How the 2015 Ukraine power grid hack worked: stolen logins, no second factor
The first confirmed cyberattack to black out a power grid did not rely on exotic tricks at the moment it struck: the attackers logged in to the utilities' own control systems with real usernames and passwords and flipped the switches themselves.[1][2] This case file covers how the December 2015 Ukraine blackout was set up months in advance, how crews got the lights back on, and the one control that would have locked the attackers out.
What happened
The groundwork started more than 6 months before the blackout. Employees at Ukrainian electricity companies received emails that looked like they came from people they knew, carrying Word and Excel attachments. Opening them and enabling macros installed a backdoor on the business network.[2][3]
From that foothold, the attackers collected valid user credentials, raised their privileges and moved through the office networks until they could reach the systems that control the grid.[3] Among what they gathered were the logins for the utilities' virtual private networks, the encrypted tunnels staff used to work on the control network from outside.[1]
On the afternoon of December 23, 2015, during the holiday season when control rooms had lighter staffing, they struck 3 regional distribution companies within about 30 minutes of each other.[1][4] Operators watched as breakers were opened remotely. Around 30 substations were taken offline and about 225,000 customers lost power.[2][3]
How they got in
The decisive step was simple. With stolen VPN credentials in hand, the attackers connected to the industrial control network from outside and used the operators' own control software to open circuit breakers.[1] The utilities' VPN connections asked only for a username and password, with no second factor such as a one-time code.[1][2] To the system, the intruders looked like employees.
The attackers also worked to slow the recovery. They turned off backup power supplies at control centers, loaded bad firmware onto devices that linked control rooms to substations so remote commands would no longer work, and ran a wiping program that erased computers and logs.[1][3] At the same time, a flood of calls tied up customer phone lines so people could not report outages.[1][2]
How it was caught and what it cost
There was nothing subtle to catch: the lights went out in front of the operators. Because the remote controls had been sabotaged, crews had to drive to substations and switch equipment back on by hand.[1] Power returned after roughly 1 to 6 hours, depending on the area.[4] The damaged control devices and wiped computers took far longer to replace.
An industry analysis afterward pointed to gaps that let the attack succeed: no two-factor login on VPNs, weak credential management, little separation between office and control networks, and no monitoring that would have spotted months of intruders moving around.[1][2]
On October 15, 2020, the U.S. Justice Department charged 6 officers of Russia's military intelligence agency, the GRU, with 7 counts each. The indictment covers destructive attacks on Ukraine's electric grid, its Ministry of Finance and its State Treasury Service between December 2015 and December 2016, among other attacks. The DOJ attributed the campaign to GRU Unit 74455. The officers have not been tried and are presumed innocent.[5]
The missing control
The missing control: a second login factor on every remote connection into the control network.
The phishing emails, the months of spying and the wiper all mattered, but the moment the lights went out depended on the attackers connecting from outside as trusted staff. Two-factor authentication means a stolen password alone is not enough; the login also needs a code or device the real employee holds.[3] The attackers would have had a pile of credentials and no way to use them on the grid. Separating the office network from the control network, and watching for strange logins, would have given defenders further chances to stop it.
What to do in your business
- Put two-factor on every remote door. VPN, remote desktop, email and any cloud admin page should require a code or app prompt, not just a password.
- Separate what runs the business from everyday office use. Keep point-of-sale, security cameras, building controls and equipment off the same network as email and web browsing.
- Treat macro prompts as a warning. Tell staff never to enable macros in an emailed document, and block macros from the internet in Office settings where you can.
- Know how to run by hand. Write down how you would open, take payments and serve customers if your computers went dark for a day.
- Keep a second way to reach customers. If your main phone line or website is flooded or down, have a backup number, text list or social account ready.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Dark Reading: Lessons from the Ukraine electric grid hack
- eWeek: Hackers infiltrated Ukrainian power grid months before cyber-attack
- George Mason University Center for Infrastructure Protection: Lessons learned from the power outage in Ukraine
- Wikipedia: 2015 Ukraine power grid hack
- U.S. Department of Justice: Six Russian GRU officers charged in connection with worldwide deployment of destructive malware