A Centrii risk assessment found that a coordinated compromise of cloud-based battery-storage control platforms could destabilize the ERCOT grid by maliciously coordinating battery dispatch. The model estimates that control of roughly 1,500 one-megawatt units—about 5.4% of Texas’s battery fleet—could disrupt frequency response, potentially interrupting service for up to 30 million people and causing as much as $65 billion in economic damage. Centralized optimizer and manufacturer cloud services, rather than individual batteries, are identified as the critical control-plane targets.
Malicious battery commands could resemble legitimate frequency-response activity or a poorly tuned controller, complicating detection and attribution during an incident. Centrii estimated a 92% probability of a notable battery-infrastructure cyberattack by 2031 under industry-average security practices; upgrading the fleet to IEC 62443 Security Level 2 could reduce the modeled attack’s effectiveness at an estimated $800 million to $2.8 billion. The findings are simulation-based risk estimates, not evidence that a battery-grid cyberattack has occurred.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
A 49-member expert panel concluded that Spain's blackout resulted from oscillations, voltage-control, and protection issues rather than a cyberattack. ENTSO-E published its final report and noted that key data from initially tripped power plants was unavailable.
Spain's power grid collapsed after a converter-driven forced oscillation at 0.63 Hz. The incident was initially difficult to diagnose.
Research by Afzal and colleagues found that altering load equivalent to 15% of a battery fleet's power could push grid frequency outside normal operating bounds.
Centrii published a risk assessment modeling coordinated compromise of grid-connected battery assets, estimating that compromise of about 1,500 ERCOT battery units, or 5.4% of the fleet, could destabilize the Texas grid. The modeled scenario could affect up to 30 million people and cause up to $65 billion in damage; it was not evidence of an actual battery-grid cyberattack.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.