The Qilin ransomware operation claimed it breached Tennessee Valley Electric Cooperative (TVEC), an electric cooperative serving parts of West Tennessee, but provided no data samples on its leak site and TVEC had not publicly acknowledged the incident at the time of reporting. Based on Qilin’s prior activity against other U.S. electric cooperatives, the alleged theft could involve organizational data such as employee and customer information or internal documents, though the specific data allegedly taken from TVEC remains unverified.
Separately, ELECQ, a maker of smart EV chargers, notified customers that a ransomware attack hit parts of its AWS cloud environment, with some databases reportedly encrypted and copied, indicating potential data theft. ELECQ said exposed data was limited to customer contact details (names, emails, phone numbers, and home addresses), with no payment/credit-card data involved and no impact to the charging devices themselves; the company reported taking affected servers offline, restoring from backups, and hardening access controls (including disabling remote access services such as SSH and Telnet) while reporting the incident to regulators including the UK ICO and Germany’s BfDI.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Reporting on Qilin's recent activity also noted the group claimed to have stolen 222 GB of data from Spark Power, a Canada-based electrical services company with U.S. operations. The synopsis does not provide independent verification or a more specific date for the claim.
The Qilin ransomware operation purportedly listed Tennessee Valley Electric Cooperative on its leak site, claiming a breach of the U.S. electric cooperative. No proof-of-data samples were published, and TVEC had not publicly acknowledged the incident at the time of reporting.
As part of its response, ELECQ said it disabled remote access services such as SSH and Telnet and improved encryption measures. It also urged customers to reset passwords and remain alert for phishing attempts.
ELECQ notified customers that names, email addresses, phone numbers, and home addresses were exposed in the ransomware attack, while saying payment and credit card data and charging devices were not affected. The company also said it reported the incident to European regulators including the UK ICO and Germany’s Federal Commissioner for Data Protection and Freedom of Information.
After detecting the intrusion, ELECQ said it took affected servers offline and started incident response and recovery efforts, including restoring systems from backups. The company also engaged third-party cybersecurity specialists to support forensic investigation.
ELECQ said it identified unusual activity affecting its AWS cloud environment on March 7, 2026. The incident involved encryption of some databases and copying of data, indicating likely data theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.