Case Study - Industrial Control System (ICS) Cyberattack

Ukraine Power Grid Attack

Year – 2015

Estimated Economic Losses – No authoritative total financial loss figure publicly established

Systems Affected – Approximately 225,000 Customers

Type of Attack – Critical Infrastructure Cyberattack | ICS/SCADA Attack

Suspected Group / Organization – Associated with the Sandworm Group and attributed to Russian state-sponsored cyber actors

Detailed Working
Attackers used spear-phishing emails and malicious attachments to gain initial access to Ukrainian power distribution companies. After infiltrating the networks, they stole credentials, moved laterally, accessed operational control systems, and remotely opened circuit breakers at electrical substations, causing widespread power outages.

Forensic Investigations
Investigators used malware analysis, network traffic examination, system log analysis, and ICS/SCADA forensics to reconstruct the attack. The investigation identified Black Energy malware, compromised credentials, unauthorized remote access, malicious activity within operational networks, and destructive KillDisk malware, while threat intelligence and infrastructure analysis contributed to the attack’s attribution.

+91-7087055115

Subscribe Now.

No content is added yet.