Mining’s Digital Shift Expands Cyber Risk Beyond IT
By Diego Valverde | Journalist & Industry Analyst -
Wed, 09/02/2026 - 10:40
Mining cybersecurity is becoming an operational resilience issue as IT-OT convergence, third-party access, AI adoption, geopolitical competition, and tighter regulation expose production systems to risks that extend beyond traditional data breaches.
The mining sector has long measured risk in geological terms. Unstable ground, water ingress, and seismic events exemplify this scenario. But today the most disruptive threats arrive through fiber optic cables and satellite links, targeting the digital systems that keep modern mines running.
Between 2023 and 2024, cyberattacks against the global mining and metals industry tripled, according to the Mining and Metals Information Sharing and Analysis Centre (MM-ISAC). The organization documented 30 reported incidents in 2024, up from 10 the prior year. "And those are just the ones we know about," says Rob Labbe, CEO and CISO in Residence, MM-ISAC. "There is a massive under-reporting in cyber incidents."
The financial toll of these attacks is significant. Cyber-enabled fraud in the mining sector has exceeded US$4 billion globally in recent years, while in the general landscape IBM reports that the average cost of a single data breach reached US$4.99 million in 2025, a 10% year-over-year increase.
For mining companies, however, the calculus extends beyond. Operational disruptions like halted mills, disabled ventilation systems, or frozen logistics significantly worsen the impact of these incidents.
Mining Key Operational Risks and Threats
The convergence between information technology and operational technology (IT-OT) is where mining's vulnerability becomes most acute. Legacy machinery retrofitted with internet-connected sensors, control systems running on outdated software, and human-machine interfaces that were never designed for a connected world have created an attack surface that expands with every digital upgrade.
"If you are a mining company, and cybercriminals disable your mill, every second it is stopped costs about US$5.97. Multiply that by 3,600 for an hour, and the financial impact can accumulate, even for days," says David Tintor, Director of Operations, TBSEK, to MBN. "They make it clear: Pay US$1 million or suffer damage worth US$10 million."
The consequences extend beyond financial loss. An attacker who compromises a mine's ventilation system creates a direct risk of injury and death. Shutdowns triggered to contain a cyber threat can themselves cause operational technology systems to malfunction, potentially harming workers on the ground. Full recovery from a significant breach takes more than 100 days on average, according to A&O Shearman analysis.
The ransomware wave hit the sector relentlessly through 2024. Alamos Gold in Canada fell victim to BlackBasta ransomware. South Africa's Sibanye-Stillwater was targeted by RansomHouse. Australia's Evolution Mining reported an attack on its IT systems. In each case, the pattern repeated: encryption, extortion, operational disruption.
Then, in May 2026, the Scope Systems ransomware attack struck, described by Labbe as the "broadest-reaching cyber event the mining industry has ever experienced in terms of the number of companies impacted by a single third-party breach." The attack against the Australian ERP software provider cascaded across its mining clients, demonstrating how a single compromised supplier can paralyze an entire value chain.
Third-Party Vulnerabilities
Supply chain vulnerability has become another mining pressing cybersecurity challenge. Cybersecurity company Claroty surveyed 1,100 information security, OT engineering, clinical and biomedical engineering, facilities management, and plant operations specialists globally, asking about cyberattacks on their organizations.
Claroty research found that 76% of respondents identified third-party supplier access to their cyber-physical systems environment as a source of cyberattacks, with 41% reporting five or more attacks originating from such access in a 12-month period.
The issue runs deeper than conventional IT vendor management. Mining operations depend on original equipment manufacturers, cloud-based ERP systems, fuel and chemical delivery logistics, and remote monitoring services, all connected through a web of digital access points that attackers can exploit.
"Your definition of what is critical to maintain production maybe has to expand," Labbe says. "In the case of mining, an ERP is accounting and numbers, but it is also how a gold mine gets cyanide to run its process, how diesel gets delivered for trucks."
Nearly half of organizations surveyed by Claroty reported that five or more attacks in the previous 12 months originated from a third-party supplier's access to their environment, typically through insecure internet connections or poorly configured VPNs.
Of 125,000 operational technology assets analyzed, 13% were insecurely connected to the internet. More than 36% of engineering workstations and human-machine interfaces with insecure connections also contained at least one confirmed known exploited vulnerability.
“As most organisations now recognise, the question is not if a cyber event will occur, it is when," says Jeff Pick, Director of Cybersecurity Architecture and Operations, Freeport-McMoRan. "In many cases, threat actors thrive on the complexity in architecture that has developed over time."
Geopolitics and Industrial Cyberespionage
The geopolitical dimension transforms mining cybersecurity from a corporate risk management exercise into a matter of national strategic interest. Access to raw materials like rare earths, lithium, cobalt, or copper, is increasingly central to geostrategic competition, and disrupting supply chains has become a tool in the struggle for technological and military advantage.
The International Energy Agency projects that meeting the goals of the Paris Agreement will trigger demand increases of 40% for copper and rare earths, 60%%–70% for nickel and cobalt, and 90% for lithium over the next two decades.
State-sponsored threat actors recognize that mining companies hold geological data, extraction methodologies, and strategic reserve information worth far more than any ransom payment. In June 2024, the BianLian cybercriminal group claimed responsibility for an attack on Northern Minerals, an Australian rare earth exploration company. The breach occurred just hours after the Australian government ordered China-affiliated investors to divest their stake in the company, citing national interest concerns.
In February 2024, US authorities reported that Volt Typhoon, a Chinese state-sponsored cyber actor, had sought "to pre-position themselves on IT networks for disruptive or destructive cyberattacks against US critical infrastructure in the event of a major crisis or conflict with the United States."
The Impact of AI and ESG Requirements
AI is reshaping both sides of the mining cybersecurity equation. AI-powered security tools can analyze vast datasets to identify vulnerabilities, detect anomalous behavior across operational technology networks, and respond to threats in real time. Behavioral analytics platforms now monitor normal patterns of interaction with mine control systems and flag deviations that could indicate compromise.
At the same time, threat actors have embraced AI with equal enthusiasm. "AI is making life way easier for cybercriminals," warns Labbe, noting that generative AI tools enable attackers to craft highly personalized phishing campaigns, impersonate executives, and inject false data into decision-making systems.
Pick identifies a particularly insidious risk. "The use of AI is starting to yield real dividends. This brings with it potential risks, as the models in use become part of our proprietary information or trade secrets that contribute to our competitive advantage. Risks to manage include data poisoning or exfiltration to competitors," he says.
The ESG dimension adds another layer of urgency. Only 38% of mining companies claim to be fully compliant with cybersecurity regulations, according to industry analysis. As environmental, social, and governance frameworks mature, cybersecurity is emerging as a prerequisite for investment rather than an operational afterthought.
Falsified ESG metrics, whether from internal manipulation or external compromise, represent a growing form of fraud. Regulators now inspect these metrics more rigorously, and manipulated data can result in inaccurate reporting on tailing dams, ventilation systems, or toxic exposure levels, posing severe threats to worker safety and environmental integrity.
The regulatory environment is tightening across major mining jurisdictions. The European Union's NIS2 Directive requires boards and CEOs to possess the knowledge and skills to assess cybersecurity risks. Australia's Cyber Security Act 2024 introduces mandatory ransomware reporting obligations. In the United States, the SEC's cyber-disclosure rule and CIRCIA have significantly expanded board-level cybersecurity responsibilities.








