CASE DOSSIER charged

Ukraine Electrical Substation Cyber Warfare Blackout

Docket: 2:20-cr-00211 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2015-12-23 Sector: Energy & Electric Utilities

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$50.0 million
Power outages for 230,000 residents and replacement of physical RTUs and servers.
Techniques
3
Verified mappings
Defendants
2
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Energy & Electric Utilities.
  • Documented Financial Loss: $50.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

First confirmed cyberattack to deliberately cause an electrical power grid blackout. Russian military GRU hackers infiltrated power distribution companies, hijacked SCADA human-machine interfaces (HMI), opened circuit breakers at 30 substations, and destroyed control systems with KillDisk.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Spearphishing campaign delivering weaponized Microsoft Office documents containing BlackEnergy 3 macro malware targeting corporate networks of Ukrainian regional electricity distribution companies (Oblenergos).

Operational & Financial Fallout

Disconnected 30 electrical substations across western Ukraine, leaving approximately 230,000 residents without electrical power for several hours in freezing winter temperatures. Adversaries simultaneously blinded operators by wiping Master Boot Records with KillDisk and executing telephone denial-of-service attacks against customer call centers.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Spearphishing campaign delivering weaponized Microsoft Office documents containing BlackEnergy 3 macro malware targeting corporate networks of Ukrainian regional electricity distribution companies (Oblenergos).

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Weaponized Document Phishing
MITRE ATT&CK T1566.001 →

Spearphishing emails carrying Excel attachments with malicious VBA macros deployed BlackEnergy 3 trojan droppers on operator workstations.

Artifacts & Tooling: Weaponized XLS macros BlackEnergy 3 dropper
2
Pivoting VPN Credential Theft & SCADA Ingress
MITRE ATT&CK T1078 →

Attackers dumped credentials from IT workstations to pivot across dual-homed VPN connections into the isolated Operational Technology (OT) SCADA network.

Artifacts & Tooling: Harvested VPN credentials Dual-homed routing pivot
3
Control Manipulation Human-Machine Interface Hijacking
MITRE ATT&CK T1565.001 →

Threat actors took remote control of graphical SCADA HMI consoles, manually opening circuit breakers across dozens of distribution substations.

Artifacts & Tooling: HMI remote desktop hijack Substation breaker trip commands
4
Inhibition Firmware Manipulation of Serial Gateways
MITRE ATT&CK T1495 →

Custom malicious firmware was flashed onto serial-to-Ethernet converters, preventing operators from remotely closing tripped breakers.

Artifacts & Tooling: Corrupted gateway firmware Serial converter disablement
5
Destructive Impact KillDisk Wiper & Telephone Flooding
MITRE ATT&CK T1485 →

KillDisk wiped server system drives and Master Boot Records, while a telephonic denial-of-service attack flooded customer support lines.

Artifacts & Tooling: KillDisk wiper MBR zeroing routine Telephony DoS floods
Real-World Blast Radius & Operational Fallout

Disconnected 30 electrical substations across western Ukraine, leaving approximately 230,000 residents without electrical power for several hours in freezing winter temperatures. Adversaries simultaneously blinded operators by wiping Master Boot Records with KillDisk and executing telephone denial-of-service attacks against customer call centers.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce complete physical and logical network separation between IT and OT industrial control networks.
✓ Require hardware token MFA for all remote engineering access to SCADA workstations and HMIs.
✓ Preserve manual-override operational procedures for critical physical infrastructure control systems.
✓ Implement firmware validation and cryptographic signature checks on industrial field devices and converters.

Procedural & Incident Timeline

2015-12-23 incident

Sandworm operators remotely open breakers across 30 substations, cutting power to 230,000 citizens in freezing winter.

2016-02-25 advisory

U.S. CISA, DOE, and FBI publish joint alert identifying the multi-component SCADA attack.

2020-10-15 indictment

U.S. DOJ indicts six GRU military officers for the Ukrainian power grid cyberattacks.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yuriy Sergeyevich Andrienko Russian Federation fugitive Pending None GRU Unit 74455 military officer who developed components of the NotPetya and Olympic Destroyer malware.
Sergey Vladimirovich Detistov Russian Federation fugitive Pending None GRU Unit 74455 officer who conducted spearphishing campaigns targeting the 2018 PyeongChang Winter Olympic Games.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"Operatives sent spearphishing emails with malicious Microsoft Office attachments containing BlackEnergy 3 macros to utility administrative personnel." CISA Alert IR-ALERT-H-16-056-01 reviewed
T1078 Valid Accounts
Defense Evasion
"Conspirators hijacked legitimate Virtual Private Network (VPN) credentials connecting corporate IT networks to the isolated Industrial Control System (ICS) network." DOJ Indictment ¶ 55, Page 37 reviewed
T1485 Data Destruction
Impact
"Operators deployed the KillDisk wiper utility, overwriting master boot records and systematically destroying operator workstation files to inhibit grid restoration." CISA Alert IR-ALERT-H-16-056-01 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Ukraine Electrical Substation Cyber Warfare Blackout, No. 2:20-cr-00211 (U.S. District Court for the Western District of Pennsylvania 2015), https://cybercaselibrary.com/cases/ukraine-power-grid-blackout-sandworm/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/ukraine-power-grid-blackout-sandworm" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>