Calling energy the #1 ransomware target doesn’t hold up. The FBI ranked it 10th of 16 critical sectors for ransomware complaints in 2025. Houston still matters more than that rank suggests. Harris County alone holds 28.3% of US oil and gas extraction jobs, and the only 2 energy-sector companies in the US that filed an SEC material cyber incident report since late 2023 are based here. For the defensive side, start with our cybersecurity services in Houston.
Energy isn’t the #1 ransomware target, ranking 10th of 16 critical infrastructure sectors in FBI ransomware complaints for 2025, far behind healthcare and manufacturing. Houston energy companies get hit for a different reason. They run the billing, engineering, and financial systems a whole industry depends on.
I run operations at Uprite. So I read these incidents the way an operations person does. Less about the malware. More about what stopped working on Monday morning.
That #1 claim bugged me. It’s everywhere. Headlines, vendor decks, sales emails. Usually with no source. So before writing a word, we checked it against FBI complaint data, the SEC’s cyber incident filings, the Texas Attorney General’s breach list, and federal employment counts. The headline didn’t survive. The worry behind it did.
Harris County alone holds 28.3% of the country’s private oil and gas extraction jobs. The ransomware attacks with a paper trail here hit the office side of the business, not the wellhead. That’s the story worth telling. It’s also the kind of attack most likely to hit a 60-person oilfield service company in Katy or an engineering contractor in the Energy Corridor, not just the names you’d recognize.
What counts as a ransomware attack on an energy company?
A ransomware attack on an energy company is an intrusion where criminals encrypt or steal data on the company’s IT systems, such as billing, ERP, engineering files, and email, then demand payment to decrypt it or keep it quiet. Pipelines and rigs rarely get encrypted directly. When they stop, it’s usually because the business systems around them can’t run.
Colonial Pipeline is still the clearest example, even 5 years on. Its CEO told the Senate that DarkSide got in through a legacy VPN profile that was not intended to be in use. One forgotten login, basically. The company believes the attack encrypted its IT systems, and it shut down the entire pipeline as a precaution so the malware couldn’t reach the operational network that actually moves the fuel. The fuel stopped moving because the office got hit. Restart began 5 days later.
Dragos, which tracks attacks on industrial companies, said much the same about early 2026. In its first-quarter 2026 ransomware analysis, it didn’t observe any ransomware engineered to manipulate industrial control protocols. The damage came from lost IT systems, ERP platforms, and virtualization servers that operations lean on. Different door. Same outage.

Is energy really the #1 ransomware target?
No. Not in any dataset we checked. The FBI’s 2025 Internet Crime Report, from its Internet Crime Complaint Center (IC3), counted 54 ransomware complaints from the energy sector, 10th of 16 critical infrastructure sectors. Healthcare led with 460. Critical manufacturing had 355. Not close, either.
| Source and period | Who ranked #1 | Where energy landed |
|---|---|---|
| FBI IC3, 2025 ransomware complaints | Healthcare and public health, 460 | 10th of 16 sectors, 54 complaints |
| FBI IC3, 2024 ransomware complaints | Critical manufacturing, 258 | 9th of 14 sectors, 38 complaints |
| Dragos, industrial ransomware victims worldwide, Q1 2026 | Manufacturing, 62% of victims | 39 oil and gas incidents out of 1,020 |
| Texas AG breach notices, all causes, 12 months to Sept. 2026 | Retail or Merchant filers, 166 (a catch-all type) | 18 energy companies, 2.8% of 637 listings |
So why does the #1 line keep circulating? Some of it’s recycled marketing. And energy attacks are loud. When a pipeline stops, the whole country hears about it. A manufacturer’s outage usually stays private.
My take, for what it’s worth. Energy isn’t the most attacked sector, but it’s getting hit more each year, and the stakes per incident are unusually high. FBI ransomware complaints from the sector went from 30 in 2023 to 38 in 2024 to 54 in 2025. Counting public disclosures and leak-site postings worldwide, Dragos logged 15 oil and gas ransomware incidents in the first quarter of 2025 and 49 in the fourth quarter. More than triple within 2025. The count eased to 39 and 45 in the first two quarters of 2026.
The cost side is worse. Sophos surveyed energy, oil and gas, and utilities victims for its 2024 critical infrastructure report, and 79% of attempts to compromise their backups succeeded, the highest rate of any sector. More of those victims paid the ransom (61%) than restored from backups (51%). The median payment was $2.5 million. IBM’s 2026 Cost of a Data Breach study puts the average energy-sector breach at $5.2 million, above the $4.99 million global average. An operator should lose more sleep over those numbers than over any ranking.
Why does Houston carry so much of the exposure?
Because the business side of American energy lives here. Harris County alone had 33,022 private oil and gas extraction jobs in 2025, according to the Bureau of Labor Statistics Quarterly Census of Employment and Wages. That’s 28.3% of the national total and more than 4 times Midland County, the next largest, which tells you where the industry’s desks are, even when its rigs are somewhere else entirely.
| Industry (NAICS code) | Harris, Montgomery, and Fort Bend jobs, 2025 | US jobs, 2025 | Houston area share |
|---|---|---|---|
| Oil and gas extraction (211) | 34,044 or more | 116,777 | 29.2% or more |
| Pipeline transportation (486) | 13,500 | 56,154 | 24.0% |
| Drilling oil and gas wells (213111) | 7,749 or more | 40,658 | 19.1% or more |
| Support activities for oil and gas (213112) | 23,948 | 213,244 | 11.2% |
| Oil and gas pipeline construction (237120) | 14,515 | 146,412 | 9.9% |
Look at that first row. Those 3 counties hold 490 oil and gas extraction establishments, only 8% of the country’s, yet they employ at least 29% of the industry’s workers. It’s what headquarters look like in the data. Big offices full of the land, finance, engineering, and IT people who keep production moving hundreds of miles away in the Permian or the Gulf.
The Dallas Fed counts 19 energy-related companies among Houston’s 26 Fortune 500 headquarters as of 2025. Each of those sits on top of a supplier base of drilling contractors, plant service firms, engineering shops, and accounting advisors, most of them private and plenty of them small enough that nobody has security as a full-time job. Those firms worry me.
Texas producers see the split the same way. Ed Longanecker, president of the Texas Independent Producers and Royalty Owners Association (TIPRO), told the Odessa American, in a story GovTech reprinted, that criminal ransomware gangs tend to hit the business side of larger energy companies, while state actors pre-position in operational systems.

What do SEC filings show about Houston energy attacks?
Every Texas energy-sector company that filed an SEC Item 1.05 material cybersecurity incident report since the rule took effect in December 2023 is headquartered in Houston. Just 2. Halliburton and ENGlobal. We found that by pulling every Item 1.05 filing in SEC EDGAR through Sept. 26, 2026, which came to 84 filings from 58 companies nationwide, and those 2 Houston firms are the only energy-sector companies anywhere in that set.
Only 9 filings from 7 Texas companies carried Item 1.05 at all. The other 5 companies were in telecom, technology, and healthcare. None were energy. Widen the lens to every disclosure type and 5 Houston-area energy incidents show up in SEC filings.
| Company and HQ | Found | How it was disclosed | What went down | Cost disclosed |
|---|---|---|---|---|
| Halliburton, Houston | Aug. 21, 2024 | 8-K Item 8.01, then Item 1.05 | Parts of its business applications disrupted, some systems taken offline, data taken | $35 million expense in Q3 2024 |
| Newpark Resources (now NPK International), The Woodlands | Oct. 29, 2024 | 8-K Item 8.01, called ransomware by the company | Financial and operating reporting systems limited, field work ran on downtime procedures | None disclosed |
| ENGlobal, Houston | Nov. 25, 2024 | 8-K Item 1.05, amended Jan. 2025 | Some data files encrypted, IT limited to essential operations, reporting systems limited for about 6 weeks | None quantified |
| Flowco Holdings, Houston | Q2 2026 | 10-Q only, no 8-K | Internal business data exfiltrated | None disclosed |
| CenterPoint Energy, Houston | Sept. 2026 | 8-K Item 8.01 | Customer personal data taken through an external-facing system, service unaffected, not described as ransomware | Expects insurance to offset costs |
The first 3 landed within 96 days of each other in the second half of 2024, and by the time ENGlobal disclosed its attack, Cybersecurity Dive was calling it at least the third disruptive cyber incident at energy sector providers since August. Halliburton’s Item 1.05 filing said the attack disrupted and limited access to portions of its business applications supporting aspects of its operations and corporate functions. BleepingComputer later tied it to the RansomHub gang and was told that customers couldn’t generate invoices or purchase orders. Halliburton never named a group.
Newpark was blunter. Its Nov. 7, 2024 8-K called it a ransomware incident and said manufacturing and field operations continued “in all material respects” by using established downtime procedures. Read that twice. Especially if you run operations. Somebody at Newpark had written down how the field keeps working when the office systems are dark, and it paid off.
ENGlobal, an engineering and automation contractor serving the energy industry from the Energy Corridor, told investors in an amended filing that its financial and operating reporting systems were limited for about 6 weeks. Six weeks. The company filed for Chapter 11 in March 2025, and to be fair, its bankruptcy filing doesn’t blame the attack. I won’t either. But running on limited reporting systems for 6 weeks is a heavy load for a small public contractor. Ask any controller.
One caution. SEC data is a floor, not a count. Private companies don’t file 8-Ks, and several of these firms told investors their incident wasn’t material. The quiet cases are somewhere else.
What do smaller Houston energy firms’ breach notices show?
Energy companies and their plant service contractors made up 12 of the 75 Greater Houston breach notices on the Texas Attorney General’s list in the 12 months to Sept. 25, 2026, or 16%. By our classification, that’s second only to healthcare in the Houston area, even though the same group is only 4.2% of the whole list.
Texas law requires any organization whose breach affects 250 or more Texans to report it to the Attorney General within 30 days, and the AG publishes a running list of those reports. On Sept. 26, 2026, we pulled the data behind that list, all 637 listings posted between Oct. 1, 2025, and Sept. 25, 2026, including the breach start and discovery dates that companies report but the public table doesn’t display. Then we read every company name by hand, because the list has no energy category. Energy companies filed themselves as Other, as Retail or Merchant, and in one case as Financial Services. You won’t find them unless you read the names.
- 18 energy companies appeared on the list, from producers and oilfield service firms to a refiner, utilities, and energy engineering contractors. The count rises to 27 once you add the plant service and supply firms that work mainly for refineries and petrochemical sites.
- All 27 energy-sector filings we counted involved Social Security numbers. That’s common, though. SSNs show up in 83% of all listings.
- Among the 6 Houston-area energy companies whose notices include dates, the median gap from the start of a breach to the day the company says it discovered or confirmed it was 80 days. Energy filers on the whole list ran 64 days, faster than the list-wide 72.
- Those dates are self-reported, and some mark when a company confirmed what data was taken, not when it spotted the intruder. Deer Park’s USA DeBusk, for example, dates its incident to around Sept. 5, 2025, and says it determined on July 6, 2026, that personal information had been taken.
- Just outside our counts, Opportune LLP, a Houston advisory firm that works with energy companies, filed a notice covering 32,174 Texans.
What these notices can’t tell you is how many were ransomware. The public list doesn’t show what kind of breach each one was. Some were email account compromises, going by the companies’ own notice letters. Ransomware gangs have claimed a few of the others on leak sites, but the filings don’t confirm it, and I’m not going to guess on a company’s behalf.
Now look at who’s listed. Plant service contractors in Deer Park and Pasadena. A directional drilling firm in Conroe. A refiner on Eldridge Parkway. The SEC filings show you the big names. The AG list shows you the supply chain, and it’s longer.
The FBI sees it too. Outside the critical infrastructure sectors, contractors filed 17% of 2025 ransomware complaints and engineering firms filed 10%, a split we unpacked in why San Antonio businesses are ransomware targets. Swap in Houston’s plant service and engineering base and the math only gets worse.
How are attackers getting into Houston energy companies?
Mostly through the same doors they use everywhere else (stolen logins, unpatched edge devices, and vendor access), plus a few energy-specific ones. Nothing exotic.
- Stolen or weak logins. Sophos found energy, oil and gas, and utilities organizations had the highest identity breach rate of any industry it surveyed in 2026, at 80%.
- Unpatched VPN and firewall appliances. Vulnerability exploitation caused 40% of the incidents in IBM’s 2026 X-Force Threat Intelligence Index.
- An old remote access path nobody retired, like Colonial’s legacy VPN profile.
- Default passwords on field equipment. CISA warned in May 2025 that unsophisticated actors were targeting control systems in the oil and natural gas sector, and a companion fact sheet from CISA, the FBI, the EPA, and the Department of Energy flagged default or easily guessed passwords.
- Flat networks. In Dragos’s 2026 oil and gas findings, poor separation between IT and operational networks turned up in 29% of oil and gas findings, the highest share of any sector.
- Vendors and integrators with standing remote access to your systems, who often hold the keys to more than one operator at a time.
- Backups on the same network as everything else. In that 2024 Sophos survey, 98% of energy victims said attackers tried to compromise their backups.

That vendor bullet deserves more room than a bullet. A lot of Houston’s energy economy runs on contractors logging into someone else’s network, whether that’s the compressor technician with a tablet or the engineering firm with a standing connection into a client’s document system. When one of those firms gets compromised, the attacker inherits its access. Keys and all. Federal agencies make the same point more carefully in that fact sheet, noting that misconfigurations in operational systems can come from integrators, managed service providers, or vendor defaults. That includes firms like ours. Ask your providers how they secure their own access to you.
Dragos also measured how long ransomware sat in operational environments. Its 2026 Year in Review put the industry-wide average dwell time at 42 days. Organizations that could see across those networks detected and contained it in 5. Here in Texas, the Royal gang spent 26 days inside the City of Dallas network in 2023 before encrypting anything, which we covered in what Dallas City Hall learned the hard way.
What changed for Texas energy companies in 2026?
Three things moved this year, and none of them is a new state law.
First, the nation-state picture sharpened. A joint advisory from 7 federal agencies, AA26-097A, said an Iranian-affiliated group has been disrupting programmable logic controllers in the energy, water, and government sectors since at least March 2026, causing operational disruption and financial loss for some victims. That isn’t ransomware. It matters anyway, because a June 2025 fact sheet from CISA, the FBI, the NSA, and the Defense Department’s Cyber Crime Center warned that Iranian actors may work directly with ransomware affiliates.
Second, Texas regulators got louder. On April 10, 2026, the Railroad Commission passed those federal warnings to every regulated operator in a notice about an increased possibility of cyber attacks on internet-facing control equipment. In September, Commissioner Wayne Christian urged operators to tighten their defenses after the Coast Guard and FBI boarded 2 foreign-flagged energy vessels bound for the US, one of them a tanker headed to Galveston, over signs that foreign cyber actors had compromised their networks. The state also created the Texas Cyber Command in 2025, headquartered in San Antonio, and GovTech reports that its remit covers electric utilities, oil and gas pipelines, refineries, and LNG terminals.
Third, the rules are still in motion. TSA renewed both of its pipeline security directives. Security Directive Pipeline-2021-01G, in force since Jan. 16, 2026, requires designated critical pipelines to report cyber incidents to CISA within 72 hours. Its companion, 02G, runs from May 3, 2026, to May 2, 2027, and says operators stay responsible for compliance even when they hand security work to an outside provider. The federal Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule will require covered companies to report ransom payments to CISA within 24 hours, but it still wasn’t final when we checked CISA’s own CIRCIA page in late September 2026. Plan for it anyway.
Our guide to IT compliance for Texas oil and gas operators maps the rules that already apply. If you own power generation or large electrical loads, check whether NERC CIP rules for Texas oil and gas reach you too.
The Houston energy businesses most exposed to ransomware
The biggest names get hit too. They can absorb it. Halliburton booked $35 million. The firms that worry me more are the mid-size service and supply companies that hold a big operator’s data, connect into its network, and run with a 1- or 2-person IT department.
| Type of Houston energy business | What an attacker wants from it | First thing to check |
|---|---|---|
| Operator or midstream headquarters | Billing, ERP, and scheduling systems that stop revenue when they go down | Whether field operations can run on documented downtime procedures for 2 weeks |
| Oilfield service company, 50 to 500 people | Payroll, customer invoices, and remote access into operator sites | Who still has VPN or remote tool access, and whether MFA covers all of it |
| Engineering or EPC contractor | Drawings, bids, and standing connections into client document systems | How client project data is separated and backed up offline |
| Plant service contractor near the Ship Channel | Employee records with Social Security numbers, plus site access schedules | How long it would take you to notice a stranger in your HR system |
| Energy advisory or accounting firm | Royalty, tax, and financial data for many clients at once | Email security and phishing-resistant sign-in for every account |
If you run a 30-person back office for a family-owned producer, you’re in this table even if you never touch a control system. Maybe especially then.
What should a Houston energy company fix first?
Start with the business systems that stop revenue, because that’s where most Houston incidents on record did their damage. Protect the logins to them, keep an offline copy of their data somewhere an attacker can’t reach, and write down how the field keeps working if they go dark for 2 weeks.
People skip that last part. Security teams focus on keeping attackers out, and they should. But one sentence in Newpark’s filing is the most useful line in this whole story, and it isn’t about security at all. It’s about operations. When the office systems failed, the field already knew what to do.
From where I sit, the order looks like this.
- Put phishing-resistant MFA on email, remote access, and your ERP. In Sophos’s 2026 identity survey, 67% of ransomware victims said their incident stemmed from an identity attack.
- Kill old remote access paths. Every VPN profile, remote tool, and vendor account should have a named owner, or it goes.
- Keep one backup copy offline and restore something from it this quarter. Time it. Judson ISD’s backups reported success while the data behind them was being encrypted, one of the ransomware lessons from San Antonio worth stealing.
- Separate office and field networks so a compromised laptop can’t reach control equipment.
- Write the downtime procedures. Billing, payroll, dispatch, field reporting. On paper, if it comes to that.
- Rehearse it with leadership once a year, including who calls the lawyers, the insurer, and the FBI.
If you want the full control-by-control version, our ransomware protection playbook for Houston businesses walks through all 7 layers. For the operational technology side, the gaps where office and plant networks meet are covered in our guide to OT/IT security for Texas energy companies. And if you’re reading this in the middle of an incident, go straight to the first 72 hours of a ransomware recovery.
How Uprite approaches ransomware risk for energy companies
Uprite Services is a Texas-based managed IT and cybersecurity provider that has served businesses in Houston, San Antonio, Dallas, and Fort Worth since 1999, including oilfield service firms, engineering contractors, and energy suppliers. We focus on the business side (identity, endpoints, backups, and response), and we coordinate with the specialists who own a client’s control systems.
Our work with energy clients is mostly oil and gas IT services in Houston, with security built in, or security layered on top of an in-house IT team. Outside the Houston area, our page on managed IT for oil and gas companies covers the rest of Texas. Our MSSP Security Focus plan starts at $40 per user per month, and fully managed IT starts at $138 per user per month. Both prices are on our pricing page.
A fair warning, since we sell this. If you already run a 24/7 security operations center with analysts who understand operational networks, and you’ve restored your ERP from an offline backup in the last year, you probably don’t need us for this. Most Houston energy suppliers aren’t there yet. No criticism intended.
Want to know how your company would hold up if billing and reporting were down for 6 weeks? We’ll assess your logins, remote access, backups, and downtime plans, then hand you the fixes in the order they matter.
Get a Ransomware Risk AssessmentWhat Houston energy companies ask about ransomware
Has a Houston energy company actually been hit by ransomware?
Yes, and the filings say so. Newpark Resources in The Woodlands disclosed a ransomware incident it detected on Oct. 29, 2024, and Houston’s ENGlobal reported that a threat actor encrypted some of its data files a month later. Halliburton’s August 2024 attack was linked to the RansomHub gang by BleepingComputer, though Halliburton never named a group.
Can ransomware shut down a pipeline or a refinery?
Indirectly, and that’s usually how it happens. DarkSide hit only Colonial Pipeline’s IT systems in 2021, but Colonial shut its whole line so the malware couldn’t reach pipeline controls. Dragos didn’t observe ransomware engineered to manipulate industrial control protocols in early 2026.
Do small oilfield service and engineering firms really need to worry?
They should. Suppliers are where most of the visible Houston cases sit. On the Texas Attorney General’s breach list, Houston-area energy notices came mostly from service firms and contractors rather than the biggest names. Small firms also tend to hold standing access into bigger clients’ networks, which is exactly what an attacker wants to borrow.
How long do attackers sit inside before anyone notices?
42 days on average inside operational networks, according to Dragos’s 2026 Year in Review, and 5 days to detect and contain it for organizations that can see across those networks. On the Texas Attorney General’s list, the 6 Houston-area energy companies that reported dates took a median 80 days from the start of a breach to discovering or confirming it.
Who has to be told if a Houston energy company gets hit?
Usually more than one agency. Texas requires a report to the Attorney General within 30 days when a breach affects 250 or more Texans. Public companies generally must file an Item 1.05 8-K within 4 business days of deciding an incident is material, under the SEC’s 2023 cyber disclosure rule. TSA-designated critical pipelines must report cyber incidents to CISA within 72 hours. You can also report it to the FBI through IC3, the same system behind the complaint numbers in this post.
Do energy companies usually pay the ransom?
About half do. In Sophos’s 2026 ransomware survey, 47% of energy, oil and gas, and utilities organizations whose data was encrypted paid, close to the 48% average across sectors. Two years earlier, the sector’s rate was 61%, with a median payment of $2.5 million.









