ENGlobal Cyber-Attack Reveals Vulnerable Information

ENGlobal, a US energy contractor, recently became a victim of a cyber-attack that resulted in the exposure of sensitive personal information. The attack occurred in November 2024, and the company’s IT system was infiltrated by a threat actor who gained access to a portion of data containing confidential details. In a filing with the Securities and Exchange Commission (SEC) dated January 27, 2025, ENGlobal confirmed that notifications will be sent out to affected individuals and relevant regulatory bodies as per legal requirements.

Limited information has been provided regarding the specific data that was compromised during the breach. Following the incident, the company experienced disruptions to several business applications supporting operations and corporate functions for approximately six weeks, including financial and operating reporting systems. However, all systems have since been fully restored, and ENGlobal believes that the threat actor no longer has access to its IT infrastructure.

Despite the cybersecurity incident, ENGlobal asserted in its SEC filing that the breach has not had a significant impact, nor is it likely to have a material effect on the company’s financial stability and operational performance. To enhance its cybersecurity measures and prevent future unauthorized access, the firm is collaborating with cybersecurity experts to bolster its defenses against cyber threats.

Specializing in automation and control systems for energy sector clients and US government agencies, ENGlobal holds contracts with organizations such as the Department of Defense and the Department of Energy. The attack on ENGlobal underscores the escalating cyber threats faced by critical infrastructure entities, with an increased risk of threat actors exploiting vulnerabilities to compromise system integrity and data confidentiality.

Initial findings following the cyber-attack suggest that ransomware may have been involved, with data files being encrypted by the threat actor. The identity of the perpetrator remains unknown at this time. The incident serves as a reminder of the growing trend of cybercriminals targeting third-party suppliers to gain unauthorized access to critical infrastructure organizations. A recent report by SecurityScorecard and KPMG highlighted that 45% of security breaches affecting the industry in the past year were linked to third-party breaches.

In a similar ransomware incident in November 2024, energy services provider Halliburton reported a $35 million loss as a result of a cyber-attack. The frequency and severity of cyber threats targeting critical infrastructure have raised concerns about the need for robust cybersecurity measures to protect sensitive data, prevent unauthorized access, and mitigate potential financial losses resulting from breaches. As organizations like ENGlobal continue to work towards strengthening their defenses and improving their incident response capabilities, the cybersecurity landscape remains a dynamic and evolving environment that demands vigilance, innovation, and collaboration in the fight against cyber threats.