Ransomware Disrupts Romania’s Largest Coal Power Producer, Inside the Cyberattack on Oltenia Energy Complex + Video

Listen to this Post

Featured Image
🎯 Introduction: A Critical Energy Pillar Faces a Digital Shock

Romania’s energy sector entered a tense moment during the winter holidays when a major ransomware attack struck the Oltenia Energy Complex, the country’s largest coal-based electricity producer. While physical power generation remained stable, the incident exposed how deeply digital infrastructure now underpins national energy security. The attack did not just interrupt internal systems, it reignited concerns about cyber resilience across strategic state-controlled utilities at a time of geopolitical pressure and green transition.

🧩 Summary: What Happened at Oltenia Energy Complex

The Oltenia Energy Complex, known as CE Oltenia, is Romania’s primary lignite mining and coal-fired electricity producer. It operates 12 power generation units with a combined capacity of roughly 3,570 megawatts, spread across the Rovinari, Turceni, and Craiova power plants. Alongside generation, the company manages 15 open-pit lignite mines that collectively extract between 15 and 18 million tonnes of coal annually. Despite workforce reductions from around 15,000 to approximately 10,000 employees, CE Oltenia remains a cornerstone of Romania’s baseload energy supply.

On December 26, 2025, at approximately 01:40 in the morning, the company detected a ransomware attack attributed to a threat actor group known as “Gentlemen.” The cyberattack targeted the organization’s IT business infrastructure and resulted in the encryption of internal documents and files. Several essential digital services became temporarily unavailable, including enterprise resource planning systems, document management platforms, email services, and the company’s public website.

Oltenia Energy Complex confirmed that its operational activity was only partially affected and emphasized that the functioning of Romania’s National Energy System was never endangered. As a precaution, affected systems were isolated immediately, and authorities were notified. These included the National Directorate of Cyber Security, the Ministry of Energy, and law enforcement bodies responsible for investigating cybercrime.

Internal IT teams began restoring services using backups deployed on newly prepared infrastructure. At the time of disclosure, the full scope of the breach remained under investigation, and officials had not confirmed whether sensitive or personal data had been exfiltrated by the attackers. A criminal complaint was formally submitted to DIICOT, Romania’s Directorate for Investigating Organized Crime and Terrorism.

Notably, the Gentlemen ransomware group had not published Oltenia Energy Complex on its Tor-based data leak platform at the time of reporting. This absence often suggests that negotiations may still be ongoing or that attackers are waiting to increase pressure. The incident followed another recent ransomware attack on Romanian Waters, the national authority managing water resources, where approximately 1,000 systems across central and regional offices were affected. In that case, authorities confirmed the use of Windows BitLocker for system encryption, though operational infrastructure remained untouched.

🔎 What Undercode Say: Cyber Pressure Meets Energy Transition

The attack on Oltenia Energy Complex is not an isolated technical failure, it reflects a broader structural vulnerability within state-run critical infrastructure. As energy producers modernize operations and integrate complex IT and hybrid digital environments, their exposure to ransomware groups increases dramatically. In CE Oltenia’s case, the attackers targeted business systems rather than industrial control systems, which indicates a calculated decision to maximize disruption without triggering immediate national emergency protocols.

This incident also highlights a recurring pattern across Europe, where ransomware groups increasingly focus on public-sector and semi-public organizations that cannot afford prolonged outages. Energy providers face a unique dilemma. Paying a ransom risks legal, ethical, and political fallout, while refusal can prolong operational paralysis and public scrutiny. The silence of the Gentlemen group’s leak site suggests leverage-building behavior rather than immediate data extortion.

From a strategic standpoint, the timing is particularly sensitive. CE Oltenia is undergoing a costly transition driven by European Union decarbonization mandates. With over €1.4 billion earmarked for photovoltaic and gas-based projects, the company is already balancing financial pressure, workforce restructuring, and long-term energy security obligations. A ransomware incident introduces an additional risk layer that investors, regulators, and policymakers cannot ignore.

There is also a systemic lesson here. Romania’s recent string of ransomware incidents across water and energy sectors suggests attackers are probing national cyber defenses for consistency and response speed. Even when operational technology remains untouched, disruptions to ERP systems, communications, and logistics can slow decision-making during peak demand periods, especially in winter.

Cyber resilience must therefore be treated as infrastructure, not IT overhead. This means segmented networks, offline backups tested under real conditions, mandatory incident simulations, and tighter coordination between energy operators and national cyber authorities. Without these measures, future attacks may escalate from business disruption to physical consequences, regardless of current assurances.

🔍 Fact Checker Results

✅ The ransomware attack occurred on December 26, 2025 and disrupted IT business systems.
✅ National energy supply and operational power generation remained unaffected.
❌ No confirmed evidence yet of data exfiltration or public leak by attackers.

📊 Prediction

⚠️ Ransomware targeting Eastern European energy providers will intensify as geopolitical and economic pressure grows.
🔐 State-controlled utilities will face stricter cyber compliance and monitoring requirements.
⚡ Cybersecurity investment will become a prerequisite for energy transition funding and EU alignment.

▶️ Related Video (80% Match):

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon