅ Crews and communities coordinated emergency response

 

In October 2024, a powerful windstorm swept through the Vancouver area, resulting in widespread power outages and disruption across the region. The storm, characterized by fierce winds and heavy rainfall, reflected conditions seen when strong winds in the Miami Valley knocked out power earlier this year, and was part of a larger weather pattern that affected much of British Columbia. Residents braced for the impacts, with local authorities and utility companies preparing for the worst.

The Storm's Impact

The windstorm hit Vancouver with wind gusts exceeding 100 km/h, toppling trees, and downing power lines. As the storm progressed, reports of damaged properties and fallen trees began to flood in. Many neighborhoods experienced significant power outages, mirroring widespread outages in Quebec earlier in the season, with thousands of residents left without electricity for extended periods. The areas hardest hit included the West End, Kitsilano, and parts of the North Shore, where the impact of the storm was particularly severe.

Utility companies, including BC Hydro operations, mobilized their crews quickly in response to the storm's aftermath. Emergency response teams worked tirelessly to restore power, often facing challenging conditions. The restoration efforts were complicated by the sheer number of outages reported—over 200,000 customers were affected at the height of the storm. Crews encountered not only downed lines but also hazardous conditions as they navigated through debris-laden streets.

Community Response and Resilience

In the wake of the storm, the community showcased remarkable resilience. Local residents rallied together to assist one another, sharing resources and providing support to those most affected. Many community centers opened their doors as emergency shelters, offering warmth and safety to those without power, a step also taken when a London power outage disrupted mornings for thousands across the city.

Authorities also emphasized the importance of preparedness in such situations. They urged residents to have emergency kits ready, including food, water, and essential supplies, noting that nearby areas like North Seattle can face sudden outages with little warning. Local officials highlighted the value of staying informed through weather updates and alerts, allowing residents to make informed decisions during extreme weather events.

The Role of Climate Change

The October windstorm serves as a stark reminder of the increasing frequency and intensity of extreme weather events, a trend often linked to climate change. Experts have noted that rising global temperatures are contributing to more severe weather patterns, including stronger storms and increased Toronto flooding events. As cities like Vancouver face the reality of climate change, discussions about infrastructure resilience and adaptation strategies have gained urgency.

City planners and environmental advocates are pushing for initiatives that enhance the city's ability to withstand extreme weather. This includes improving stormwater management systems, increasing green spaces to absorb rainfall, and investing in renewable energy sources. By addressing these challenges proactively, Vancouver aims to mitigate the impacts of future storms and protect its residents.

Moving Forward

As recovery efforts continue, the focus now shifts to restoring normalcy and preparing for future weather events. Residents are encouraged to report any ongoing outages or hazards to local authorities and to stay updated through reliable news sources. BC Hydro and other utility companies are committed to transparency, providing regular updates on power restoration efforts, even as outages can persist for days as seen in Toronto after a spring storm.

The October 2024 windstorm will be remembered not only for its immediate impacts but also as a catalyst for discussions on resilience and community preparedness. As Vancouver looks ahead, the lessons learned from this storm will shape strategies for better handling extreme weather, ensuring that the city is equipped to face the challenges posed by a changing climate.

In conclusion, while the windstorm caused significant disruption and hardship for many, it also highlighted the strength of community spirit and the importance of proactive planning in the face of climate challenges. Vancouver's response and recovery will be crucial in building a more resilient future for all its residents.

 

Related News

View more

Four Major Types of Substation Integration Service Providers Account for More than $1 Billion in Annual Revenues

Substation Automation Services help electric utilities modernize through integration, EPC engineering, protective relaying, communications and security, with CAPEX and OPEX insights and a growing global market for third-party providers worldwide rapidly.

 

Key Points

Engineering, integration, and EPC support modernizing utility substations with protection, control, and secure communications

✅ Third-party engineering, EPC, and OEM services for utilities

✅ Integration of multi-vendor devices and platforms

✅ Focus on relays, communications, security, CAPEX-OPEX

 

The Newton-Evans Research Company has released additional findings from its newly published four volume research series entitled: The World Market for Substation Automation and Integration Programs in Electric Utilities: 2017-2020.

This report series has observed four major types of professional third-party service providers that assist electric utilities with substation modernization. These firms range from (1) smaller local or regional engineering consultancies with substation engineering resources to (2) major global participants in EPC work, to (3) the engineering services units of manufacturers of substation devices and platforms, to (4) substation integration specialist firms that source and integrate devices from multiple manufacturers for utility and industrial clients, and often provide substation automation training to support implementation.

2016 Global Share Estimates for Professional Services Providers of Electric Power Substation Integration and Automation Activities

The North American market report (Volume One) includes survey participation from 65 large and midsize US and Canadian electric utilities while the international market report (Volume Two) includes survey participation from 32 unique utilities in 20 countries around the world. In addition to the baseline survey questions, the report includes 2017 substation survey findings on four additional specific topics: communications issues; protective relaying trends; security topics and the CAPEX/OPEX outlook for substation modernization.

Volume Three is the detailed market synopsis and global outlook for substation automation and integration:

Section One of the report provides top-level views of substation modernization, automation & integration and the emerging digital grid landscape, and a narrative market synopsis.

Section Two provides mid-year 2017 estimates of population, electric power generation capacity, transmission substations, including the 2 GW UK substation commissioning as a benchmark, and primary MV distribution substations for more than 120 countries in eight world regions. Information on substation related expenditures and spending for protection and control for each major world region and several major countries is also provided.

Section Three provides information on NGO funding resources for substation modernization among developing nations.

Section Four of this report volume includes North American market share estimates for 2016 shipments of many substation automation-related devices and equipment, such as trends in the digital relay market for utilities.

The Supplier Profiles report (Volume Four) provides descriptive information on the substation modernization offerings of more than 90 product and services companies, covering leading players in the transformer market as well.

 

Related News

View more

Florida Power & Light Faces Controversy Over Hurricane Rate Surcharge

FPL Hurricane Surcharge explained: restoration costs, Florida PSC review, rate impacts, grid resilience, and transparency after Hurricanes Debby and Helene as FPL funds infrastructure hardening and rapid storm recovery across Florida.

 

Key Points

A fee by Florida Power & Light to recoup hurricane restoration costs, under Florida PSC review for consumer fairness.

✅ Funds Debby and Helene restoration, materials, and crews

✅ Reviewed by Florida PSC for consumer protection and fairness

✅ Raises questions on grid resilience, transparency, and renewables

 

In the aftermath of recent hurricanes, Florida Power & Light (FPL) is under scrutiny as it implements a rate surcharge, alongside proposed rate hikes that span multiple years, to help cover the costs of restoration and recovery efforts. The surcharges, attributed to Hurricanes Debby and Helene, have stirred significant debate among consumers and state regulators, highlighting the ongoing challenges of hurricane preparedness and response in the Sunshine State.

Hurricanes are a regular threat in Florida, and FPL, as the state's largest utility provider, plays a critical role in restoring power and services after such events. However, the financial implications of these natural disasters often leave residents questioning the fairness and necessity of additional charges on their monthly bills. The newly proposed surcharge, which is expected to affect millions of customers, has ignited discussions about the adequacy of the company’s infrastructure investments and its responsibility in disaster recovery.

FPL’s decision to implement a surcharge comes as the company faces rising operational costs due to extensive damage caused by the hurricanes. Restoration efforts are not only labor-intensive but also require significant investment in materials and equipment to restore power swiftly and efficiently. With the added pressures of increased demand for electricity during peak hurricane seasons, utilities like FPL must navigate complex financial landscapes, similar to Snohomish PUD's weather-related rate hikes seen in other regions, while ensuring reliable service.

Consumer advocacy groups have raised concerns over the timing and justification for the surcharge. Many argue that frequent rate increases following natural disasters can strain already financially burdened households, echoing pandemic-related shutoff concerns raised during COVID that heightened energy insecurity. Florida residents are already facing inflationary pressures and rising living costs, making additional surcharges particularly difficult for many to absorb. Critics assert that utility companies should prioritize transparency and accountability, especially when it comes to costs incurred during emergencies.

The Florida Public Service Commission (PSC), which regulates utility rates and services, even as California regulators face calls for action amid soaring bills elsewhere, is tasked with reviewing the surcharge proposal. The commission’s role is crucial in determining whether the surcharge is justified and in line with the interests of consumers. As part of this process, stakeholders—including FPL, consumer advocacy groups, and the general public—will have the opportunity to voice their opinions and concerns. This input is essential in ensuring that the commission makes an informed decision that balances the utility’s financial needs with consumer protection.

In recent years, FPL has invested heavily in strengthening its infrastructure to better withstand hurricane impacts. These investments include hardening power lines, enhancing grid resilience, and implementing advanced technologies for quicker recovery, with public outage prevention tips also promoted to enhance preparedness. However, as storms become increasingly severe due to climate change, the question arises: are these measures sufficient? Critics argue that more proactive measures are needed to mitigate the impacts of future storms and reduce the reliance on post-disaster rate increases.

Additionally, the conversation around climate resilience is becoming increasingly prominent in discussions about energy policy in Florida. As extreme weather events grow more common, utilities are under pressure to innovate and adapt their systems. Some experts suggest that FPL and other utilities should explore alternative strategies, such as investing in decentralized energy resources like solar and battery storage, even as Florida declined federal solar incentives that could accelerate adoption, which could provide more reliable service during outages and reduce the overall strain on the grid.

The issue of rate surcharges also highlights a broader conversation about the energy landscape in Florida. With a growing emphasis on renewable energy and sustainability, consumers are becoming more aware of the environmental impacts of their energy choices, and some recall a one-time Gulf Power bill decrease as an example of short-term relief. This shift in consumer awareness may push utilities like FPL to reevaluate their business models and explore more sustainable practices that align with the public’s evolving expectations.

As FPL navigates the complexities of hurricane recovery and financial sustainability, the impending surcharge serves as a reminder of the ongoing challenges faced by utility providers in a climate-volatile world. While the need for recovery funding is undeniable, the manner in which it is implemented and communicated will be crucial in maintaining public trust and ensuring fair treatment of consumers. As discussions unfold in the coming weeks, all eyes will be on the PSC’s decision and FPL’s approach to balancing recovery efforts with consumer affordability.

 

Related News

View more

EU Smart Meters Spur Growth in the Customer Analytics Market

EU Smart Meter Analytics integrates AMI data with grid edge platforms, enabling back-office efficiency, revenue assurance, and customer insights via cloud and PaaS solutions, while system integration cuts costs and improves utility performance.

 

Key Points

EU smart meter analytics uses AMI data and cloud to improve utility performance, revenue assurance, and outcomes.

✅ AMI underpins grid edge analytics and utility IT/OT integration

✅ Cloud and PaaS reduce costs and scale data-driven applications

✅ Focus shifts from meter rollout to back-office and revenue analytics

 

Europe's investment in smart meters has begun to open up the market for analytics that benefit both utilities and customers.

Two new reports from GTM Research demonstrate the substantial investment in both advanced metering infrastructure (AMI) and specific customer analytics segments -- the first report analyzes the progress of AMI deployment in Europe, while the second is a comprehensive assessment of analytics use cases, including AI in utility operations, enabled by or interacting with AMI.

The Third Energy Package mandated EU member states to perform a cost-benefit analysis to evaluate the economic viability of deploying smart meters and broader grid modernization costs across member states. Two-thirds of the member states found there was a net positive result, while seven members found negative or inconclusive results.

“The mandate spurred AMI deployment in the EU, but all member states are deploying some AMI. Even without an overall positive cost-benefit outcome, utilities found pockets of customers where there is a positive business case for AMI,” said Paulina Tarrant, research associate at GTM Research and lead author of “Racing to 2020: European Policy, Deployment and Market Share Primer.”

Annual AMI contracting peaked in 2013 -- two years after the mandate -- with 29 million contracted that year. Today, 100 million meters have been contracted overall. As member states reach their respective targets, the AMI market will cool in Europe and spending on analytics and applications will continue to ramp up, aligning with efforts to invest in smarter infrastructure across the sector, Tarrant noted.

Between 2017 and 2021, more than $30 billion will be spent on utility back-office and revenue-assurance analytics in the EU, reflecting the shift toward the digital grid architecture, according to GTM Research’s Grid Edge Customer Utility Analytics Ecosystems: Competitive Analysis, Forecasts and Case Studies.

The report examines the broad landscape of customer analytics showing how AMI interacts with the larger IT/OT environment of a utility.

“The benefits of AMI expand beyond revenue assurance -- in fact, AMI represents the backbone of many customer utility analytics and grid edge solutions,” said Timotej Gavrilovic, author of the Grid Edge Customer Utility Ecosystems report.

Integration is key, according to the report.

“Technology providers are integrating data sets, solutions and systems and partnering with others to provide a one-stop shop serving broad utility needs, increasing efficiencies and reducing costs,” Gavrilovic said. “Cloud-based deployments and platform-as-a-service offerings are becoming commonplace, creating an opportunity for utilities to balance the cost versus performance tradeoff to optimize their analytics systems and applications.”

A diverse array of customer analytics applications is a critical foundation for demonstrating the positive cost-benefit of AMI.

“Advanced analytics and applications are key to ensuring that AMI investments provide a positive return after smart meters are initiated,” said Tarrant. “Improved billing and revenue assurance was not enough everywhere to show customer benefit -- these analytics packages will leverage the distributed network infrastructure, including advanced inverters used with distributed energy resources, and subsequent increased data access, uniting the electricity markets of the EU.”

 

Related News

View more

Electricity distributors warn excess solar power in network could cause blackouts, damage infrastructure

Australian Rooftop Solar Grid Constraints are driving debates over voltage rise, export limits, inverter curtailment, DER integration, and network reliability, amid concerns about localized blackouts, infrastructure protection, tariff reform, and battery storage adoption.

 

Key Points

Limits on solar exports to curb voltage rise, protect equipment, and keep the distribution grid reliable.

✅ Voltage rise triggers transformer protection and local outages.

✅ Export limits and smart inverter curtailment manage midday backfeed.

✅ Tariff reform and DER orchestration defer costly network upgrades.

 

With almost 1.8 million Australian homes and businesses relying on power from rooftop solar panels, there is a fight brewing over the impact of solar energy on the national electricity grid.

Electricity distributors are warning that as solar uptake continues to increase, there is a risk excess solar power could flow into the network, elevating power outage risks, causing blackouts and damaging infrastructure.

But is it the network businesses that are actually at risk, as customers turn away from centrally produced electricity?

This is what three different parties have to say:

Andrew Dillon of the network industry peak body, Energy Networks Australia (ENA), told 7.30 the way customers are charged for electricity has to change, or expensive grid upgrades to poles and wires will be needed to keep solar customers on the grid.

"The engineering reality is once we get too much solar in a certain space it does start to cause technical issues," he said.

"If there is too much energy coming back up the system in the middle of the day, it can cause frequency voltage disturbances in the system, which can lead to transformers tripping off to protect themselves from being damaged and that will cause localised blackouts.

"There are pockets of the grid already where we have significant penetration and we are starting to see technical issues."

However, he acknowledges that excess solar power has yet to cause any blackouts, or damage electricity infrastructure.

"I don't buy that at all," he said.

"It can be that in some suburbs or parts of suburbs a high penetration of solar on the point of use can raise voltage, these issues generally can be dealt with quickly.

"The critical issue is think where you are getting that perspective from. It is from an industry whose underlying market is threatened by customers doing it for themselves through peer-to-peer energy models. So, think with some critical insight to these claims."

He said when too many people rely on solar it threatens the very business model of the companies that own Australia's poles and wires.

"When the customers use the network less to buy centrally produced electricity, they ship less product," he said.

"When they ship less product, their underlying business is undermined, they need to charge more to the customers left and that leads to what has been called a death spiral.

"We are seeing rapid reductions in consumption at the point of use per household."

But Mr Dillon denies the distributors are acting out of self-interest.

"I absolutely reject that claim," he said.

"[What] we, as networks, have an interest in is running a safe network, running a reliable network, enabling the transition to a low carbon future and doing all that while keeping costs down as much as possible."

Solar installers say the networks are holding back business

Around Australia the poles and wires companies can decide which solar systems can connect to the grid.

Small systems can connect automatically, but in some areas, those wanting a larger system can find themselves caught up in red tape.

The vice-president of the Australian Solar Council, Glen Morris, said these limitations were holding back solar installation businesses and preventing the take-up of new battery storage technology.

"If you've already got a five kilowatt system, your house is full as far as the network is concerned," Mr Morris said.

"You go to add a battery, that's another five kilowatts and so they say no you're already full … so you can't add storage to your solar system."

The powers that be are stumbling in the dark to prevent a looming energy crisis, as the grid seeks to balance renewables' hidden challenges and competing demands.

Mr Morris also said the networks had the capacity to solve the problem of any excess solar flows into the grid, and infrastructure upgrades were not necessary.

"They already have the capability to turn off your solar invertor whenever they feel like it," he said.

"If they choose to connect that functionality, it's there in the inverter. The customer already has it."

ENA has acknowledged there is frustration with rooftop system size limits in the solar industry.

"What we are seeing is solar installers and others slightly frustrated at different requirements for different networks and sometimes they are unclear on the reasons for that," Mr Dillon said.

"Limitations are in place across the country to keep the lights on and make sure the network stays safe and we don't have sudden rushes of people connecting to the grid that causes outage issues."

But Mr Mountain is unconvinced, calling the limitations "somewhat spurious".

"The published, documented, critically reviewed analyses are few and far between, so it is very easy for engineers to make these arguments and those in policy circles only have so much tolerance for the detail," he said.

 

Related News

View more

Kaspersky Lab Discovers Russian Hacker Infrastructure

Crouching Yeti APT targets energy infrastructure with watering-hole attacks, compromising servers to steal credentials and stage intrusions; Kaspersky Lab links the Energetic Bear group to ICS threats across Russia, US, Europe, and Turkey.

 

Key Points

Crouching Yeti APT, aka Energetic Bear, is a threat group that targets energy firms using watering-hole attacks.

✅ Targets energy infrastructure via watering-hole compromises

✅ Uses open-source tools and backdoored sshd for persistence

✅ Scans global servers to stage intrusions and steal credentials

 

A hacker collective known for attacking industrial companies around the world have had some of their infrastructure identified by Russian security specialists.

Kaspersky Lab said that it has discovered a number of servers compromised by the group, belonging to different organisations based in Russia, the US, and Turkey, as well as European countries.

The Russian-speaking hackers, known as Crouching Yeti or Energetic Bear, mostly focus on energy facilities, as seen in reports of infiltration of the U.S. power grid targeting critical infrastructure, for the main purpose of stealing valuable data from victim systems.

 

Hacked servers

Crouching Yeti is described as an advanced persistent threat (APT) group that Kaspersky Lab has been tracking since 2010.

#google#

Kaspersky Lab said that the servers it has compromised are not just limited to industrial companies. The servers were hit in 2016 and 2017 with different intentions. Some were compromised to gain access to other resources or to be used as intermediaries to conduct attacks on other resources.

Others, including those hosting Russian websites, were used as watering holes.

It is a common tactic for Crouching Yeti to utilise watering hole attacks where the attackers inject websites with a link redirecting visitors to a malicious server.

“In the process of analysing infected servers, researchers identified numerous websites and servers used by organisations in Russia, US, Europe, Asia and Latin America that the attackers had scanned with various tools, possibly to find a server that could be used to establish a foothold for hosting the attackers’ tools and to subsequently develop an attack,” said the security specialists in a blog posting.

“The range of websites and servers that captured the attention of the intruders is extensive,” the firm said. “Kaspersky Lab researchers found that the attackers had scanned numerous websites of different types, including online stores and services, public organisations, NGOs, manufacturing, etc.

Kaspersky Lab said that the hackers used publicly available malicious tools, designed for analysing servers, and for seeking out and collecting information. The researchers also found a modified sshd file with a preinstalled backdoor. This was used to replace the original file and could be authorised with a ‘master password’.

“Crouching Yeti is a notorious Russian-speaking group that has been active for many years and is still successfully targeting industrial organisations through watering hole attacks, among other techniques,” explained Vladimir Dashchenko, head of vulnerability research group at Kaspersky Lab ICS CERT.

 

Russian government?

“Our findings show that the group compromised servers not only for establishing watering holes, but also for further scanning, and they actively used open-sourced tools that made it much harder to identify them afterwards,” he said.

“The group’s activities, such as initial data collection, the theft of authentication data, and the scanning of resources, are used to launch further attacks,” said Dashchenko. “The diversity of infected servers and scanned resources suggests the group may operate in the interests of the third parties.”

This may well tie into a similar conclusion from a rival security vendor.

In 2014 CrowdStrike claimed that the ‘Energetic Bear’ group was also tracked in Symantec's Dragonfly research and had been hacking foreign companies on behalf of the Russian state.

The security vendor had said the group had been carrying out attacks on foreign companies since 2012, with reports of breaches at U.S. power plants that underscored the campaign, and there was evidence that these operations were sanctioned by the Russian government.

Last month the United States for the first time publicly accused Russia in a condemnation of Russian grid hacking of attacks against the American power grid.

Symantec meanwhile warned last year of a resurgence in cyber attacks on European and US energy companies, including reports of access to U.S. utility control rooms that could result in widespread power outages.

And last July the UK’s National Cyber Security Centre (NCSC) acknowledged it was investigating a broad wave of attacks on companies in the British energy and manufacturing sectors.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.