What happened
A US Department of Justice indictment unsealed in March 2022 charged three FSB officers over a 2012-2017 campaign against the global energy sector. Between 2014 and 2017 the conspirators sent spear-phishing emails to more than 3,300 users at over 500 US and international companies. The indictment names Wolf Creek Nuclear Operating Corporation in Burlington, Kansas as a victim whose business network was compromised through successful spear phishing. Plant safety systems were not affected.
How the deception worked
The operators mailed engineers and IT staff at energy companies with documents tailored to their work, including material presented as job applications and CVs and as industry technical content, so opening the attachment felt like part of the job. Recipients who opened the files installed malware or were funnelled to credential-harvesting pages. The campaign also compromised websites the same engineers routinely visited, so credentials could be captured without any email at all. At Wolf Creek the successful phishing gave access to the corporate business network, which the group then used to push deeper into the victim's systems.
The control that would have caught it· our reading, not a claim from the sources
Role-targeted phishing against engineers demands hardware-backed MFA and strict separation between corporate email environments and any network adjacent to operational technology.
Sources (2)
- Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure WorldwideU.S. Department of Justice·justice.govOpen ↗
- Indictment related to Wolf Creek computer hack unsealedAmerican Nuclear Society·ans.orgOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.