PES Energize

PES Energize, the municipal electric and broadband utility in Pulaski, Tennessee, reported a cybersecurity incident Dec. 5, 2025, that disabled office phones and computers. The utility closed its customer lobby, suspended in-person and phone payments, and directed outage reports to alternate channels; power and broadband delivery were not reported disrupted.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that PES Energize experienced a disruptive cyber incident in December 2025. Our Dec. 5 report recounts the utility’s public statements that a cybersecurity incident disabled phones and computer systems and caused a precautionary shutdown of some systems. The utility worked with federal agencies and outside cyber partners.
The customer lobby closed and staff could not take payments in person or by phone. Customers were directed to alternate numbers and channels for outage reports and payments. The reviewed statements do not establish interruption of electric or broadband delivery.
The initial statements did not give a restoration date. Current utility contact and payment pages again list normal channels, but the reviewed sources do not establish precisely when full operations returned. This retrospective record is presumed resolved without claiming a verified all-clear.
The victim’s public notices support the cyber-incident assessment and internal-service disruption. Attack mechanism, unauthorized-access confirmation, data exposure and actor identity remain unestablished. The utility said at the time that it had no indication customer data was compromised; that was a preliminary assessment.
Initial access, actor, data outcome and final restoration date remain unresolved.

Affected utility's electric-service remit. Cyber incident disrupted customer office phones, computers and payments; no electric or broadband delivery interruption was reported.
Pulaski is the utility's municipal core; the separate HIFLD electric-service territory is also mapped. Neither the city nor the broader territory establishes an electric or broadband delivery outage.
Pulaski office and closed customer lobby are the physical anchors.
We reported utility notices that a cyber incident disabled PES Energize phones and office computers, closed its customer lobby, and forced alternate payment and outage-reporting channels.
The Q4 2025 incident table lists PES Energize, a U.S. electricity provider, under denial of IT systems and services. It does not identify ransomware, data theft or disrupted electric delivery for this case.
Signed-in members can report an error, update, or missing source.