Itron Inc. disclosed on April 27, 2026 that an unauthorized third party had accessed certain of its corporate IT systems, discovered on April 13. The Spokane-based company — which manufactures smart meters, distribution automation sensors, and grid-analytics platforms deployed by more than 8,000 utilities serving electricity, gas, and water customers across 100 countries — filed a Form 8-K with the SEC and activated its incident-response plan. Itron said it found no unauthorized activity in the customer-hosted portion of its systems, did not identify evidence of customer data exposure, and determined the incident was not reasonably likely to have a material impact on the company. Insurance is expected to cover a significant portion of direct costs. No threat actor has claimed responsibility and no malware family has been identified publicly.
The disclosure is notable less for what was confirmed than for what was not. Itron’s products sit at the boundary between utility IT and OT: advanced metering infrastructure (AMI) deployments connect smart meters directly to head-end software, which in turn feeds distribution management and outage management systems. A compromise that reached from Itron’s corporate environment into its product-engineering or firmware-management systems would carry a direct path toward the field devices of thousands of utilities. The company’s statement that customer-hosted systems were unaffected is the key containment claim, but the investigation was ongoing at the time of disclosure and Itron declined to specify which internal systems were accessed or how long the intruder had access before detection on April 13.
The structural precedent is Halliburton’s RansomHub breach in August 2024, where an energy-services supplier’s corporate IT compromise caused operational disruption at customer sites and required Halliburton to disconnect systems. The MKS Instruments ransomware incident in 2023 is a closer analogue for supply-chain propagation risk: a semiconductor process-equipment vendor’s manufacturing and service-delivery systems were encrypted, causing multi-week production stoppages at major chipmakers that used MKS equipment. Itron’s declared scope — corporate IT only, no customer-hosted systems — would place this incident below that threshold if the investigation holds. Utility operators running Itron head-end software in on-premises or co-managed deployments should confirm with Itron that their specific environments were within the scope of the “customer-hosted” exclusion.