On 23 December 2015 attackers took control of systems at three Ukrainian regional electricity distributors, Prykarpattyaoblenergo, Kyivoblenergo, and Chernivtsioblenergo. They cut power to around 225,000 customers for several hours. It is widely regarded as the first confirmed power outage caused by a cyber attack.
What happened
- The attackers first got in through spear-phishing emails carrying BlackEnergy malware and stole login credentials to reach the systems that control the grid.
- They remotely opened circuit breakers at substations and flooded the utilities’ customer phone lines. They also used KillDisk malware to wipe computers and slow down recovery.
- Power was restored in under six hours, largely by switching to manual operation.
- Ukraine’s security service blamed Russia. In 2020 the US Department of Justice charged six Russian GRU officers over attacks that included the destructive malware campaigns against Ukraine’s power grid from December 2015.
Why it mattered
The attack showed that a cyber intrusion could cause physical disruption to critical national infrastructure. Governments and energy operators around the world reviewed their defences as a result.
Lessons for organisations
Operators of critical systems should separate corporate and operational networks, use multi-factor authentication for remote access, and practise manual fallback procedures so that services can be restored quickly.
Sources: E&E News, US Department of Justice
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.