What 1,500 Compromised Batteries Could Do to a Grid
Modelling puts the threshold at 5.4% of ERCOT's storage fleet, and the detection problem is severe: a battery flipping from charge to discharge in under a second is normal behaviour.

An interview published on 2 September with Rafael Narezzi, chief executive of Centrii, puts numbers on a scenario the storage industry has mostly discussed in the abstract: how many grid batteries an attacker would need to control before the grid itself became unstable.
In the ERCOT modelling the figure is 1,500 compromised one-megawatt units — 5.4 per cent of a fleet of roughly 28,000 units across 28 GW of storage. For Great Britain the equivalent is 400 units, about 29 per cent of a roughly 1,400-unit fleet totalling 6.8 GW. Estimated economic damage is put at $12 to 65 billion for Texas and £2 to 10 billion for Great Britain. Separate research cited in the piece found that 15 per cent of battery fleet power is enough to destabilise systems, and Centrii's own estimate is that as few as 11 to 21 compromised two-megawatt units could destabilise a regional grid.
The route in is not the battery. Compromise of a cloud management platform is estimated to succeed 35 to 70 per cent of the time over a two-to-five-week campaign, which is the familiar shape of modern OT risk: the field equipment is reached through the fleet management layer that exists to operate it at scale.
The detection problem is the part engineers should sit with. A battery flipping from full charge to full discharge in under a second is not anomalous — it is exactly what frequency response is supposed to look like. Malicious dispatch and legitimate dispatch are indistinguishable on the monitoring systems operators actually have, because the whole value of the asset is its ability to do violent things quickly. The proposed signature is a reverse governor effect, where inverter output amplifies system oscillations instead of damping them, which is a behavioural rather than a signature-based detection and requires someone to be watching the aggregate rather than the unit.
The forecast in the piece puts a 92.1 per cent probability on a major attack affecting a million or more people by 2031, falling to 61.4 per cent where IEC 62443 certification requirements and quarterly drills are in place. Those are modelled figures with wide assumptions behind them and should be read as a direction rather than a measurement — but the direction is that certification and rehearsal move the number substantially, which is a more useful finding than the headline probability.
One historical note lands harder than the modelling. Spain's April 2025 grid collapse took eleven months to rule out a cyberattack, with key forensic data missing. Whatever caused that event, the investigation demonstrated that a deliberate attack could hide comfortably inside an accident investigation — and forensic readiness on inverters and their management platforms is a much cheaper thing to fix in advance than after.
Source: Help Net Security