Hackers Caused a Blackout for the First Time, Researchers Say

Advertisement
By Andrea Peterson, The Washington Post | Updated: 6 January 2016 10:43 IST
Hackers Caused a Blackout for the First Time, Researchers Say

Hackers caused a power outage in Ukraine during the holiday season, researchers say, signalling a potentially troubling new escalation in digital attacks.

"This is the first incident we know of where an attack caused a blackout," said John Hultquist, head of iSight Partner's cyberespionage intelligence practice. "It's always been the scenario we've been worried about for years because it has ramifications across broad sectors."

Half of the homes in Ukraine's Ivano-Frankivsk region were left without power for several hours on December 23rd, according to a local report that attributed the blackout to a virus that disconnected electrical substations from the grid. Researchers at iSight on Monday said their analysis of malware found on the systems of at least three regional electrical operators confirmed that a "destructive" cyber-attack led to the power outage.

Electrical outages can lead to ripple effects that leave communities struggling with things like transportation and communication, according to security experts who have long warned about the potential for cyber-attacks on the power grid.

Advertisement

In this case, the attackers used a kind of malware that wiped files off computer systems, shutting them down and resulting in the blackout, Hultquist said. At least one of the power systems was also infected with a type of malware known as BlackEnergy. A similar combination was used against some Ukrainian media organizations during local elections last year, he said.

A blog post from cyber-security company ESET also reported that BlackEnergy malware helped deliver the destructive component "in attacks against Ukrainian news media companies and against the electrical power industry."

Advertisement

While ESET's analysis showed the destructive element was "theoretically capable of shutting down critical systems," it said BlackEnergy malware's ability to take control of a system would give attackers enough access to take down the computers. In that case, the destructive element may have been a way to make it harder to get the systems up and running again, according to ESET.

Hultquist believes the attacks that caused the blackout were the work of a group iSight dubs "Sandworm" that the company previously observed using BlackEnergy. In a 2014 report, iSight said the group was targeting NATO, energy sector firms and US academic institutions as well as government organizations in Ukraine, Poland and Western Europe.

Advertisement

"Operators who have previously targeted American and European sensitive systems look to have actually carried out a successful attack that turned the lights out," Hultquist said.

He described the group as "Russian," but declined to connect it to a specific government or group. Other destructive cyber-attacks in the past have been attributed to government actors - such as attacks on Iranian nuclear facilities thought to be the result of a collaboration between the US and Israel, or the Sony Pictures entertainment attack blamed on North Korea.

But experts warn that, while is easy to come to circumstantial conclusions about cyberattacks, it can be very difficult to pin down who was responsible - or even what exactly happened. And there have been false alarms about cyber-attacks on infrastructure in the past.

In 2011, experts said that a pump failure at an Illinois water plant appeared to be caused by foreign hackers. However, it was later reported that there hadn't been any malicious activity: Instead, a remote login to the plant's computers systems from a contractor traveling in Russia was mistakenly connected to the issue.

"It's easy to assume this threat actor is controlled by the Russian government and they intentionally shut down power in this region in Ukraine, but evidence to prove that conclusion is very difficult to obtain for various reasons," said Tom Cross, chief technology officer at cyber-security firm Drawbridge Networks.

The picture can often become clearer as more information trickles out, but the public and even some of those investigating may not be operating with all the facts, according to Cross.

"When a plane crashes, the FAA publishes all of the details about the incident. That makes sense because we pilots want to know what to do to avoid the next crash," he said. "In our industry, when something like this happens, some information comes out and some doesn't."

Not everyone necessarily has an interest in fully disclosing the attacks because it might embarrass them or give new information to attackers, Cross said. But he argues that the more people know the details about the attack, the better the security industry can prepare for the next one.

"People should operate with an abundance of caution and assume the threat is real while demanding technical detail and evidence," he said.

Assuming that the hackers did take out the power in Ukraine, there was a silver lining, according to Cross: The grid seems to have rebounded quickly.

"The world didn't end here - they did get power back up," Cross said.

© 2016 The Washington Post

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 3 Surfaces on Geekbench Ahead of Launch on July 1
  2. You Can Now Code in the Terminal With Google's Free Gemini CLI Tool
  3. Upcoming Phones in July: Samsung Galaxy Z Fold 7, OnePlus Nord 5, More
  4. WhatsApp Can Now Summarise Unread Messages for You Using Meta AI
  5. Oppo Reno 14F 5G With 6,000mAh Battery Launched: Price, Specifications
  6. Vivo X Fold 5 With Snapdragon 8 Gen 3 SoC, 6,000mAh Battery Launched
  7. Motorola Teases New Phone Launch in India; Could Be the Moto G96 5G
  1. Tecno Pova 7 5G Series India Launch Set for July 4; Rear Design Teased
  2. OnePlus Expands Doorstep Pickup and Drop Service for Repairs to More Cities in India
  3. Gemini Live’s Real-Time Captions Feature Is Now Rolling Out to All Users
  4. Samsung Smart Monitor M9 With QD-OLED Display, AI Features Launched Alongside Updated M8 and M7 Models
  5. Android 16 QPR1 Beta 2.1 Update With Bug Fixes, June 2025 Security Patch Rolling Out for Pixel Devices
  6. Realme P3x 5G Now Available in India With Limited-Time Discount: Check Price
  7. Google Introduces Gemini CLI Open-Source AI Agent for Coding, Available to Developers for Free
  8. Google Pixel 10 Tipped to Pack Larger Battery Than Pixel 9; May Offer Faster Charging
  9. SonicWall Says Malicious NetExtender Client Used to Steal VPN Credentials
  10. Motorola Teases Upcoming Smartphone Launch in India, Could Be the Moto G96 5G
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.