27 Avril

Utility giant Itron confirms breach of internal systems

Itron, the Liberty Lake, WA-based company that provides smart utility meters to over 110 million homes and businesses across 100+ countries, disclosed a cyberattack in an SEC filing late Friday. The breach was first detected on April 13, 2026, when the company was notified that an unauthorized third party had gained access to portions of its corporate network.

The company says it immediately activated its cybersecurity response plan, expelled the intruders, and has seen no signs of continued unauthorized access since. Law enforcement has been notified.

Itron was careful to note that it “did not identify unauthorized activity in the customer-hosted portion of its systems.” That phrasing suggests the attackers stayed within Itron’s own IT infrastructure rather than reaching customer-facing services or operational technology. The company activated data backups and contingency plans, and says operations have continued in all material respects.

But the filing includes a notable hedge: Itron warned it may need to make subsequent legal filings and regulatory notifications. That language typically signals a potential data breach that could trigger state-level breach notification laws.

The scope of the attack remains unclear. Itron did not specify whether ransomware was involved, whether it was contacted by the attackers, or what data (if any) was exfiltrated. The company also hasn’t said who is responsible for its cybersecurity, declining to comment when asked by TechCrunch.

This is a significant target. Itron provides internet-connected meters and grid management technology for electricity, gas, and water utilities. A compromise of a company this deeply embedded in critical infrastructure raises obvious questions about supply chain risk. If attackers can persist in Itron’s network, what’s stopping them from pushing malicious firmware to millions of connected meters?

The SEC filing was made on April 24, roughly 11 days after the initial detection. That timing tracks with the SEC’s new disclosure requirements for material cybersecurity incidents, which require companies to file within four business days of determining an incident is material.

The breach comes at a time of elevated concern about critical infrastructure attacks. CISA and the FBI issued a joint advisory earlier this month warning about Iranian-affiliated cyber activity targeting US energy, water, and manufacturing sectors. There’s no indication the Itron breach is connected to that campaign, but the timing adds weight to an already tense environment.

Itron says insurers are expected to cover a significant portion of direct incident-related costs. The company also recently priced a $700 million convertible senior notes offering, though that appears unrelated to the cyber incident.

The company’s stock (NASDAQ: ITRI) hasn’t shown any significant movement in response to the disclosure as of Monday morning trading.

Sources: TechCrunch, BleepingComputer, Security Affairs, SEC 8-K Filing

Mots-cles

itron cyberattack critical infrastructure data breach smart meters sec filing