Attacks on power substations are growing. Why is the electric grid so hard to protect?


substation

CSA Z463 Electrical Maintenance

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 6 hours Instructor-led
  • Group Training Available
Regular Price:
$249
Coupon Price:
$199
Reserve Your Seat Today

Power Grid Attacks surge across substations and transmission lines, straining critical infrastructure as DHS and FBI cite vandalism, domestic extremists, and cybersecurity risks impacting resilience, outages, and grid reliability nationwide.

 

Key Points

Power Grid Attacks are deliberate strikes on substations and lines to disrupt power and weaken grid reliability.

✅ Physical attacks rose across multiple states and utilities.

✅ DHS and FBI warn of threats to critical infrastructure.

✅ Substation security and grid resilience upgrades urged.

 

Even before Christmas Day attacks on power substations in five states in the Pacific Northwest and Southeast, similar incidents of attacks, vandalism and suspicious activity were on the rise.

Federal energy reports through August – the most recent available – show an increase in physical attacks at electrical facilities across the nation this year, continuing a trend seen since 2017.

At least 108 human-related events were reported during the first eight months of 2022, compared with 99 in all of 2021 and 97 in 2020. More than a dozen cases of vandalism have been reported since September.

The attacks have prompted a flurry of calls to better protect the nation's power grid, with a renewed focus on protecting the U.S. power grid across sectors, but experts have warned for more than three decades that stepped-up protection was needed.

Attacks on power stations on the rise 
Twice this year, the Department of Homeland Security warned "a heightened threat environment" remains for the nation, including its critical infrastructure amid reports of suspected Russian breaches of power plant systems. 

At least 20 actual physical attacks were reported, compared with six in all of 2021. 
Suspicious-activity reports jumped three years ago, nearly doubling in 2020 to 32 events. In the first eight months of this year, 34 suspicious incidents were reported.
Total human-related incidents – including vandalism, suspicious activity and cyber events such as Russian hackers and U.S. utilities in recent years – are on track to be the highest since the reports started showing such activity in 2011.


Attacks reported in at least 5 states
Since September, attacks or potential attacks have been reported on at least 18 additional substations and one power plant in Florida, Oregon, Washington and the Carolinas. Several involved firearms.

  • In Florida: Six "intrusion events" occurred at Duke Energy substations in September, resulting in at least one brief power outage, according to the News Nation television network, which cited a report the utility sent to the Energy Department. Duke Energy spokesperson Ana Gibbs confirmed a related arrest, but the company declined to comment further.
  • In Oregon and Washington state: Substations were attacked at least six times in November and December, with firearms used in some cases, local news outlets reported. On Christmas Day, four additional substations were vandalized in Washington State, cutting power to more than 14,000 customers.
  • In North Carolina: A substation in Maysville was vandalized on Nov. 11. On Dec. 3, shootings that authorities called a "targeted attack" damaged two power substations in Moore County, leaving tens of thousands without power amid freezing temperatures.
  • In South Carolina: Days later, gunfire was reported near a hydropower plant, but police said the shooting was a "random act."

It's not yet clear whether any of the attacks were coordinated. After the North Carolina attacks, a coordinating council between the electric power industry and the federal government ordered a security evaluation.


FBI mum on its investigations
The FBI is looking into some of the attacks, including cyber intrusions where hackers accessed control rooms in past cases, but it hasn't said how many it's investigating or where. 

Shelley Lynch, a spokesperson for the FBI's Charlotte field office, confirmed the bureau was investigating the North Carolina attack. The Kershaw County Sheriff's Office reported the FBI was looking into the South Carolina incident.

Utilities in Oregon and Washington told news outlets they were cooperating with the FBI, but spokespeople for the agency's Seattle and Portland field offices said they couldn't confirm or deny an investigation.

Could domestic extremists be involved?
In January, the Department of Homeland Security said domestic extremists had been developing "credible, specific plans" since at least 2020, including a Neo-Nazi plot against power stations detailed in a federal complaint, and would continue to "encourage physical attacks against electrical infrastructure."

In February, three men who ascribed to white supremacy and Neo-Nazism pleaded guilty to federal crimes related to a scheme to attack the grid with rifles.

In a news release, Timothy Langan, assistant director of the FBI’s Counterterrorism Division, said the defendants "wanted to attack regional power substations and expected the damage would lead to economic distress and civil unrest."

 

Why is the power grid so hard to protect?
Industry experts, federal officials and others have warned in one report after another since at least 1990 that the power grid was at risk, and a recent grid vulnerability report card highlights dangerous weak points, said Granger Morgan, an engineering professor at Carnegie Mellon University who chaired three National Academies of Sciences reports.

The reports urged state and federal agencies to collaborate to make the system more resilient to attacks and natural disasters such as hurricanes and storms. 

"The system is inherently vulnerable, with the U.S. grid experiencing more blackouts than other developed nations in one study. It's spread all across the countryside," which makes the lines and substations easy targets, Morgan said. The grid includes more than 7,300 power plants, 160,000 miles of high-voltage power lines and 55,000 transmission substations.

One challenge is that there's no single entity whose responsibilities span the entire system, Morgan said. And the risks are only increasing as the grid expands to include renewable energy sources such as solar and wind, he said. 

 

Related News

Related News

How Ukraine Unplugged from Russia and Joined Europe's Power Grid with Unprecedented Speed

Ukraine-ENTSO-E Grid Synchronization links Ukraine and Moldova to the European grid via secure interconnection, matching frequency for stability, resilience, and energy security, enabling cross-border support, islanding recovery, and coordinated load balancing during wartime disruptions.

 

Key Points

Rapid alignment of Ukraine and Moldova into the European grid to enable secure interconnection and system stability.

✅ Matches 50 Hz frequency across interconnected systems

✅ Enables cross-border support and electricity trading

✅ Improves resilience, stability, and energy security

 

On February 24 Ukraine’s electric grid operator disconnected the country’s power system from the larger Russian-operated network to which it had always been linked. The long-planned disconnection was meant to be a 72-hour trial proving that Ukraine could operate on its own and to protect electricity supply before winter as contingencies were tested. The test was a requirement for eventually linking with the European grid, which Ukraine had been working toward since 2017. But four hours after the exercise started, Russia invaded.

Ukraine’s connection to Europe—which was not supposed to occur until 2023—became urgent, and engineers aimed to safely achieve it in just a matter of weeks. On March 16 they reached the key milestone of synchronizing the two systems. It was “a year’s work in two weeks,” according to a statement by Kadri Simson, the European Union commissioner for energy. That is unusual in this field. “For [power grid operators] to move this quickly and with such agility is unprecedented,” says Paul Deane, an energy policy researcher at the University College Cork in Ireland. “No power system has ever synchronized this quickly before.”

Ukraine initiated the process of joining Europe’s grid in 2005 and began working toward that goal in earnest in 2017, as did Moldova. It was part of an ongoing effort to align with Europe, as seen in the Baltic states’ disconnection from the Russian grid, and decrease reliance on Russia, which had repeatedly threatened Ukraine’s sovereignty. “Ukraine simply wanted to decouple from Russian dominance in every sense of the word, and the grid is part of that,” says Suriya Jayanti, an Eastern European policy expert and former U.S. diplomat who served as energy chief at the U.S. embassy in Kyiv from 2018 to 2020.

After the late February trial period, Ukrenergo, the Ukrainian grid operator, had intended to temporarily rejoin the system that powers Russia and Belarus. But the Russian invasion made that untenable. “That left Ukraine in isolation mode, which would be incredibly dangerous from a power supply perspective,” Jayanti says. “It means that there’s nowhere for Ukraine to import electricity from. It’s an orphan.” That was a particularly precarious situation given Russian attacks on key energy infrastructure such as the Zaporizhzhia nuclear power plant and ongoing strikes on Ukraine’s power grid that posed continuing risks. (According to Jayanti, Ukraine’s grid was ultimately able to run alone for as long as it did because power demand dropped by about a third as Ukrainians fled the country.)

Three days after the invasion, Ukrenergo sent a letter to the European Network of Transmission System Operators for Electricity (ENTSO-E) requesting authorization to connect to the European grid early. Moldelectrica, the Moldovan operator, made the same request the following day. While European operators wanted to support Ukraine, they had to protect their own grids, amid renewed focus on protecting the U.S. power grid from Russian hacking, so the emergency connection process had to be done carefully. “Utilities and system operators are notoriously risk-averse because the job is to keep the lights on, to keep everyone safe,” says Laura Mehigan, an energy researcher at University College Cork.

An electric grid is a network of power-generating sources and transmission infrastructure that produces electricity and carries it from places such as power plants, wind farms and solar arrays to houses, hospitals and public transit systems. “You can’t just experiment with a power system and hope that it works,” Deane says. Getting power where it is it needed when it is needed is an intricate process, and there is little room for error, as incidents involving Russian hackers targeting U.S. utilities have highlighted for operators worldwide.

Crucial to this mission is grid interconnection. Linked systems can share electricity across vast areas, often using HVDC technology, so that a surplus of energy generated in one location can meet demand in another. “More interconnection means we can move power around more quickly, more efficiently, more cost effectively and take advantage of low-carbon or zero-carbon power sources,” says James Glynn, a senior research scholar at the Center on Global Energy Policy at Columbia University. But connecting these massive networks with many moving parts is no small order.

One of the primary challenges of interconnecting grids is synchronizing them, which is what Ukrenergo, Moldelectrica and ENTSO-E accomplished last week. Synchronization is essential for sharing electricity. The task involves aligning the frequencies of every energy-generation facility in the connecting systems. Frequency is like the heartbeat of the electric grid. Across Europe, energy-generating turbines spin 50 times per second in near-perfect unison, and when disputes disrupt that balance, slow clocks across Europe can result, reminding operators of the stakes. For Ukraine and Moldova to join in, their systems had to be adjusted to match that rhythm. “We can’t stop the power system for an hour and then try to synchronize,” Deane says. “This has to be done while the system is operating.” It is like jumping onto a moving train or a spinning ride at the playground: the train or ride is not stopping, so you had better time the jump perfectly.

 

Related News

View more

Environmentalist calls for reduction in biomass use to generate electricity

Nova Scotia Biomass Energy faces scrutiny as hydropower from Muskrat Falls via the Maritime Link increases, raising concerns over carbon emissions, biodiversity, ratepayer costs, and efficiency versus district heating in the province's renewable mix.

 

Key Points

Electricity from wood chips and waste wood in Nova Scotia, increasingly questioned as hydropower from the Maritime Link grows.

✅ Hydropower deliveries reduce need for biomass on the grid

✅ Biomass is inefficient, costly, and impacts biodiversity

✅ District heating offers better use of forestry residuals

 

The Ecology Action Centre's senior wilderness coordinator is calling on the Nova Scotia government to reduce the use of biomass to generate electricity now that more hydroelectric power is flowing into the province.

In 2020, the government of the day signed a directive for Nova Scotia Power to increase its use of biomass to generate electricity, including burning more wood chips, waste wood and other residuals from the forest industry. At the time, power from Muskrat Falls hydroelectric project in Labrador was not flowing into the province at high enough levels to reach provincial targets for electricity generated by renewable resources.

In recent months, however, the Maritime Link from Muskrat Falls has delivered Nova Scotia's full share of electricity, and, in some cases, even more, as the province also pursues Bay of Fundy tides projects to diversify supply.

Ray Plourde with the Ecology Action Centre said that should be enough to end the 2020 directive.

Ray Plourde is senior wilderness coordinator for the Ecology Action Centre. (CBC)
Biomass is "bad on a whole lot of levels," said Plourde, including its affects on biodiversity and the release of carbon into the atmosphere, he said. The province's reliance on waste wood as a source of fuel for electricity should be curbed, said Plourde.

"It's highly inefficient," he said. "It's the most expensive electricity on the power grid for ratepayers."

A spokesperson for the provincial Natural Resources and Renewables Department said that although the Maritime Link has "at times" delivered adequate electricity to Nova Scotia, "it hasn't done so consistently," a context that has led some to propose an independent planning body for long-term decisions.

"These delays and high fossil fuel prices mean that biomass remains a small but important component of our renewable energy mix," Patricia Jreiga said in an email, even as the province plans to increase wind and solar projects in the years ahead.

But to Plourde, that explanation doesn't wash.

The Nova Scotia Utility and Review Board recently ruled that Nova Scotia Power could begin recouping costs of the Maritime Link project from ratepayers. As for the rising cost of fossil fuels, Ploude noted that the inefficiency of biomass means there's no deal to be had using it as a fuel source.

"Honestly, that sounds like a lot of obfuscation," he said of the government's position.

No update on district heating plans
At the time of the directive, government officials said the increased use of forestry byproducts at biomass plants in Point Tupper and Brooklyn, N.S., including the nearby Port Hawkesbury Paper mill, would provide a market for businesses struggling to replace the loss of Northern Pulp as a customer. Brooklyn Power has been offline since a windstorm damaged that plant in February, however. Repairs are expected to be complete by the end of the year or early 2023.

Ploude said a better use for waste wood products would be small-scale district heating projects, while others advocate using more electricity for heat in cold regions.

Although the former Liberal government announced six public buildings to serve as pilot sites for district heating in 2020, and a list of 100 other possible buildings that could be converted to wood heat, there have been no updates.

"Currently, we're working with several other departments to complete technical assessments for additional sites and looking at opportunities for district heating, but no decisions have been made yet," provincial spokesperson Steven Stewart said in an email.

 

Related News

View more

Californians Learning That Solar Panels Don't Work in Blackouts

Rooftop Solar Battery Backup helps Californians keep lights on during PG&E blackouts, combining home energy storage with grid-tied systems for wildfire prevention, outage resilience, and backup power when solar panels cannot supply nighttime demand.

 

Key Points

A home battery paired with rooftop solar, providing backup power and blackout resilience when the grid is down.

✅ Works when grid is down; panels alone stop for safety.

✅ Requires home battery storage; market adoption is growing.

✅ Supports wildfire mitigation and PG&E outage preparedness.

 

Californians have embraced rooftop solar panels more than anyone in the U.S., but amid California's solar boom many are learning the hard way the systems won’t keep the lights on during blackouts.

That’s because most panels are designed to supply power to the grid -- not directly to houses, though emerging peer-to-peer energy models may change how neighbors share power in coming years. During the heat of the day, solar systems can crank out more juice than a home can handle, a challenge also seen in excess solar risks in Australia today. Conversely, they don’t produce power at all at night. So systems are tied into the grid, and the vast majority aren’t working this week as PG&E Corp. cuts power to much of Northern California to prevent wildfires, even as wildfire smoke can dampen solar output during such events.

The only way for most solar panels to work during a blackout is pairing them with solar batteries that store excess energy. That market is just starting to take off. Sunrun Inc., the largest U.S. rooftop solar company, said some of its customers are making it through the blackouts with batteries, but it’s a tiny group -- countable in the hundreds.

“It’s the perfect combination for getting through these shutdowns,” Sunrun Chairman Ed Fenster said in an interview. He expects battery sales to boom in the wake of the outages, as the state has at times reached a near-100% renewables mark that heightens the need for storage.

And no, trying to run appliances off the power in a Tesla Inc. electric car won’t work, at least without special equipment, and widespread U.S. power-outage risks are a reminder to plan for home backup.

 

Related News

View more

Group to create Canadian cyber standards for electricity sector IoT devices

Canadian Industrial IoT Cybersecurity Standards aim to unify device security for utilities, smart grids, SCADA, and OT systems, aligning with NERC CIP, enabling certification, trust marks, compliance testing, and safer energy sector deployments.

 

Key Points

National standards to secure industrial IoT for utilities and grids, enabling certification and NERC CIP alignment.

✅ Aligns with NERC CIP and NIST frameworks for energy sector security

✅ Defines certification, testing tools, and a trusted device repository

✅ Enhances OT, SCADA, and smart grid resilience against cyber threats

 

The Canadian energy sector has been buying Internet-connected sensors for monitoring a range of activities in generating plants, distribution networks facing harsh weather risks and home smart meters for several years. However, so far industrial IoT device makers have been creating their own security standards for devices, leaving energy producers and utilities at their mercy.

The industry hopes to change that by creating national cybersecurity standards for industrial IoT devices, with the goal of improving its ability to predict, prevent, respond to and recover from cyber threats, such as emerging ransomware attacks across the grid.

To help, the federal government today announced an $818,000 grant support a CIO Strategy Council project oversee the setting of standards.

In an interview council executive director Keith Jansa said the money will help a three-year effort that will include holding a set of cross-country meetings with industry, government, academics and interest groups to create the standards, tools to be able to test devices against the standards and the development of product repository of IoT safe devices companies can consult before making purchases.

“The challenge is there are a number of these devices that will be coming online over the next few years,” Jansa said. “IoT devices are designed for convenience and not for security, so how do you ensure that a technology an electricity utility secures is in fact safeguarded against cyber threats? Currently, there is no associated trust mark or certification that gives confidence associated with these devices.”

He also said the council will work with the North American Electric Reliability Corporation (NERC), which sets North American-wide utility safety procedural standards and informs efforts on protecting the power grid across jurisdictions. The industrial IoT standards will be product standards.

According to Robert Wong, vice-president and CIO of Toronto Hydro, all the big provincial utilities are subject to adhering to NERC CIP standards which have requirements for both cyber and physical security. Ontario is different from most provinces in that it has local distribution companies — like Toronto Hydro — which buy electricity in bulk and resell it to customers.  These LDCs don’t own or operate critical infrastructure and therefore don’t have to follow the NERC CIP standards.

Regional reforms, such as regulatory changes in Atlantic Canada, aim to bring greener power options to the grid.

Electricity is considered around the world as one of a country’s critical national infrastructure. Threats to the grid can be used for ransom or by a country for political pressure. Ukraine had its power network knocked offline in 2015 and 2016 by what were believed to be Russian-linked attackers operating against utilities.

All the big provincial utilities operate “critical infrastructure” and are subject to adhering to NERC CIP (critical infrastructure protection) standards, which have requirements for both cyber and physical security, as similar compromises at U.S. electric utilities have highlighted recently.  There are audited on a regular basis for compliance and can face hefty fines if they fail to meet the requirements.  The LDCs in Ontario don’t own or operate “critical infrastructure” and therefore are not required to adopt NERC CIP standards (at least for now).

The CIO Strategy Council is a forum for chief information officers that is helping set standards in a number of areas. In January it announced a partnership with the Internet Society’s Canada Chapter to create standards of practice for IoT security for consumer devices. As part of the federal government’s updated national cybersecurity strategy it is also developing a national cybersecurity standard for small and medium-sized businesses. That strategy would allow SMBs to advertise to customers that they meet minimum security requirements.

“The security of Canadians and our critical infrastructure is paramount,” federal minister of natural resources Seamus O’Regan said in a statement with today’s announcement. “Cyber attacks are becoming more common and dangerous. That’s why we are supporting this innovative project to protect the Canadian electricity sector.”

The announcement was welcomed by Robert Wong, Toronto Hydro’s vice-president and CIO. “Any additional investment towards strengthening the safeguards against cyberattacks to Canada’s critical infrastructure is definitely good news.  From the perspective of the electricity sector, the convergence of IT and OT (operational technology) has been happening for some time now as the traditional electricity grid has been transforming into a Smart Grid with the introduction of smart meters, SCADA systems, electronic sensors and monitors, smart relays, intelligent automated switching capabilities, distributed energy resources, and storage technologies (batteries, flywheels, compressed air, etc.).

“In my experience, many OT device and system manufacturers and vendors are still lagging the traditional IT vendors in incorporating Security by Design philosophies and effective security features into their products.  This, in turn, creates greater risks and challenges for utilities to protecting their critical infrastructures and ensuring a reliable supply of electricity to its customers.”

The Ontario Energy Board, which regulates the industry in the province, has led an initiative for all utilities to adopt the National Institute of Standards and Technology (NIST) Cybersecurity Framework, along with the ES-C2M2 maturity and Privacy By Design models, he noted.  Toronto Hydro has been managing its cybersecurity practice in adherence to these standards, as the city addresses growing electricity needs as well, he said.

“Other jurisdictions, such as Israel, have invested heavily on a national level in developing its cybersecurity capabilities and are seen as global leaders.  I am confident that given the availability of talent, capabilities and resources in Canada (especially around the GTA) if we get strong support and leadership at a federal level we can also emerge as a leader in this area as well.”

 

Related News

View more

Hydro One deal to buy Avista receives U.S. antitrust clearance

Hydro One-Avista Acquisition secures U.S. antitrust clearance under Hart-Scott-Rodino, pending approvals from state utility commissions, the FCC, and CFIUS, with prior FERC approval and shareholder vote supporting the cross-border utility merger.

 

Key Points

A $6.7B cross-border utility merger cleared under HSR, still awaiting state, FCC, and CFIUS approvals; FERC approved earlier.

✅ HSR waiting period expired; U.S. antitrust clearance obtained

✅ Approvals pending: state commissions, FCC, and CFIUS

✅ FERC and Avista shareholders have approved the transaction

 

Hydro One Ltd. says it has received antitrust clearance in the United States for its deal to acquire U.S. energy company Avista Corp., even as it sought to redesign customer bills in Ontario.

The Ontario-based utility says the 30-day waiting period under the Hart-Scott-Rodino Antitrust Improvements Act expired Thursday night.

Hydro One announced the friendly deal to acquire Avista last summer, amid customer backlash in some service areas, in an agreement that valued the company at $6.7 billion.

The deal still requires several other approvals, including those from utility commissions in Washington, Idaho, Oregon, Montana and Alaska.

Analysts also warned of political risk for Hydro One during this period, reflecting concerns about provincial influence.

The U.S. Federal Communications Commission must also sign off on the transaction, and although U.S. regulators later rejected the $6.7B takeover following review, clearance is required by the Committee on Foreign Investment in the United States.

The agreement has received approval from the U.S. Federal Energy Regulatory Commission as well as Avista shareholders, and it mirrored other cross-border deals such as Algonquin Power's acquisition of Empire District that closed in the sector.

 

Related News

View more

Former B.C. Hydro CEO earns half a million without working a single day

B.C. Hydro Salary Continuance Payout spotlights executive compensation, severance, and governance at a Crown corporation after a firing, citing financial disclosure reports, Site C dam ties, and a leadership change under a new government.

 

Key Points

Severance-style pay for B.C. Hydro's fired CEO, via salary continuance and disclosed in public filings.

✅ $541,615 total compensation without working days

✅ Salary continuance after NDP firing; financial disclosures

✅ Later named Canada Post interim CEO amid strike

 

Former B.C. Hydro president and chief executive officer Jessica McDonald received a total of $541,615 in compensation during the 2017-2018 fiscal year, a figure that sits amid wider debates over executive pay at utilities such as Hydro One CEO pay at the provincial utility, without having worked a single day for the Crown corporation.

She earned this money under a compensation package after the in-coming New Democratic government of John Horgan fired her, a move comparable to Ontario's decision when the Hydro One CEO and board exit amid share declines. The previous B.C. Liberal government named her president and CEO of B.C. Hydro in 2014, and McDonald was a strong supporter of the controversial Site C dam project now going ahead following a review.

The current New Democratic government placed her on what financial disclosure documents call “salary continuance” effective July 21, 2017 — the day the government announced her departure — at a utility scrutinized in a misled regulator report that raised oversight concerns.

According to financial disclosure statements, McDonald remained on “salary continuance” until Sept. 21 of this year, and the utility has also been assessed in a deferred operating costs report released by the auditor general. During this period, she earned $272,659, a figure that includes benefits, pension and other compensation.

McDonald — who used to be the deputy minister to former premier Gordon Campbell — is now working for Canada Post, which appointed her as interim president and chief executive officer in March, while developments at Manitoba Hydro highlight broader political pressures on Crown utilities.

She started in her new role on April 2, 2018, and now finds herself in the middle of managing a postal carrier strike.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.