Romania’s Electrica Group disclosed a cyberattack on December 9, 2024. The incident was later identified as a LYNX ransomware attack affecting the information systems of Distribuție Energie Electrică România (DEER), Electrica’s electricity-distribution subsidiary. Customer-facing services were disrupted, but official statements said the electricity network and operational SCADA systems remained functional.
The wording matters for customers: this was not evidence of a nationwide power outage, and the confirmed victim was not simply Electrica’s electricity-selling business, Electrica Furnizare.
What happened to Electrica?
Electrica announced on December 9, 2024, that it was responding to an ongoing cyberattack. The company said it had activated its internal incident-response procedures, was working with Romanian cybersecurity authorities, and had applied protective measures to limit the impact.
Electrica’s initial market disclosure did not name a ransomware family. It warned that protective measures could cause temporary problems with customer interactions and said the company was prioritising the protection of personal and operational data.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Romania’s Ministry of Energy subsequently described the event as a ransomware attack against DEER’s information systems. Electrica’s 2024 annual report, published later, identified it as a LYNX ransomware attack.
Which Electrica business was affected?
Electrica SA is the listed parent company of a group that includes several distinct businesses:
- DEER: Distribuție Energie Electrică România, the electricity-distribution company that operates parts of the physical power network.
- Electrica Furnizare: the electricity supplier that manages customer contracts, billing and related commercial services.
A distributor maintains lines, substations, meters and other network infrastructure. A supplier sells electricity and handles customer accounts. The official descriptions of the 2024 incident point primarily to DEER’s information systems, so it is imprecise to describe the event simply as Electrica Furnizare being hacked.
Electrica says DEER operates nearly 198,988 kilometres of power lines across 18 Romanian counties and serves more than 3.8 million users. That current corporate footprint should not be confused with the approximately 3.5 million consumers whose affected services were referenced in Electrica’s 2024 annual report.
Free tools Windows power users keep installed
One-click scans. No signup required.
Did the ransomware attack cut off electricity?
The available official statements do not indicate that the attack disrupted electricity delivery or nationwide grid operations.
The Ministry of Energy said network equipment was not affected and that the SCADA system had been isolated but remained fully operational. SCADA systems are used to monitor and control industrial processes, including elements of electricity infrastructure.
That does not mean the incident was harmless. A utility can isolate business IT systems, customer platforms or supporting services while keeping operational technology running. Customers may then have difficulty contacting the company, checking an account or completing a digital transaction even though power continues to flow.
What services were disrupted?
Electrica’s initial disclosure referred to possible malfunctions in interactions with consumers caused by protective measures applied to its internal infrastructure. Its later annual report said services for approximately 3.5 million consumers were affected.
Rank #3
The public record does not provide a complete service-by-service outage list. It supports cautious references to customer-interaction and supporting IT disruption, which may include account-management or billing-related processes. It does not establish that electricity generation, transmission, grid control or every billing system was unavailable.
For a customer, an inaccessible portal or delayed response therefore does not by itself prove that the physical electricity network was compromised.
Who was behind the attack?
Electrica’s 2024 annual report identified the incident as a LYNX ransomware attack. That is the strongest public attribution in the supplied official record.
There is not enough verified information to say who operated LYNX, whether the group was state-sponsored, what its motive was, how it gained access, how much ransom was demanded, whether any ransom was paid or whether stolen data was published.
Was customer data stolen?
Public sources reviewed do not confirm that customer data was exfiltrated. The initial disclosure said Electrica was prioritising the protection of personal and operational data, but that is not the same as confirming either data theft or the absence of data theft.
Rank #4
The confirmed facts are narrower: Electrica experienced a cyberattack, protective measures caused customer-facing disruption, and the later annual report described services for approximately 3.5 million consumers as affected.
What customers should do
The 2024 ransomware incident should not be confused with a separate phishing warning issued by Electrica Furnizare on May 23, 2026. In that notice, the supplier warned that criminals were impersonating the company and directing customers toward purported invoices or payments.
- Use Electrica’s official website and independently verified customer-service details rather than links in unexpected messages.
- Check the sender’s full email domain carefully.
- Do not open unexpected attachments or enter personal, banking or card details on an unfamiliar page.
- Do not assume that a message mentioning a genuine bill or electricity account is authentic.
- If a payment request seems unusual, contact the supplier through a contact method obtained independently.
Electrica Furnizare’s phishing warning contains the company’s specific guidance. It concerns impersonation and phishing, not evidence of a new ransomware attack on Electrica.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTimeline
| Date | What was reported |
|---|---|
| December 9, 2024 | Electrica disclosed an ongoing cyberattack and activated its response procedures. |
| December 9, 2024 | The Ministry of Energy described the event as ransomware affecting DEER’s IT systems, while saying network equipment was unaffected and SCADA remained operational. |
| April 30, 2025 | Electrica’s 2024 annual report identified the attack as LYNX ransomware and referred to services affecting approximately 3.5 million consumers. |
| May 23, 2026 | Electrica Furnizare warned about a separate phishing campaign impersonating the supplier. |
What remains unknown
The public disclosures do not establish:
- the initial access route or exploited vulnerability;
- how long attackers had access;
- the number and type of encrypted systems;
- whether data was stolen or published;
- the ransom demand or payment status;
- a complete restoration timeline; or
- any connection to wider Romanian cyber activity.
Those gaps make it inappropriate to claim that no data was stolen, that the incident was fully resolved by a particular date, or that the attack caused a physical electricity outage.
Best Value
Why the incident matters
The attack demonstrates why a utility’s cyber resilience cannot be measured only by whether customers’ lights stayed on. Energy companies depend on interconnected business systems for billing, customer support, identity management, field operations and communications. At the same time, their operational technology must be protected and, where necessary, isolated without compromising safe network operation.
Electrica’s sustainability and directors’ reporting describes measures including incident detection and response, encryption, continuous monitoring and broader cybersecurity strengthening. Those measures do not prove that any particular control caused or prevented the 2024 incident, but they show why ransomware affecting enterprise IT can still become a material operational and financial risk for a distributor.
The bottom line for customers
Electrica Group was hit by a ransomware attack in December 2024, and its later reporting identified LYNX as the ransomware operation. The affected business was primarily DEER’s information environment. Customer-facing services were disrupted, but the official account said the electricity network and operational SCADA systems remained functional. There is no confirmed public evidence in the supplied record that customer data was stolen or that electricity supply was cut nationwide.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




