Itron, a U.S. utility technology company, disclosed that an unauthorized third party accessed portions of its internal IT environment, with the intrusion detected on April 13. The company said it activated its incident response plan, engaged external cybersecurity experts, notified law enforcement, and began containment, remediation, and forensic investigation. Itron reported that malicious activity has been blocked, no subsequent unauthorized activity has been observed in its corporate systems, and no unauthorized activity was identified in the customer-hosted portion of its environment.
The company said business operations have remained largely unaffected because of contingency plans and backups, and it does not currently expect the incident to have a material impact, with insurance expected to cover a significant share of related costs. The full scope of the breach remains under investigation, including whether legal or regulatory notifications will be required, and no threat actor or ransomware group has publicly claimed responsibility for the intrusion.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Medtronic said an unauthorized party accessed data in certain corporate IT systems. The company stated its products, patient safety, manufacturing, distribution, customer connections, and financial reporting systems were not affected.
At Black Hat Asia in Singapore, RunSybil CEO Ari Herbert-Voss said frontier LLMs are accelerating offensive security work and that average time from bug discovery to exploitation had fallen from five months in 2023 to about 10 hours in 2026. He said AI can autonomously perform substantial parts of multistep attack chains in controlled settings, but still remains unreliable for fully autonomous real-world mass exploitation.
Itron publicly disclosed that an unauthorized third party had accessed portions of its internal IT environment and said its investigation into scope and impact was ongoing. The company stated it did not expect a material impact and anticipated insurance would cover a significant portion of related costs.
After detecting the intrusion, Itron activated its cybersecurity response plan, engaged external cybersecurity advisors, and notified law enforcement to investigate, contain, and remediate the breach. The company said the malicious activity was blocked and no follow-on activity had been observed.
Itron detected a cyberattack involving unauthorized access to certain internal corporate systems on April 13, 2026. The company later said it had not observed unauthorized activity in customer-hosted environments and that business operations were largely unaffected.
Operational technology and industrial control system security leaders, including representatives from Claroty and SANS, warned that pure-play OT and ICS vendors appeared to be left out of Anthropic's Project Glasswing early-access effort. They argued critical infrastructure defenders need participation because OT patching and mitigation timelines are slower and AI is sharply reducing time-to-exploit.
Anthropic said its advanced AI model Mythos had already found thousands of high-severity vulnerabilities, including flaws in major operating systems and web browsers, but did not release it publicly because of its dangerous exploit-generation capability. This decision became a focal point for debate over who should receive early access through Project Glasswing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcego.theregister.com
Open sourcetechcrunch.com
Open sourcethecyberthrone.in
Open sourcedarkreading.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.