Company Details
edp
13,818
447,314
22
http://www.edp.com
35
EDP_3158362
Completed

EDP Company CyberSecurity Posture
http://www.edp.comOur story began more than 40 years ago. Today we are a global company, among the largest players in the energy sector in Europe and the 4th largest producer of wind energy. We are proud to be a leading utility integrated in the Dow Jones Sustainability Indexes (World). We want to build a new energy by promoting renewable sources. To do this, we have chosen ... ... to be 100% green by 2030; ... to be Net Zero by 2040; ... to innovate, to shape the energy sector; ... empower our communities to live more sustainably. Ours is the energy that strives to create a better future, inspired by people from four regional hubs. It is the energy that knows no borders, that never sleeps, and that connects us to you. We will harness wind, sun and water to lead the energy transition. We will all be green. We choose the Earth. Welcome to the official EDP Group LinkedIn page.
Company Details
edp
13,818
447,314
22
http://www.edp.com
35
EDP_3158362
Completed
Between 750 and 799

EDP Global Score (TPRM)XXXX

Description: Portuguese multinational energy giant Energias de Portugal (EDP) was targeted by the Ragnar Locker ransomware group after they encrypted the systems. The attackers asked for a 1580 BTC ransom ($10.9M or €9.9M). EDP Group is one of the largest European operators in the energy sector (gas and electricity) and the world’s 4th largest producer of wind energy.


No incidents recorded for EDP in 2025.
No incidents recorded for EDP in 2025.
No incidents recorded for EDP in 2025.
EDP cyber incidents detection timeline including parent company and subsidiaries

Our story began more than 40 years ago. Today we are a global company, among the largest players in the energy sector in Europe and the 4th largest producer of wind energy. We are proud to be a leading utility integrated in the Dow Jones Sustainability Indexes (World). We want to build a new energy by promoting renewable sources. To do this, we have chosen ... ... to be 100% green by 2030; ... to be Net Zero by 2040; ... to innovate, to shape the energy sector; ... empower our communities to live more sustainably. Ours is the energy that strives to create a better future, inspired by people from four regional hubs. It is the energy that knows no borders, that never sleeps, and that connects us to you. We will harness wind, sun and water to lead the energy transition. We will all be green. We choose the Earth. Welcome to the official EDP Group LinkedIn page.


Somos uma companhia de capital aberto com ações (NEOE3) negociadas na Bolsa de Valores de São Paulo. Parte do grupo espanhol Iberdrola, atuamos no Brasil desde 1997, e atualmente, somos uma das líderes do setor elétrico do país. Estamos presentes em 18 estados e no Distrito Federal, com negócios em
NTPC Limited is India’s largest power generation utility with roots planted way back in 1975 to accelerate power development in India. Since then it has established itself as the dominant power major with a presence in the entire value chain of the power generation business. From fossil fuels, it ha

Westinghouse Electric Company is the world's leading supplier of safe and innovative nuclear technology. We provide our utility customers around the world with the most reliable, dependable nuclear power plants, nuclear fuel, plant automation and operating plant products and services. We are driven

The Government of West Bengal has restructured the erstwhile WBSEB into two successor entities, namely West Bengal State Electricity Distribution Company Limited (WBSEDCL) and West Bengal State Electricity Transmission Company Limited (WBSETCL), under the ownership of the State Government. The two C

Our team at American Electric Power is committed to improving our customers' lives with reliable, affordable power. We are investing $54 billion from 2025 through 2029 to enhance service for customers and support the growing energy needs of our communities. Our nearly 16,000 employees operate and ma

Grupo Cobra es una compañía global de 80 años de experiencia en el sector de la ingeniería industrial aplicada y servicios especializados. Contamos con un equipo de 18.700 personas especializadas en todos los campos relacionados con la ingeniería, instalación y mantenimiento industrial de infraestru

Joint stock company Elektroprivreda Srbije as the largest company in Serbia represents economic and energy backbone of the country. The main activities of EPS AD are the production, supply and trade of electricity. EPS is owner a the coal mines, thermopower plant and hydropower plant. EPS supplies e
We are a multinational company changing the face of energy, one of the world’s leading integrated utilities. As the largest private player in producing clean energy with renewable sources we have more than 88 GW of total capacity, including around 64 GW of renewables. Distributing electricity t
Together with our subsidiaries, we deliver clean, safe, reliable and affordable energy to our 9 million customers. Our focus is doing so with service excellence. That means we are leaders who take action to meet our customers’ and communities’ needs while advancing our commitment to net zero emiss
.png)
Sahaja Reddy Udumala, a 24-year-old cyber security professional from Telangana, tragically lost her life in a fire accident in the United...
When the Syrian civil war erupted in 2011, hundreds of thousands of Syrians, including many Kurdish families and other ethnoreligious...
Cyber security firm QuicHeal's enterprise arm Seqrite has detected over 265 million attacks across 8 million endpoints or installed bases of...
Rockwell Automation, the global leader in industrial automation and digital transformation, has announced the launch of its SecureOT...
In a strategic move, markets regulator Sebi has announced a partnership with the National Forensic Sciences University (NFSU) to upgrade its...
The study reviews how AI can strengthen cybersecurity and sustainability in Industry 4.0, highlighting its power to detect and predict...
Portugal's first heat-as-a-service agreement combines a 7 MW solar plant and a 100 MWh thermal battery to provide continuous, zero-emission...
The Better Business Bureau (BBB) has created an online resource full of tips and resources to strengthen cybersecurity knowledge.
Legal uncertainty adds another layer of complexity. Current laws focus on breaches of cybersecurity or personal data.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of EDP is http://www.edp.com.
According to Rankiteo, EDP’s AI-generated cybersecurity score is 775, reflecting their Fair security posture.
According to Rankiteo, EDP currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, EDP is not certified under SOC 2 Type 1.
According to Rankiteo, EDP does not hold a SOC 2 Type 2 certification.
According to Rankiteo, EDP is not listed as GDPR compliant.
According to Rankiteo, EDP does not currently maintain PCI DSS compliance.
According to Rankiteo, EDP is not compliant with HIPAA regulations.
According to Rankiteo,EDP is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
EDP operates primarily in the Utilities industry.
EDP employs approximately 13,818 people worldwide.
EDP presently has no subsidiaries across any sectors.
EDP’s official LinkedIn profile has approximately 447,314 followers.
EDP is classified under the NAICS code 22, which corresponds to Utilities.
Yes, EDP has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/edp-llc.
Yes, EDP maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/edp.
As of December 19, 2025, Rankiteo reports that EDP has experienced 1 cybersecurity incidents.
EDP has an estimated 4,199 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Title: Ragnar Locker Ransomware Attack on EDP
Description: Portuguese multinational energy giant Energias de Portugal (EDP) was targeted by the Ragnar Locker ransomware group after they encrypted the systems. The attackers asked for a 1580 BTC ransom ($10.9M or €9.9M).
Type: Ransomware
Attack Vector: Ransomware
Threat Actor: Ragnar Locker
Motivation: Financial Gain
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Systems Affected: Encrypted systems

Entity Name: Energias de Portugal (EDP)
Entity Type: Company
Industry: Energy
Location: Portugal
Size: Large

Ransom Demanded: 1580 BTC ($10.9M or €9.9M)
Ransomware Strain: Ragnar Locker
Data Encryption: Yes
Last Ransom Demanded: The amount of the last ransom demanded was 1580 BTC ($10.9M or €9.9M).
Last Attacking Group: The attacking group in the last incident was an Ragnar Locker.
Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was 1580 BTC ($10.9M or €9.9M).
.png)
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.