CASE DOSSIER uncharged

Operation Olympic Games (Stuxnet Natanz Centrifuge Sabotage)

Docket: Operation-Olympic-Games-01 Court: International Atomic Energy Agency (IAEA) Technical Reports Opened: 2010-06-17 Sector: Nuclear Energy & Industrial Control Systems

Key Facts

Status
UNCHARGED
Legal disposition
Loss Amount
$1.0 billion
Physical destruction of roughly 1,000 uranium centrifuges and multi-year setback to Iranian nuclear enrichment program.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: UNCHARGED in International Atomic Energy Agency (IAEA) Technical Reports.
  • Primary Target Sector: Nuclear Energy & Industrial Control Systems.
  • Documented Financial Loss: $1.0 billion.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Historic joint U.S. and Israeli cyber warfare campaign deploying the Stuxnet computer worm to physically sabotage Iranian nuclear enrichment facilities at Natanz, manipulating Siemens S7-300 PLCs and variable-frequency drives to over-spin IR-1 centrifuges to destruction while playing normal sensor telemetry to operators.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2010-2568, CVE-2010-2729, CVE-2010-2772, CVE-2010-3888) combined with targeted spearphishing and stolen remote access credentials.

Operational & Financial Fallout

Physical destruction of roughly 1,000 uranium centrifuges and multi-year setback to Iranian nuclear enrichment program. Impacted Nuclear Energy & Industrial Control Systems infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: UNCHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2010-2568, CVE-2010-2729, CVE-2010-2772, CVE-2010-3888) combined with targeted spearphishing and stolen remote access credentials.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the Nuclear Energy & Industrial Control Systems sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

Historic joint U.S. and Israeli cyber warfare campaign deploying the Stuxnet computer worm to physically sabotage Iranian nuclear enrichment facilities at Natanz, manipulating Siemens S7-300 PLCs and variable-frequency drives to over-spin IR-1 centrifuges to destruction while playing normal sensor telemetry to operators.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Physical destruction of roughly 1,000 uranium centrifuges and multi-year setback to Iranian nuclear enrichment program. Impacted Nuclear Energy & Industrial Control Systems infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2009-11-15 incident

Centrifuge destruction escalates as Stuxnet modifies PLC drive control routines.

2010-06-17 discovery

VirusBlokAda identifies malware spreading via LNK zero-day, dubbed Stuxnet.

2010-11-23 disclosure

Iranian officials publicly acknowledge centrifuge equipment disruptions.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1091
"Stuxnet crossed air-gapped industrial control boundaries via infected USB removable storage devices exploiting Windows LNK shortcut vulnerability CVE-2010-2568." Symantec Security Response Stuxnet Dossier v1.4, Page 12 reviewed
T0831
"Injected malicious ladder logic into Siemens Simatic Step 7 software to alter frequency converter drive speeds to 1,410 Hz before dropping to 2 Hz, inducing rotor resonance vibration failure." IAEA Board of Governors Verification Report GOV/2010/62 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Operation Olympic Games (Stuxnet Natanz Centrifuge Sabotage), No. Operation-Olympic-Games-01 (International Atomic Energy Agency (IAEA) Technical Reports 2010), https://cybercaselibrary.com/cases/stuxnet-natanz-centrifuges/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/stuxnet-natanz-centrifuges" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>