Key Takeaways
- Reported mining and metals cyber incidents rose from 10 in 2023 to 30 in 2024, with under-reporting likely obscuring the full scale.
- The May 2026 Scope Systems ransomware attack showed how one compromised supplier can disrupt multiple mining operators.
- Connected operational technology, AI systems and third-party access are turning cybersecurity into a production, safety and board-level issue.
Cybersecurity in mining is no longer confined to stolen credentials or inaccessible office files. As mines connect processing plants, autonomous equipment, remote operations centers and logistics systems, a breach can interfere with the physical processes that keep workers safe and ore moving.
Reported cyberattacks against the global mining and metals industry tripled between 2023 and 2024, according to the Mining and Metals Information Sharing and Analysis Centre, or MM-ISAC. It documented 30 incidents in 2024, compared with 10 the previous year.
“And those are just the ones we know about,” said the CEO and CISO in Residence at MM-ISAC. “There is a massive under-reporting in cyber incidents.”
The trend has continued to evolve as operations become more connected, a risk also highlighted by MiningWeekly in its coverage of emerging mining cyberthreats. Cyber-enabled fraud across the sector has increased globally in recent years, though specific financial metrics were not disclosed. IBM, meanwhile, reported that the average cost of a data breach across industries continued to rise in 2025.
For miners, those figures capture only part of the exposure. A cyber incident can halt a mill, freeze shipments or interrupt the delivery of diesel and processing chemicals. It can also affect ventilation, environmental monitoring and other systems tied to worker safety.
Operational technology was often built for reliability and long service life, not routine exposure to enterprise networks or the internet. Retrofitted sensors, outdated control software and remotely accessible human-machine interfaces have expanded the attack surface. Australian Mining Review has identified securing OT as an increasingly important issue for operators managing connected industrial environments.
Team82’s 2025 State of CPS Security report found that 40% of organizations had OT assets insecurely exposed to the internet, while 12% contained known exploited vulnerabilities. Mining was specifically highlighted among sectors where OT devices were communicating with malicious domains. Fortinet’s 2024 OT cybersecurity report found that 78% of organizations experienced intrusions affecting OT or converged IT-OT environments, with 49% of incidents affecting both (source).
The ransomware pattern has already touched major operators. Alamos Gold was hit by BlackBasta, Sibanye-Stillwater was targeted by RansomHouse, and Evolution Mining reported an attack on its IT systems during 2024. According to A&O Shearman analysis, recovery from a significant breach takes more than 100 days on average.
Then came Scope Systems. Its May 2026 ransomware attack spread across customers of the Australian ERP software provider. The MM-ISAC CEO described it as the “broadest-reaching cyber event the mining industry has ever experienced in terms of the number of companies impacted by a single third-party breach.”
That incident challenged a common distinction between administrative and production systems. An ERP platform may handle accounting, but it can also coordinate cyanide purchases for gold processing or diesel deliveries for haul trucks. If that platform fails, how long can production continue?
Third-party access is particularly difficult to control. Claroty research involving 1,100 specialists found that 82% viewed supplier access to cyber-physical systems as a source of attacks (source). Affected organizations reported at least five attacks originating from such access within a 12-month period. Among 125,000 OT assets analyzed, 13% were insecurely connected to the internet.
AI adds another layer. Defensive systems can use behavioral analytics to detect unusual commands or traffic across mine networks. Attackers can use the same technology for targeted phishing, executive impersonation and manipulation of operational data. AI models may themselves contain proprietary geological or process information vulnerable to poisoning or theft.
Regulation is catching up. MiningDoc frames cybersecurity as integral to modern mining operations, reflecting a broader shift toward operational resilience. The EU’s NIS2 Directive covers mining and metals as critical infrastructure, Australia’s Cyber Security Act 2024 introduced mandatory ransomware reporting, and US disclosure requirements have expanded board oversight.
According to industry data, only 38% of mining companies claim full compliance with cybersecurity regulations. Closing that gap will involve more than buying another security product. Operators increasingly need accurate OT inventories, segmented networks, tightly governed supplier access and recovery exercises built around physical production. In a connected mine, cybersecurity has become part of the safety case as well as the business case.
⬇️