Skip to main content

Texas Today

Texas Energy Industry Gets New Cybersecurity Warning

Texas Energy Industry Gets New Cybersecurity Warning
Photo Credit: Unsplash.com

The Railroad Commission of Texas has urged oil and gas producers, pipeline operators and other energy companies to strengthen cybersecurity defenses after recent incidents involving energy vessels and federal warnings about attacks targeting connected operational technology. The warning puts cybersecurity risks affecting Texas energy infrastructure in sharper focus.

Key Takeaways

  • Railroad Commission Commissioner Wayne Christian called on Texas energy companies to strengthen cybersecurity defenses.
  • The warning followed incidents involving foreign-flagged energy vessels bound for the United States.
  • The 1,093-foot VL Prosperity was bound for Galveston and could carry roughly 2.3 million barrels of crude oil.
  • Federal officials have not publicly attributed the vessel-related cyber incidents to a specific country or group.
  • The RRC has previously warned regulated operators that cyberattacks could disrupt operations and cause financial losses across critical infrastructure.

Railroad Commission Issues Cybersecurity Warning to Energy Operators

Texas energy cybersecurity concerns prompted Railroad Commission Commissioner Wayne Christian to call on oil and gas producers, pipeline operators and other energy companies to strengthen their defenses against cyberattacks.

The RRC issued the warning on September 24, citing recent cyber incidents involving Texas-bound energy tankers and federal warnings about malicious actors targeting internet-connected operational technology and industrial control systems.

The warning applies to energy companies operating systems that can connect digital networks with physical infrastructure. Operational technology can be used to monitor or control industrial equipment, making cybersecurity a concern for facilities involved in energy production and transportation.

Christian called on operators to invest in cybersecurity measures, test their defenses and monitor their systems. He also urged companies to strengthen protections before vulnerabilities can be exploited.

The RRC regulates Texas oil and gas operations as well as intrastate pipeline safety. Its cybersecurity warning therefore addresses companies operating within industries under the agency’s regulatory jurisdiction.

The commission’s notice does not establish that Texas energy infrastructure itself has been successfully breached. Instead, the agency cited recent vessel incidents and federal warnings as reasons for energy operators to review and strengthen their defenses.

The RRC also warned that successful cyberattacks can cause operational disruptions and financial losses across critical infrastructure.

Recent Vessel Incidents Raise Operational Technology Concerns

The RRC’s warning followed incidents involving two foreign-flagged energy vessels bound for the United States. The Coast Guard and FBI boarded the vessels in August after indications that foreign cyber actors had compromised their networks.

One of the vessels, the 1,093-foot VL Prosperity, was a Liberian-flagged crude oil tanker bound for Galveston.

The tanker was capable of carrying roughly 2.3 million barrels of oil, according to the RRC. Its planned destination gave the incident a direct connection to Texas energy infrastructure.

Federal officials have not publicly attributed the attacks to a specific country or group. The RRC therefore did not identify a confirmed perpetrator for the vessel-related incidents.

The cases nevertheless formed part of the factual basis for Christian’s warning to Texas energy operators. The commission pointed to the incidents alongside federal warnings concerning attacks against internet-connected operational technology and industrial control systems.

Texas also relies on extensive pipeline and export systems to move energy to domestic and international markets. That broader network includes natural gas export infrastructure connecting producing regions with cross-border markets.

Operational technology differs from conventional information technology because it can interact directly with industrial equipment and physical processes. A disruption involving such systems can therefore affect the operation of infrastructure rather than only the availability of digital information.

For Texas energy companies, those systems can be connected to facilities and processes used across oil, gas and pipeline operations. The RRC’s warning specifically calls on operators to account for cyber risks affecting those connected systems.

Texas Energy Infrastructure Faces Connected-System Risks

Federal warnings cited by the RRC include concerns about cyber actors targeting U.S. critical infrastructure through internet-connected operational technology and industrial control systems.

The commission identified energy infrastructure as part of that critical-infrastructure environment. Its September 24 warning specifically addressed Texas oil and gas producers, pipeline operators and other energy companies.

The RRC said cyberattacks against critical infrastructure can produce operational disruptions and financial losses. Those effects can occur when a cyber incident interferes with systems needed to operate or monitor physical infrastructure.

The commission had already issued a notice to regulated operators earlier in 2026 warning about cyber risks. The latest statement renews that message following the vessel incidents and federal warnings.

The RRC also referenced federal warnings concerning China-linked and Iran-affiliated cyber actors targeting U.S. critical infrastructure. Those references describe federal warnings rather than a finding that either country was responsible for the specific vessel incidents cited by the commission.

State lawmakers have separately examined foreign-linked energy technology used on the Texas power grid, including potential vulnerabilities involving imported equipment and connected systems.

That distinction is important because federal officials have not publicly attributed the attacks involving the vessels to a specific country or group.

The commission’s warning instead focuses on preparedness. Operators were urged to strengthen cyber resilience and take steps to protect systems that connect digital networks with energy infrastructure.

RRC Urges Companies to Strengthen Cybersecurity Defenses

Christian urged energy companies to invest in cybersecurity protections, test their defenses and monitor their systems. The RRC’s statement places those measures within the responsibilities of companies operating energy infrastructure in Texas.

Testing can help operators examine whether existing defenses can withstand attempted intrusions. Monitoring can help identify unusual activity affecting connected systems. The RRC did not announce a new cybersecurity regulation as part of the September 24 warning.

The commission’s message instead calls on operators to strengthen existing defenses in response to identified cyber risks.

The agency also referred to artificial intelligence in its warning. Christian said cyber actors could seek to use AI against critical infrastructure and argued that AI should also be used as a defensive tool.

The statement did not announce a specific AI security system or requirement for Texas energy operators. The reference was part of Christian’s broader call for companies to prepare for cyber threats affecting energy infrastructure.

The RRC’s earlier notice to regulated operators also identified potential operational disruptions and financial losses as consequences of successful cyberattacks.

For energy companies, those consequences can extend beyond information systems when connected technology is involved in physical industrial operations. The September 24 warning therefore directs attention to cybersecurity measures covering both digital systems and the operational technology connected to energy facilities.

Cybersecurity Measures Remain Relevant to Texas Energy Operations

The RRC’s warning places cybersecurity among the operational concerns facing Texas oil and gas producers, pipeline operators and other energy companies regulated by the agency.

The immediate trigger cited by the commission was the combination of recent cyber incidents involving Texas-bound energy vessels and federal warnings about attacks targeting connected operational technology and industrial control systems.

The VL Prosperity incident provided a direct Texas connection because the crude oil tanker was bound for Galveston and had capacity for roughly 2.3 million barrels of oil.

The federal government has not publicly identified a specific country or group as responsible for the vessel-related cyber incidents. The RRC’s warning therefore focuses on defensive measures rather than assigning responsibility for the attacks.

The commission has also warned that successful cyberattacks can create operational disruptions and financial losses across critical infrastructure. That warning applies to the potential effects of successful attacks rather than reporting a new disruption to Texas energy operations.

Christian’s September 24 statement calls on energy operators to invest in cybersecurity, test their defenses and monitor their systems. Those measures are directed at strengthening the resilience of infrastructure connected to the state’s oil, gas and pipeline industries.

Frequently Asked Questions

What cybersecurity warning did the Railroad Commission of Texas issue?

The Railroad Commission urged Texas oil and gas producers, pipeline operators and other energy companies to strengthen cybersecurity defenses. The warning followed recent incidents involving Texas-bound energy vessels and federal warnings about attacks targeting operational technology and industrial control systems.

Which Texas energy companies are affected by the RRC warning?

The warning is directed at Texas oil and gas producers, pipeline operators and other energy companies. These businesses operate within industries covered by the Railroad Commission’s regulatory responsibilities.

What cybersecurity risks did the RRC identify?

The RRC cited threats to internet-connected operational technology and industrial control systems. The commission said successful cyberattacks could cause operational disruptions and financial losses across critical infrastructure.

What happened to the energy vessels referenced by the RRC?

The Coast Guard and FBI boarded two foreign-flagged energy vessels bound for the United States in August after indications that foreign cyber actors had compromised their networks. One vessel, the VL Prosperity, was bound for Galveston and could carry roughly 2.3 million barrels of crude oil.

Why is operational technology important to Texas energy infrastructure?

Operational technology can connect digital systems with physical industrial equipment and processes. Cyber incidents affecting those systems can therefore interfere with the operation or monitoring of energy infrastructure.

Texas Today

Deep in the heart of the Lone Star State, with the spirit that makes us proud.