US: Sophisticated Attackers Hacked Ukrainian Electric Grid

Advertisement
By Associated Press | Updated: 29 February 2016 11:07 IST
A US investigation found that a December hack on the Ukrainian power grid was coordinated and highly sophisticated.

The report released Thursday offers a detailed look at one of the first cyber-attacks to succeed in taking down part of a national power grid. The well-planned strike, which blacked out more than 225,000 people, hit three regional electronic power distribution companies within 30 minutes of each other on December 23.

An attack such as this one has long been a nightmare scenario for top US officials. National Security Agency and US Cyber Command chief Adm. Michael Rogers has previously warned that it's not a matter of if, but when attackers will also target US power systems.

Advertisement

The impacted sites continue to "run under constrained operations" more than two months later. In addition, the report states that three other organizations, some involved with unspecified Ukrainian "critical infrastructure," also appear to have been hacked - but didn't suffer overt impacts to their operations.

The US sent a team of cyber officials including from the Department of Homeland Security, Department of Energy, and FBI to Ukraine to work with the government and learn lessons to prevent such future attacks.

Advertisement

The group didn't independently review technical evidence from the Dec. 23 cyber-attack, although it conducted interviews and did other spadework to piece together what appears to be a highly targeted and advanced hack.

The hackers appeared to conduct "extensive reconnaissance of the victim networks," possibly by first using malware introduced via phony "phishing" emails to snag usernames and passwords to access the facility remotely and hit their circuit breakers.

Advertisement

The networks were compromised at least six months before the outage, by sending emails that included the downloader for the virus BlackEnergy to company employees whose emails were found publicly online, said Anna Dudka, a spokeswoman for the Ukrainian Energy Ministry.

All the affected companies reported infections with malware known as "BlackEnergy," although US investigators said they are still evaluating whether that specific malware played a role in the attacks.

Advertisement

At the end of the attack, hackers wiped targeted files on some of the systems at the three electrical companies using malware called "KillDisk," which also rendered the system inoperable.

The hackers also did their best to interfere with power-restoration efforts. For instance, they aimed to keep important servers inoperative by remotely disconnecting their "uninterruptable power supplies," which would normally keep the computers running even in a blackout. The attackers managed that by accessing an internal management program for those power supplies.

Among several preventative measures, the report suggests that companies isolate systems used to run critical infrastructure from the Internet and that they limit the ability to remotely access these systems.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cyber attack, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  2. Spotify Expands Its Self-Serve Ads Manager Platform in India
  3. Oppo Find X9s With Triple 50-Megapixel Cameras Launched at This Price
  4. Oppo Find X9s Pro Launched With 200-Megapixel Cameras: See Price, Features
  5. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  6. Xiaomi TV S Mini LED 75 (2026) Review
  7. Oppo Watch X3 Launched Globally With Titanium Build, 3,000-Nit OLED Screen
  8. Oppo F33 Pro 5G Review: The Best Looking Phone Under Rs. 40,000?
  9. NoiseFit Diva Araya Jewellery-Inspired Smartwatch Debuts in India
  1. Oppo Find X9s Launched With Dimensity 9500s SoC, Hasselblad-Tuned 50-Megapixel Cameras: Price, Specifications
  2. Oppo Watch X3 Launched Globally With Titanium Build, 3,000-Nit OLED Screen: Price, Features
  3. NoiseFit Diva Araya Jewellery-Inspired Smartwatch With Ceramic Build Launched in India: Price, Features
  4. Spotify Ads Manager Platform Launched in India, Brings Self-Serve Advertising to Businesses
  5. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets; Ends Day-One Call of Duty Access
  6. Incoming Apple CEO John Ternus Already Driving AI Overhaul Ahead of Leadership Transition: Report
  7. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  8. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  9. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  10. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.