Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

The First Successful Cyber Attack on an Electrical Grid

Author: Scarinci Hollenbeck, LLC

Date: January 20, 2016

Key Contacts

Back

Experts have long warned about the exposure of industrial control systems to cyber attack. These systems, like those used in our electrical grid, usually are not regularly updated.

Their failure would cause significant social disruption. They are the soft underbelly of our modern world. For example, Stuxnet exploited a Siemens industrial controller not designed to withstand cyber attack. In another case, original, 1960’s 8 inch, floppy disks control parts of the launch systems for U.S. nuclear missiles.[1] Indeed, most homes still have traditional circuit breakers.

distribution electric substation with power lines and transformers, at sunset

The first known instance of malware causing a disruption in major electrical service took place on December 23, 2015 in Ukraine. At least three regional substations were disconnected from the grid. While not in the U.S., the Ukrainian methods and apparatuses for delivering electricity to the end-user are not significantly different. In all, around 700,000 homes lost power as a result of this attack.

The cyber attack happened when many Ukrainian power stations became infected by the malware package “BlackEnergy.” The package’s original purpose was to spy on various business groups, such as media organizations, power companies, and telecoms. However, the malware used in this attack contained several important upgrades to its functionality—most notably: making the infected machine unbootable, wiping all data on the infected machine, and backdooring a secure shell (SSH) utility, which gave the attackers permanent access to the infected machines. Researchers suspect that the attackers used the SSH to gain access to the systems and shut them down. Meanwhile, the program wiped all the data on the systems, making their recovery much more lengthy and difficult. Finally, the attackers waged denial-of-service attacks (DDoS) on the target’s internet and phones systems to prevent power company personnel from learning about the outages.

The group behind BlackEnergy is known as the “Sandworm Gang.”

In the past, this group has spied on NATO, Eastern European agencies, and European commercial and industrial groups. Research suggests that the group operates from Russia, although confirmation has been slippery, and even if they did operate from Russia, it is not clear who is directing them. Whoever this group is though, they possess enough sophistication to run a three pronged attack: shutting down electric service, wiping data on the system computers, and coordinating a DDoS attack on internet and phone systems. No one of these three prongs is necessarily a difficult attack. However, the coordination of all three indicates that, without hyper-sophisticated malware, attackers can use a variety of low-sophistication attacks in tandem to produce a high-level result.

The infection most likely, although not confirmed, occurred through Microsoft Word macros. These sorts of attacks are considered “social engineering” attacks, which rely on duping an end-user into installing malware or taking an action they otherwise would not and should not take. This particular kind is simple and insidious. For example, the end-user receives an email from his boss saying to review the attached document ASAP. The email looks legitimate, and not wanting to disappoint the boss, the user opens the attachment. As the Word document opens, it runs a macro that installs the malicious software, unbeknownst to the end-user.

Despite experts’ warnings, attacks on these sorts of systems have been rare and usually done only for specific discrete reasons. However, with the now real threat that these attacks could become more widespread and more frequent, we will have to acknowledge that any device with a computer connected to a system, must be secured and monitored for cyber-attack.

[1] Oddly enough, this is currently a pretty secure way to operate these missiles as the technology is so old that it is impervious to the advancements in cyber attack software. However, once someone does develop an exploit, the whole system will need to change.

Related Article:
Cyber Insecurity: The Dark Web

The Quantum Computer And The Obsolence of Current Encryption

What Is Cyber Security? It Starts With Cryptology

Cyber Insecurity: Ashley Madison Encrypted Passwords Cracked.

Survey Reveals Many Business Executives Lack Cybersecurity Confidence

Top Cybersecurity Threats Unveiled by Hackers – Is Anyone Safe?

Additional information and resources:
Cyber Security And Data Protection Group

Intellectual Property And Technology

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Scarinci Hollenbeck, LLC, LLC

    Related Posts

    See all
    Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs post image

    Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs

    When a family member can no longer make important decisions for themself, the question is often not whether the family will step in, but whether they have the legal authority to do so. A spouse may manage household finances, or an adult child may arrange medical care and pay bills. Still, informal assistance does not […]

    Author: Marc J. Comer

    Link to post with title - "Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs"
    New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments post image

    New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments

    New Jersey residential developers with affordable housing obligations should carefully review their existing approvals, development agreements, and proposed deed restrictions in light of the State’s revised UHAC regulations (Uniform Housing Affordability Controls). The regulations, which took effect on November 6, 2025, significantly change the administration and physical requirements for affordable housing units. For developers with […]

    Author: Wendy Rubinstein Quiroga

    Link to post with title - "New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments"
    “No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy post image

    “No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy

    A “no comment” response is sometimes the right call when a legal problem arises. As a blanket policy, however, it lets allegations go unanswered, deadlines pass, evidence disappear, and manageable disputes grow into expensive litigation. The businesses that fare best are usually the ones that say little publicly while acting decisively behind the scenes. When […]

    Author: Sean M. Pena

    Link to post with title - "“No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy"
    Utility-Scale Battery Storage Projects: A Legal Roadmap for Developers, Property Owners and Other Stakeholders post image

    Utility-Scale Battery Storage Projects: A Legal Roadmap for Developers, Property Owners and Other Stakeholders

    Utility-scale battery energy storage systems (BESS) are becoming an increasingly important component of the electric grid throughout New Jersey, New York, and Pennsylvania. As renewable generation expands, electricity demand increases and grid operators seek greater flexibility, battery storage can help balance supply and demand while providing additional capacity and reliability. For developers, battery storage presents […]

    Author: Nicholas Wall

    Link to post with title - "Utility-Scale Battery Storage Projects: A Legal Roadmap for Developers, Property Owners and Other Stakeholders"
    Navigating Disputes: Hire a Partnership Dispute Lawyer post image

    Navigating Disputes: Hire a Partnership Dispute Lawyer

    A falling out between partners can be disastrous for any business. In many cases, the partnership will not survive. If you are in an unworkable situation with your partners, it may be time to consult a partnership dispute lawyer experienced in handling partnership breakups and dissolutions before the situation deteriorates any further. It is easy […]

    Author: Jay McDaniel

    Link to post with title - "Navigating Disputes: Hire a Partnership Dispute Lawyer"
    Section 363 Sales in Bankruptcy: What Businesses, Lenders, and Buyers Need to Know post image

    Section 363 Sales in Bankruptcy: What Businesses, Lenders, and Buyers Need to Know

    When a company enters Chapter 11 bankruptcy, many assume the process will culminate in a lengthy reorganization plan. However, distressed businesses are increasingly being sold through a different mechanism — a sale under Section 363 of the United States Bankruptcy Code. A Section 363 sale allows a company, as a debtor-in-possession in bankruptcy, to sell […]

    Author: John D. Giampolo

    Link to post with title - "Section 363 Sales in Bankruptcy: What Businesses, Lenders, and Buyers Need to Know"

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Sign up to get the latest from our attorneys!

    Explore What Matters Most to You.

    Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

    Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

    Let`s get in touch!

    * The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
    “If you would like to submit a file, please email it directly to info@sh-law.com.

    Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!