<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Critical Infrastructure Feed</title>
    <link>https://cybercaselibrary.com/sectors/energy-oil-gas/</link>
    <description>Cyber incidents targeting energy grids, pipelines, industrial manufacturing, and critical infrastructure networks.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:15 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/feeds/critical-infrastructure.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)]]></title>
      <link>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</link>
      <guid>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</guid>
      <description><![CDATA[Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Thu, 15 Oct 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: Volt Typhoon Critical Infrastructure Pre-Positioning]]></title>
      <link>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</link>
      <guid>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</guid>
      <description><![CDATA[State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: Colonial Pipeline DarkSide Ransomware Attack]]></title>
      <link>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</guid>
      <description><![CDATA[DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Fri, 07 May 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</link>
      <guid>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</guid>
      <description><![CDATA[Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Sun, 13 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-baratov-yahoo-breach/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-baratov-yahoo-breach/</guid>
      <description><![CDATA[Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Tue, 28 Feb 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</guid>
      <description><![CDATA[Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Thu, 01 May 2014 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</guid>
      <description><![CDATA[Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Wed, 15 Mar 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-kriuchkov-tesla-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-kriuchkov-tesla-ransomware/</guid>
      <description><![CDATA[Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Tue, 25 Aug 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Peter Levashov (Kelihos Botnet)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-levashov-kelihos-botnet/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-levashov-kelihos-botnet/</guid>
      <description><![CDATA[Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Fri, 07 Apr 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-irgc-cyberav3ngers-water/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-irgc-cyberav3ngers-water/</guid>
      <description><![CDATA[Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Tue, 24 Sep 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: U.S. v. Daniel Rhyne (Industrial Insider Extortion)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-rhyne-insider-ransomware-extortion/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-rhyne-insider-ransomware-extortion/</guid>
      <description><![CDATA[Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Tue, 16 Apr 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: Snowflake Customer Multi-Tenant Credential Stuffing Campaign]]></title>
      <link>https://cybercaselibrary.com/cases/snowflake-multi-tenant-credential-attacks/</link>
      <guid>https://cybercaselibrary.com/cases/snowflake-multi-tenant-credential-attacks/</guid>
      <description><![CDATA[Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Fri, 31 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)]]></title>
      <link>https://cybercaselibrary.com/cases/operation-olympic-games-stuxnet/</link>
      <guid>https://cybercaselibrary.com/cases/operation-olympic-games-stuxnet/</guid>
      <description><![CDATA[Joint United States and Israeli covert cyber operation that deployed the Stuxnet computer worm, the first known malware capable of causing physical destruction to industrial hardware. The worm exploited four Windows zero-day vulnerabilities and compromised Siemens Step7 PLC software to spin Natanz nuclear centrifuges out of control.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Thu, 17 Jun 2010 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)]]></title>
      <link>https://cybercaselibrary.com/cases/saudi-aramco-shamoon-wiper/</link>
      <guid>https://cybercaselibrary.com/cases/saudi-aramco-shamoon-wiper/</guid>
      <description><![CDATA[Devastating state-sponsored wiper attack attributed to Iranian threat actors ('Cutting Sword of Justice') that detonated the Shamoon (Disttrack) wiper across Saudi Aramco, simultaneously wiping 35,000 workstation hard drives and overwriting Master Boot Records with an image of a burning American flag.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Wed, 15 Aug 2012 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Critical Infrastructure Incident: AT&T Cloud Telecom Call and Text Metadata Exfiltration]]></title>
      <link>https://cybercaselibrary.com/cases/att-telecom-metadata-snowflake-breach/</link>
      <guid>https://cybercaselibrary.com/cases/att-telecom-metadata-snowflake-breach/</guid>
      <description><![CDATA[Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.]]></description>
      <category><![CDATA[Energy & Critical Infrastructure]]></category>
      <pubDate>Fri, 12 Jul 2024 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>