{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin"},"incident":{"title":"Ukraine power grid blackout of 2015 began with BlackEnergy spear phishing","date":"2015-12-23","date_precision":"day","victim_org":"Kyivoblenergo, Prykarpattyaoblenergo and Chernivtsioblenergo","sector":"Energy & Utilities","country":"Ukraine","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Service Disruption","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No monetary loss figure published; impact measured in customer-hours of lost electricity supply.","records_affected":null,"threat_actor":"Sandworm (Russian GRU-linked)","summary":"On 23 December 2015 three Ukrainian regional electricity distribution companies were hit by a coordinated cyberattack that opened breakers at roughly 30 substations and left about 225,000 customers without power. The joint E-ISAC/SANS analysis found the intrusion began months earlier with spear phishing emails carrying malicious Office documents that installed BlackEnergy 3, which was used to harvest credentials for the operators' VPN and SCADA environments.","how_it_worked":"Staff at the distribution companies received emails with Word and Excel attachments; opening them produced a prompt to enable macros, which installed BlackEnergy 3. The attackers spent months conducting reconnaissance, stealing Windows domain credentials and mapping the SCADA environment, then used legitimate remote access to the operators' control systems to open circuit breakers by hand. They followed up by uploading malicious firmware to serial-to-Ethernet converters, wiping workstations with KillDisk, and flooding customer call centres with a telephony denial of service so outages were harder to report and restore.","lessons":"Macro execution should be blocked by policy for ordinary users, and remote access into an ICS environment should be MFA-protected and separated from the corporate domain whose credentials phishing yields.","confidence":"Confirmed","sources":[{"title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","url":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2016/05/20081514/E-ISAC_SANS_Ukraine_DUC_5.pdf","publisher":"E-ISAC and SANS ICS"},{"title":"Analysis of the Cyber Attack on the Ukrainian Power Grid (archived copy)","url":"https://nsarchive.gwu.edu/sites/default/files/documents/3891751/SANS-and-Electricity-Information-Sharing-and.pdf","publisher":"National Security Archive"},{"title":"Power grid cyberattack in Ukraine (2015)","url":"https://cyberlaw.ccdcoe.org/wiki/Power_grid_cyberattack_in_Ukraine_(2015)","publisher":"NATO CCDCOE Cyber Law Toolkit"}],"entry_type":"incident","slug":"2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin","year":2015,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-ukraine-power-grid-blackout-of-2015-began-with-blackenergy-spear-phishin"}}