top of page

Ukraine's Power Grid Attacks (2015 and 2016)

7 days ago
4 min read

In the space of two winters, Ukraine's electricity network became the setting for the first confirmed cyber attacks to cause power outages. The two incidents, in December 2015 and December 2016, used very different methods but pointed to the same lesson: the ability to operate a grid by hand is not a relic, it is a safeguard.

December 2015: operators locked out of their own systems

Two-column comparison of the December 2015 and December 2016 Ukraine power grid attacks: method, target, impact and recovery
The 2015 attack used stolen remote access and operators' own tools; the 2016 attack used malware that spoke grid protocols directly.

Late in the afternoon of 23 December 2015, three regional electricity distribution companies in Ukraine, including Prykarpattyaoblenergo, Kyivoblenergo and Chernivtsioblenergo, lost power across their service areas. Around 225,000 customers were affected, with outages lasting up to about six hours.

The attackers had been inside the companies' networks for months. Access is widely reported to have begun with spear-phishing emails carrying malicious Office documents, part of a campaign using malware known as BlackEnergy 3. From there they harvested credentials, learned how the control systems worked and obtained valid remote-access paths into the control environment.

On the day itself, they used that access to take over operators' screens remotely and open circuit breakers by hand, in some cases moving the operators' own cursors while staff watched. They then made recovery harder in several deliberate ways:

  • Firmware on serial-to-Ethernet converters was overwritten, cutting remote communication to many substations.

  • KillDisk malware wiped and disabled workstations and servers.

  • Backup power to a control centre was interrupted.

  • A flood of automated calls jammed a call centre so customers could not report outages.

Crucially, Ukrainian staff restored power by switching to manual operation, driving to substations and closing breakers physically. Their familiarity with running the grid by hand is a large part of why the outage lasted hours rather than days.

December 2016: malware that spoke the grid's own language

A year later, just before midnight on 17 December 2016, a transmission substation north of Kyiv known as Pivnichna, operated by Ukrenergo, lost power. The outage cut roughly one-fifth of the capital's night-time electricity consumption and lasted about an hour.

This time the method was different and, in some ways, more concerning. Rather than relying on operators' own tools, the attackers used purpose-built malware, named Industroyer by ESET and CrashOverride by Dragos. It could speak industrial protocols directly, including IEC 60870-5-101 and IEC 60870-5-104, IEC 61850 and OPC Data Access, which meant it could issue commands to grid equipment on its own rather than needing a human at a keyboard.

Analysts noted that the malware was modular and could, in principle, be adapted to other grids that use the same international protocols. Its effect in Kyiv was limited, but the capability it demonstrated was the real story.

Attribution

Both attacks have been attributed by the United States and United Kingdom governments, along with major researchers, to a unit of Russia's military intelligence service, the GRU, widely tracked under the name Sandworm. In October 2020, the US Department of Justice indicted officers of GRU Unit 74455 in connection with the BlackEnergy, Industroyer and KillDisk attacks on Ukraine's grid, and the UK publicly attributed the activity to the GRU in February 2020.

What it taught the industry

  • Remote access is a prime target. In 2015, legitimate remote access, obtained through stolen credentials, was the attackers' main tool. The control systems were used exactly as intended, just by the wrong people.

  • Malware can talk to equipment directly. The 2016 attack showed that adversaries can build tools that understand grid protocols, removing the need for hands-on operation.

  • Attackers plan for your recovery. Wiping workstations, bricking converters, cutting backup power and jamming call centres were all aimed at slowing restoration, not just causing the initial outage.

  • Manual operations save the day. The single biggest reason outages stayed short was trained staff who could run the system by hand.

Practical defensive lessons

  • Lock down remote access. Inventory every remote path into your OT environment, including vendor and maintenance connections. Require multi-factor authentication, limit what each account can reach, and remove access that is no longer needed.

  • Separate IT and OT credentials. Accounts and identities used on office systems should not open doors into control systems.

  • Monitor for unusual control activity. Commands issued at odd hours, from unexpected places, or in unusual sequences are worth detecting. Passive network monitoring can surface this without touching live systems.

  • Keep manual operation alive. Make sure staff can operate key equipment without the control system, practise it, and keep the local knowledge and spare parts that make it possible.

  • Plan for a hostile recovery. Keep offline backups of workstations and controller configurations, hold spare converters and hardware, and build an incident plan that assumes the attacker is trying to slow you down.

Key takeaways

  • The 2015 attack hit three distribution companies and about 225,000 customers using stolen remote access and operator takeover, with outages of several hours.

  • The 2016 attack on a Kyiv-area substation used Industroyer/CrashOverride, malware that speaks grid protocols directly, with roughly an hour of outage.

  • Both are attributed by the US and UK governments and researchers to the Russian GRU unit known as Sandworm.

  • Manual operation by trained staff was the decisive factor in fast recovery.

  • Remote-access control, segmentation and the ability to run by hand are the enduring defensive lessons.

How QBits Networks can help

The 2015 and 2016 attacks both turned on remote access and the ability to keep operating under pressure. Our secure remote access reviews map every way into your OT environment and show where access is excessive or unprotected, and our OT incident response readiness work helps you plan for a recovery where the attacker is actively working against you, including keeping manual operations viable. Tell us what you need through our contact page and we'll scope it with you.

bottom of page