Case file · UKRAINE GRID 2015

How the 2015 Ukraine power grid hack worked: stolen logins, no second factor

Published 2026-09-29 · 5 min read · Missing control: Two-factor login on remote access

The first confirmed cyberattack to black out a power grid did not rely on exotic tricks at the moment it struck: the attackers logged in to the utilities' own control systems with real usernames and passwords and flipped the switches themselves.[1][2] This case file covers how the December 2015 Ukraine blackout was set up months in advance, how crews got the lights back on, and the one control that would have locked the attackers out.

What happened

The groundwork started more than 6 months before the blackout. Employees at Ukrainian electricity companies received emails that looked like they came from people they knew, carrying Word and Excel attachments. Opening them and enabling macros installed a backdoor on the business network.[2][3]

From that foothold, the attackers collected valid user credentials, raised their privileges and moved through the office networks until they could reach the systems that control the grid.[3] Among what they gathered were the logins for the utilities' virtual private networks, the encrypted tunnels staff used to work on the control network from outside.[1]

On the afternoon of December 23, 2015, during the holiday season when control rooms had lighter staffing, they struck 3 regional distribution companies within about 30 minutes of each other.[1][4] Operators watched as breakers were opened remotely. Around 30 substations were taken offline and about 225,000 customers lost power.[2][3]

How they got in

The decisive step was simple. With stolen VPN credentials in hand, the attackers connected to the industrial control network from outside and used the operators' own control software to open circuit breakers.[1] The utilities' VPN connections asked only for a username and password, with no second factor such as a one-time code.[1][2] To the system, the intruders looked like employees.

The attackers also worked to slow the recovery. They turned off backup power supplies at control centers, loaded bad firmware onto devices that linked control rooms to substations so remote commands would no longer work, and ran a wiping program that erased computers and logs.[1][3] At the same time, a flood of calls tied up customer phone lines so people could not report outages.[1][2]

How it was caught and what it cost

There was nothing subtle to catch: the lights went out in front of the operators. Because the remote controls had been sabotaged, crews had to drive to substations and switch equipment back on by hand.[1] Power returned after roughly 1 to 6 hours, depending on the area.[4] The damaged control devices and wiped computers took far longer to replace.

An industry analysis afterward pointed to gaps that let the attack succeed: no two-factor login on VPNs, weak credential management, little separation between office and control networks, and no monitoring that would have spotted months of intruders moving around.[1][2]

On October 15, 2020, the U.S. Justice Department charged 6 officers of Russia's military intelligence agency, the GRU, with 7 counts each. The indictment covers destructive attacks on Ukraine's electric grid, its Ministry of Finance and its State Treasury Service between December 2015 and December 2016, among other attacks. The DOJ attributed the campaign to GRU Unit 74455. The officers have not been tried and are presumed innocent.[5]

The missing control

The missing control: a second login factor on every remote connection into the control network.

The phishing emails, the months of spying and the wiper all mattered, but the moment the lights went out depended on the attackers connecting from outside as trusted staff. Two-factor authentication means a stolen password alone is not enough; the login also needs a code or device the real employee holds.[3] The attackers would have had a pile of credentials and no way to use them on the grid. Separating the office network from the control network, and watching for strange logins, would have given defenders further chances to stop it.

What to do in your business

Watch the case
The hackers who switched off Ukraine's lightsDrops 2026-11-07
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Dark Reading: Lessons from the Ukraine electric grid hack
  2. eWeek: Hackers infiltrated Ukrainian power grid months before cyber-attack
  3. George Mason University Center for Infrastructure Protection: Lessons learned from the power outage in Ukraine
  4. Wikipedia: 2015 Ukraine power grid hack
  5. U.S. Department of Justice: Six Russian GRU officers charged in connection with worldwide deployment of destructive malware