Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

The First Successful Cyber Attack on an Electrical Grid

Author: Scarinci Hollenbeck, LLC

Date: January 20, 2016

Key Contacts

Back

Experts have long warned about the exposure of industrial control systems to cyber attack. These systems, like those used in our electrical grid, usually are not regularly updated.

Their failure would cause significant social disruption. They are the soft underbelly of our modern world. For example, Stuxnet exploited a Siemens industrial controller not designed to withstand cyber attack. In another case, original, 1960’s 8 inch, floppy disks control parts of the launch systems for U.S. nuclear missiles.[1] Indeed, most homes still have traditional circuit breakers.

distribution electric substation with power lines and transformers, at sunset

The first known instance of malware causing a disruption in major electrical service took place on December 23, 2015 in Ukraine. At least three regional substations were disconnected from the grid. While not in the U.S., the Ukrainian methods and apparatuses for delivering electricity to the end-user are not significantly different. In all, around 700,000 homes lost power as a result of this attack.

The cyber attack happened when many Ukrainian power stations became infected by the malware package “BlackEnergy.” The package’s original purpose was to spy on various business groups, such as media organizations, power companies, and telecoms. However, the malware used in this attack contained several important upgrades to its functionality—most notably: making the infected machine unbootable, wiping all data on the infected machine, and backdooring a secure shell (SSH) utility, which gave the attackers permanent access to the infected machines. Researchers suspect that the attackers used the SSH to gain access to the systems and shut them down. Meanwhile, the program wiped all the data on the systems, making their recovery much more lengthy and difficult. Finally, the attackers waged denial-of-service attacks (DDoS) on the target’s internet and phones systems to prevent power company personnel from learning about the outages.

The group behind BlackEnergy is known as the “Sandworm Gang.”

In the past, this group has spied on NATO, Eastern European agencies, and European commercial and industrial groups. Research suggests that the group operates from Russia, although confirmation has been slippery, and even if they did operate from Russia, it is not clear who is directing them. Whoever this group is though, they possess enough sophistication to run a three pronged attack: shutting down electric service, wiping data on the system computers, and coordinating a DDoS attack on internet and phone systems. No one of these three prongs is necessarily a difficult attack. However, the coordination of all three indicates that, without hyper-sophisticated malware, attackers can use a variety of low-sophistication attacks in tandem to produce a high-level result.

The infection most likely, although not confirmed, occurred through Microsoft Word macros. These sorts of attacks are considered “social engineering” attacks, which rely on duping an end-user into installing malware or taking an action they otherwise would not and should not take. This particular kind is simple and insidious. For example, the end-user receives an email from his boss saying to review the attached document ASAP. The email looks legitimate, and not wanting to disappoint the boss, the user opens the attachment. As the Word document opens, it runs a macro that installs the malicious software, unbeknownst to the end-user.

Despite experts’ warnings, attacks on these sorts of systems have been rare and usually done only for specific discrete reasons. However, with the now real threat that these attacks could become more widespread and more frequent, we will have to acknowledge that any device with a computer connected to a system, must be secured and monitored for cyber-attack.

[1] Oddly enough, this is currently a pretty secure way to operate these missiles as the technology is so old that it is impervious to the advancements in cyber attack software. However, once someone does develop an exploit, the whole system will need to change.

Related Article:
Cyber Insecurity: The Dark Web

The Quantum Computer And The Obsolence of Current Encryption

What Is Cyber Security? It Starts With Cryptology

Cyber Insecurity: Ashley Madison Encrypted Passwords Cracked.

Survey Reveals Many Business Executives Lack Cybersecurity Confidence

Top Cybersecurity Threats Unveiled by Hackers – Is Anyone Safe?

Additional information and resources:
Cyber Security And Data Protection Group

Intellectual Property And Technology

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Scarinci Hollenbeck, LLC, LLC

    Related Posts

    See all
    What Business Owners Get Wrong Before Meeting a Litigation Attorney post image

    What Business Owners Get Wrong Before Meeting a Litigation Attorney

    What should you expect when meeting a litigation attorney about a business dispute? You should expect to describe the dispute in your own words, hand over the most important documents, flag any deadlines or immediate threats, and leave with a clearer picture of the problem, what information is still needed, and the likely next steps. […]

    Author: Michael Mietlicki

    Link to post with title - "What Business Owners Get Wrong Before Meeting a Litigation Attorney"
    Arbitration vs. Litigation vs. Mediation: What New Jersey Businesses Should Know Before Signing a Contract post image

    Arbitration vs. Litigation vs. Mediation: What New Jersey Businesses Should Know Before Signing a Contract

    Arbitration resolves disputes privately before an arbitrator whose decision is usually final, while litigation resolves them in court with full rights of appeal. Whether a business ends up in arbitration or litigation is often decided when it signs the contract, long before any dispute arises. Key Takeaways When facing a contract dispute, carefully consider your […]

    Author: Graham Staton

    Link to post with title - "Arbitration vs. Litigation vs. Mediation: What New Jersey Businesses Should Know Before Signing a Contract"
    Can You Own Part of a New Jersey Business Without a Written Agreement? post image

    Can You Own Part of a New Jersey Business Without a Written Agreement?

    Can you own part of a business in New Jersey without a written agreement? Yes, it is possible. Under New Jersey’s Uniform Partnership Act, a partnership can arise when two or more people carry on a business as co-owners for profit, whether or not they ever intended to form one. Ownership doesn’t necessarily depend on […]

    Author: Michael Mietlicki

    Link to post with title - "Can You Own Part of a New Jersey Business Without a Written Agreement?"
    Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One post image

    Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One

    For New Jersey businesses, crisis preparedness should be viewed as a legal and operational function, not simply an emergency-management exercise. A well-designed crisis response plan can help preserve evidence, protect confidential communications, meet reporting obligations, limit unnecessary exposure, and prevent an already difficult situation from becoming a larger legal problem. Key Takeaways A serious crisis […]

    Author: Sean M. Pena

    Link to post with title - "Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One"
    Monmouth County's Next Development Wave: What Developers and Investors Need to Know post image

    Monmouth County's Next Development Wave: What Developers and Investors Need to Know

    Monmouth County is entering a significant new phase of development. For those looking to acquire property or undertake a new project, understanding the market opportunity is only the beginning. The more important question is whether a particular property can actually be developed as contemplated and what approvals, agreements, and other conditions will be required to […]

    Author: Donald M. Pepe

    Link to post with title - "Monmouth County's Next Development Wave: What Developers and Investors Need to Know"
    Are Your Conversations with AI Shielded from Discovery? Courts Are Split post image

    Are Your Conversations with AI Shielded from Discovery? Courts Are Split

    Whether a client’s prompts to a generative AI tool and the documents it produces are protected from disclosure depends on the case type, who claims protection, and whether counsel was involved. In United States v. Heppner, a New York federal judge ruled that a criminal defendant’s communications with an AI platform were protected by neither […]

    Author: Chris Seelinger

    Link to post with title - "Are Your Conversations with AI Shielded from Discovery? Courts Are Split"

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Sign up to get the latest from our attorneys!

    Explore What Matters Most to You.

    Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

    Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

    Let`s get in touch!

    * The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
    “If you would like to submit a file, please email it directly to info@sh-law.com.

    Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!