2015 · Electric Power
Ukraine 2015 Power Grid Incident
Coordinated intrusion at multiple distribution utilities resulted in remote operation of breakers, causing outages affecting roughly 225,000 customers, with recovery complicated by firmware and telephony disruption.
What happened
Attackers obtained access to utility business networks, harvested credentials, reached operator environments and used legitimate remote-control capability to open breakers, then hindered restoration.
Who
Attributed in public reporting to a Russia-associated threat activity group; assessments vary in naming conventions.
Where
Multiple regional electricity distribution companies in Ukraine.
Why
Assessed objective: demonstrate capability and disrupt civilian infrastructure during a geopolitical conflict.
How
Spear-phishing into the business network, credential theft, use of VPN access into the control environment, then operation of the SCADA HMI plus destructive actions against workstations and field communication devices.
Timeline
- Spring 2015Initial access reported via spear-phishing with malicious documents
- Mid 2015Credential harvesting and reconnaissance of the operational environment
- 23 December 2015Coordinated breaker operations at multiple distribution companies
- December 2015 – January 2016Manual restoration; firmware of serial-to-Ethernet devices overwritten
Attack path
Described at the level required to build detection and controls.
Initial Access
ReportedSpear-phishing into business network
IT foothold
ReportedMalware and remote access tooling
Credential access
ReportedHarvested credentials including remote access
IT/OT boundary
ReportedVPN into the control environment
Control systems
ReportedOperator HMI used to open breakers
Physical consequence
ReportedCustomer outages across several regions
Impact
Technology involved
ATT&CK techniques
Vulnerabilities and weaknesses exploited
- No single vulnerability — credential abuse and legitimate remote access were central
Control failures
- No MFA on remote access into the control environment
- Insufficient IT/OT separation
- Limited monitoring of operator actions
- Field device firmware integrity
Where earlier detection was possible
- Alerting on remote access sessions into operator environments
- Detecting credential harvesting activity in the business network
- Monitoring for commands not correlated with operator action records
Defensive lessons
- Manual operation capability materially reduced outage duration
- MFA and mediated access into control zones are foundational
- Recovery planning must assume field devices may be unusable
Why should I care?
Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.
Sources & further reading