{
  "id": "case-ukraine-grid",
  "slug": "ukraine-power-grid-blackout-sandworm",
  "title": "Ukraine Electrical Substation Cyber Warfare Blackout",
  "summary": "First confirmed cyberattack to deliberately cause an electrical power grid blackout. Russian military GRU hackers infiltrated power distribution companies, hijacked SCADA human-machine interfaces (HMI), opened circuit breakers at 30 substations, and destroyed control systems with KillDisk.",
  "case_number": "2:20-cr-00211",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "Ukraine",
  "opened_at": "2015-12-23",
  "status": "charged",
  "victim_sector": "Energy & Electric Utilities",
  "victim_country": "Ukraine",
  "loss_amount_usd": 50000000,
  "loss_amount_note": "Power outages for 230,000 residents and replacement of physical RTUs and servers.",
  "first_seen_at": "2015-05-01T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "sandworm",
  "defendant_slugs": [
    "yuriy-andrienko",
    "sergey-detistov"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Operatives sent spearphishing emails with malicious Microsoft Office attachments containing BlackEnergy 3 macros to utility administrative personnel.",
      "evidence_locator": "CISA Alert IR-ALERT-H-16-056-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert: Cyber-Attack Against Ukrainian Critical Infrastructure",
      "source_url": "https://www.cisa.gov/news-events/ics-alerts/ir-alert-h-16-056-01",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Conspirators hijacked legitimate Virtual Private Network (VPN) credentials connecting corporate IT networks to the isolated Industrial Control System (ICS) network.",
      "evidence_locator": "DOJ Indictment \u00b6 55, Page 37",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1485",
      "evidence_excerpt": "Operators deployed the KillDisk wiper utility, overwriting master boot records and systematically destroying operator workstation files to inhibit grid restoration.",
      "evidence_locator": "CISA Alert IR-ALERT-H-16-056-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert IR-ALERT-H-16-056-01",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2015-12-23",
      "description": "Sandworm operators remotely open breakers across 30 substations, cutting power to 230,000 citizens in freezing winter."
    },
    {
      "event_type": "advisory",
      "event_date": "2016-02-25",
      "description": "U.S. CISA, DOE, and FBI publish joint alert identifying the multi-component SCADA attack."
    },
    {
      "event_type": "indictment",
      "event_date": "2020-10-15",
      "description": "U.S. DOJ indicts six GRU military officers for the Ukrainian power grid cyberattacks."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Spearphishing campaign delivering weaponized Microsoft Office documents containing BlackEnergy 3 macro malware targeting corporate networks of Ukrainian regional electricity distribution companies (Oblenergos).",
    "blast_radius": "Disconnected 30 electrical substations across western Ukraine, leaving approximately 230,000 residents without electrical power for several hours in freezing winter temperatures. Adversaries simultaneously blinded operators by wiping Master Boot Records with KillDisk and executing telephone denial-of-service attacks against customer call centers.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Weaponized Document Phishing",
        "description": "Spearphishing emails carrying Excel attachments with malicious VBA macros deployed BlackEnergy 3 trojan droppers on operator workstations.",
        "technical_artifacts": [
          "Weaponized XLS macros",
          "BlackEnergy 3 dropper"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Pivoting",
        "title": "VPN Credential Theft & SCADA Ingress",
        "description": "Attackers dumped credentials from IT workstations to pivot across dual-homed VPN connections into the isolated Operational Technology (OT) SCADA network.",
        "technical_artifacts": [
          "Harvested VPN credentials",
          "Dual-homed routing pivot"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Control Manipulation",
        "title": "Human-Machine Interface Hijacking",
        "description": "Threat actors took remote control of graphical SCADA HMI consoles, manually opening circuit breakers across dozens of distribution substations.",
        "technical_artifacts": [
          "HMI remote desktop hijack",
          "Substation breaker trip commands"
        ],
        "mitre_technique_id": "T1565.001"
      },
      {
        "phase": "Inhibition",
        "title": "Firmware Manipulation of Serial Gateways",
        "description": "Custom malicious firmware was flashed onto serial-to-Ethernet converters, preventing operators from remotely closing tripped breakers.",
        "technical_artifacts": [
          "Corrupted gateway firmware",
          "Serial converter disablement"
        ],
        "mitre_technique_id": "T1495"
      },
      {
        "phase": "Destructive Impact",
        "title": "KillDisk Wiper & Telephone Flooding",
        "description": "KillDisk wiped server system drives and Master Boot Records, while a telephonic denial-of-service attack flooded customer support lines.",
        "technical_artifacts": [
          "KillDisk wiper",
          "MBR zeroing routine",
          "Telephony DoS floods"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Enforce complete physical and logical network separation between IT and OT industrial control networks.",
      "Require hardware token MFA for all remote engineering access to SCADA workstations and HMIs.",
      "Preserve manual-override operational procedures for critical physical infrastructure control systems.",
      "Implement firmware validation and cryptographic signature checks on industrial field devices and converters."
    ]
  }
}