Skip to content

PES Energize cyber incident

Summary

PES Energize logo

PES Energize, the municipal electric and broadband utility in Pulaski, Tennessee, reported a cybersecurity incident Dec. 5, 2025, that disabled office phones and computers. The utility closed its customer lobby, suspended in-person and phone payments, and directed outage reports to alternate channels; power and broadband delivery were not reported disrupted.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that PES Energize experienced a disruptive cyber incident in December 2025. Our Dec. 5 report recounts the utility’s public statements that a cybersecurity incident disabled phones and computer systems and caused a precautionary shutdown of some systems. The utility worked with federal agencies and outside cyber partners.

Operational significance

The customer lobby closed and staff could not take payments in person or by phone. Customers were directed to alternate numbers and channels for outage reports and payments. The reviewed statements do not establish interruption of electric or broadband delivery.

Current status

The initial statements did not give a restoration date. Current utility contact and payment pages again list normal channels, but the reviewed sources do not establish precisely when full operations returned. This retrospective record is presumed resolved without claiming a verified all-clear.

Confidence and uncertainty

The victim’s public notices support the cyber-incident assessment and internal-service disruption. Attack mechanism, unauthorized-access confirmation, data exposure and actor identity remain unestablished. The utility said at the time that it had no indication customer data was compromised; that was a preliminary assessment.

Analytic gaps

Initial access, actor, data outcome and final restoration date remain unresolved.

Organizations involved

Impacted locations

  • Pulaski, Tennessee

    Pulaski is the utility's municipal core; the separate HIFLD electric-service territory is also mapped. Neither the city nor the broader territory establishes an electric or broadband delivery outage.

    Pulaski office and closed customer lobby are the physical anchors.

Sources

Cyber incident knocks out PES Energize phones in Pulaski, Tenn.

We reported utility notices that a cyber incident disabled PES Energize phones and office computers, closed its customer lobby, and forced alternate payment and outage-reporting channels.

A brief overview of the main incidents in industrial cybersecurity, Q4 2025

The Q4 2025 incident table lists PES Energize, a U.S. electricity provider, under denial of IT systems and services. It does not identify ransomware, data theft or disrupted electric delivery for this case.

See something that needs correction?

Signed-in members can report an error, update, or missing source.