Cyber-Protecting Your Power: Why Modern Networked UPS Systems are the New Target for Hackers (and How to Lock Them Down)
Share
Here's something most IT teams don't lose sleep over: their UPS getting hacked. But here's the wake-up call, modern networked UPS systems have quietly become one of the most attractive targets for cybercriminals. We're not talking about someone unplugging your backup power. We're talking about remote exploitation, firmware tampering, and the potential for catastrophic physical damage to your entire infrastructure.
If you're running a data center, managing critical IT infrastructure, or procuring power protection equipment, this isn't fear-mongering. It's the new reality of interconnected systems where even your backup power needs a security strategy.
Why Your UPS Became a Cyber Target
The shift from standalone power protection to cloud-connected, network-managed UPS systems brought incredible benefits, remote monitoring, predictive analytics, centralized management across multiple sites. But it also introduced something else: remote attack vectors.
Modern UPS devices, particularly the latest APC Smart-UPS models deployed across approximately 20 million locations worldwide, are now controlled through cloud connections. That convenience creates a pathway for attackers to exploit vulnerabilities remotely via the internet, often without any user interaction or visible signs of an attack.

Here's why these devices have become prime targets:
-
Critical infrastructure, minimal security oversight: UPS systems protect data centers, hospitals, industrial facilities, and energy suppliers, yet they're frequently overlooked in security strategies and remain "unseen" by traditional security solutions.
-
Always-on, always-connected: Unlike servers that might be patched and rebooted regularly, UPS devices often operate for years without significant updates or security reviews. Organizations install them and essentially forget about them.
-
Single point of failure: Compromise a UPS, and you potentially control power to entire racks of servers, networking equipment, or industrial control systems. It's high-impact with relatively low effort for attackers.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued specific warnings about threat actors exploiting unchanged default credentials on internet-connected UPS devices. When was the last time you changed the admin password on your UPS management interface? If you're like most organizations, the answer is "never."
The TLStorm Wake-Up Call
In 2022, security researchers discovered a series of vulnerabilities collectively dubbed "TLStorm" in widely-deployed APC Smart-UPS devices. These weren't minor bugs, they represented fundamental design flaws that highlight systemic issues across the power protection industry.
The vulnerabilities included:
- Two TLS implementation flaws (CVE-2022-22806 and CVE-2022-22805) that could be triggered via unauthenticated network packets
- Unsigned firmware updates allowing attackers to install malicious firmware without cryptographic verification
- Remote code execution capabilities enabling complete device takeover
The unsigned firmware vulnerability is particularly dangerous. Attackers can craft malicious updates deployable over the internet, local networks, or even USB drives. Once installed, this malicious firmware establishes long-lasting persistence within your network infrastructure, surviving reboots, network reconfigurations, and even traditional security scans.

Think about that for a moment. An attacker could compromise your UPS, install persistent malware, and maintain a foothold in your network that survives virtually every remediation effort you throw at it.
Real-World Attack Scenarios (And They're Not Hypothetical)
What can an attacker actually do once they've compromised your UPS? Unfortunately, plenty.
Physical Destruction: Malicious firmware could manipulate the UPS's CPU responsible for DC-to-AC conversion, causing internal circuitry to overheat and physically destroy the device. Imagine walking into your data center to find your UPS literally smoking, and taking down every connected system with it.
Operational Sabotage: Attackers can alter UPS operations to destabilize power output, potentially damaging connected equipment or triggering unexpected shutdowns during critical operations. For industries where uptime costs $7,900 per minute (per Gartner research), even brief disruptions translate to massive financial losses.
Infrastructure Leverage: The 2015 Ukraine Power Grid attack provides historical precedent. Attackers compromised UPS devices and other infrastructure components to trigger widespread power outages affecting hundreds of thousands of people. That attack demonstrated that UPS exploitation isn't theoretical, it's a proven tactic in sophisticated infrastructure attacks.
Lateral Movement: Since UPS devices connect to the same internal networks as core business systems, a compromised UPS becomes a launching point for broader network infiltration. It's essentially a persistent backdoor that security teams rarely monitor.
How to Lock Down Your Networked UPS
The good news? You don't need to disconnect all your UPS devices from the network and go back to the stone age. But you do need to treat them as critical security assets rather than "set and forget" infrastructure.
Immediate Actions
Change those default credentials. Yes, all of them. Every UPS, every management interface, every cloud portal. Use strong, unique passwords and document them securely. This single step blocks a huge percentage of opportunistic attacks.
Audit your internet exposure. Do your UPS management interfaces really need to be accessible from the public internet? For most organizations, the answer is no. Restrict access through VPNs, implement IP whitelisting, or eliminate internet exposure entirely for devices that don't require it.
Apply security patches proactively. Don't wait for automatic cloud-based updates. Download and apply patches independently, scheduling necessary downtime during maintenance windows. Check your vendor's security advisories monthly: not quarterly or annually.

Strategic Security Controls
Implement comprehensive asset visibility. You can't protect what you can't see. Deploy monitoring solutions that provide complete visibility of all UPS assets across your infrastructure. Traditional security tools often don't cover these devices, so you may need specialized solutions or custom monitoring configurations.
Establish network segmentation. Place UPS devices on isolated network segments with strict access controls. If a UPS gets compromised, segmentation limits an attacker's ability to move laterally to more valuable targets.
Deploy behavioral monitoring. Modern UPS devices should behave predictably. Implement monitoring that can identify anomalies: unexpected network connections, unusual configuration changes, firmware modifications: and alert your security team immediately.
Control management software vulnerabilities. Vulnerabilities aren't limited to the UPS hardware itself. APC Easy UPS Online Monitoring has faced authentication bypass flaws, while Eaton UPS Companion software has code execution risks. Keep all management software updated and minimize installations to only necessary workstations.
Procurement Best Practices
If you're specifying new UPS equipment, consider security as a core requirement alongside traditional metrics like capacity and runtime:
- Cryptographically signed firmware updates should be non-negotiable
- Multi-factor authentication for management interfaces adds critical protection
- Security certifications and compliance indicate vendor commitment to security
- Vendor security track record matters: research their history of vulnerabilities and response times
When evaluating vendors, ask specific questions about their security development lifecycle, penetration testing practices, and incident response procedures. Vendors like APC and CyberPower have made security improvements following vulnerability disclosures, but you need to verify that specific models meet your security requirements.
The Bottom Line
Your UPS isn't just a power protection device anymore: it's a networked computer running firmware, connecting to cloud services, and sitting on your critical infrastructure network. It deserves the same security attention as your firewalls, servers, and switches.
The good news is that with relatively straightforward security controls, you can significantly reduce your risk. Change default credentials, restrict network access, patch proactively, and monitor continuously. These aren't exotic security measures: they're fundamental best practices that happen to be neglected for UPS devices.
Key Takeaways:
- Networked UPS systems represent a growing attack surface exploited by sophisticated threat actors
- Default credentials and unsigned firmware create easily exploitable vulnerabilities
- Attacks can result in physical device destruction, operational disruption, and persistent network compromise
- Security controls like credential management, network segmentation, and behavioral monitoring provide effective protection
- Procurement decisions should include security requirements alongside traditional power protection specifications
At Ace Real Time Solutions, we help organizations design power protection strategies that account for both electrical reliability and cybersecurity. If you're evaluating your infrastructure security posture or planning new deployments, let's talk about how to build protection that works on both fronts.
Because the best backup power system is one that actually stays online when you need it: not one that becomes the entry point for your next security incident.