Hackers likely caused a Dec. 23 electricity outage in Ukraine by remotely switching breakers to cut power, after installing malware to prevent technicians from detecting the attack, a report analyzing how the incident unfolded said.
The report from Washington-based SANS ICS was released late on Saturday, providing the first detailed analysis of what caused a six-hour outage for about 80,000 customers of Western Ukraine’s Prykarpattyaoblenergo utility.
SANS ICS, which advises infrastructure operators on combating cyberattacks, also said the attackers crippled the utility’s customer-service center by flooding it with telephone calls to prevent customers from alerting the utility that power was down.
“This was a multi-pronged attack against multiple facilities. It was highly coordinated with very professional logistics,” said Robert Lee, a former US air force cyberwarfare operations officer, who helped compile the report for SANS ICS.
“They sort of blinded them in every way possible,” Lee added.
Experts have widely described the incident as the first known power outage caused by a cyberattack.
Ukraine’s SBU state security service blamed Russia, and US cyberfirm iSight Partners identified the perpetrator as a Russian hacking group known as “Sandworm.”
The Ukrainian Ministry of Fuel and Energy said it would hold off on discussing the matter until after Jan. 18, following completion of a formal probe into the matter.
The utility’s operators were able to quickly recover by switching to manual operations, essentially disconnecting infected workstations and servers from the grid, the report said.
SANS ICS said on its blog it had “high confidence” in its findings, which were based on discussions and analysis from “multiple international community members and companies.” The report’s authors declined to identify those sources.
US critical infrastructure security expert Joe Weiss said he believed the report’s findings would be validated.
“They did a phenomenal job,” Weiss said.
There is strong interest in the outage because of concerns that similar techniques could be used to launch more attacks on power operators internationally.
“What is now true is that a coordinated cyberattack consisting of multiple elements is one of the expected hazards [electric utilities] may face,” SANS ICS director Michael Assante said in a blog.
“We need to learn and prepare ourselves to detect, respond and restore from such events in the future,” said Assante, former chief security officer of the quasi-governmental North American Electric Reliability Corp.
Nearly half of China’s major cities are suffering “moderate to severe” levels of subsidence, putting millions of people at risk of flooding, especially as sea levels rise, according to a study of nationwide satellite data released yesterday. The authors of the paper, published by the journal Science, found that 45 percent of China’s urban land was sinking faster than 3mm per year, with 16 percent at more than 10mm per year, driven not only by declining water tables, but also the sheer weight of the built environment. With China’s urban population already in excess of 900 million people, “even a small portion
UNSETTLING IMAGES: The scene took place in front of TV crews covering the Trump trial, with a CNN anchor calling it an ‘emotional and unbelievably disturbing moment’ A man who doused himself in an accelerant and set himself on fire outside the courthouse where former US president Donald Trump is on trial has died, police said yesterday. The New York City Police Department (NYPD) said the man was declared dead by staff at an area hospital. The man was in Collect Pond Park at about 1:30pm on Friday when he took out pamphlets espousing conspiracy theories, tossed them around, then doused himself in an accelerant and set himself on fire, officials and witnesses said. A large number of police officers were nearby when it happened. Some officers and bystanders rushed
HYPOCRISY? The Chinese Ministry of Foreign Affairs yesterday asked whether Biden was talking about China or the US when he used the word ‘xenophobic’ US President Joe Biden on Wednesday called for a hike in steel tariffs on China, accusing Beijing of cheating as he spoke at a campaign event in Pennsylvania. Biden accused China of xenophobia, too, in a speech to union members in Pittsburgh. “They’re not competing, they’re cheating. They’re cheating and we’ve seen the damage here in America,” Biden said. Chinese steel companies “don’t need to worry about making a profit because the Chinese government is subsidizing them so heavily,” he said. Biden said he had called for the US Trade Representative to triple the tariff rates for Chinese steel and aluminum if Beijing was
Beijing is continuing to commit genocide and crimes against humanity against Uyghurs and other Muslim minorities in its western Xinjiang province, U.S. Secretary of State Antony Blinken said in a report published on Monday, ahead of his planned visit to China this week. The State Department’s annual human rights report, which documents abuses recorded all over the world during the previous calendar year, repeated language from previous years on the treatment of Muslims in Xinjiang, but the publication raises the issue ahead of delicate talks, including on the war in Ukraine and global trade, between the top U.S. diplomat and Chinese