2016 cyber attack against power transmission in Ukraine

Incident Impacts Disruption to energy supply
Affected Sector Energy
Associated Intrusion Sets ELECTRUM , Sandworm

On December 17th 2016, a cyber attack against a Ukrenergo electricity transmission substation in Pivnichna, Kiev, Ukraine resulted in a blackout shortly before midnight which lasted just over an hour.

The attack was subsequently linked to the CRASHOVERRIDE/INDUSTROYER malware by researchers at Dragos and ESET respectively. The malware was specifically designed to communicate with industrial control systems and had the potential to cause significantly more impact.

The attack was ultimately attributed to Sandworm (also known as Sandworm Team) / ELECTRUM (Dragos), with the US government charging individuals associated with Russia's GRU.

Cyber Threat Graph Context

Explore how this cyber incident relates to the wider threat graph

References