Power Grid
US and European energy sector — Dragonfly 2.0 espionage campaign
2016–2018
United States and Europe (multi-year campaign; no single site)
What happened
A sustained espionage campaign targeted energy-sector companies in the United States and Europe using spear-phishing, watering-hole sites and supply-chain staging targets, building on the earlier Havex/Dragonfly activity. In confirmed cases the actors reached workstations with access to industrial control systems, capturing screenshots of HMI interfaces and reconnaissance on generation and transmission networks, though no disruption was recorded. Related FSB-linked pre-positioning against US and international energy networks continued through roughly 2018–2020 and later produced US indictments. This is a campaign record rather than a single incident; the marker is a country-level reference, not a facility.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Reported / attributed
- Confidence
- Moderate
- Infrastructure
- Power Grid
- Latitude
- 39.8000°
- Longitude
- -98.5000°
Attribution
Attributed to Russian government actors (DHS/FBI alert TA18-074A)
DHS and the FBI formally attributed the campaign to Russian government cyber actors in March 2018. Overlapping activity is tracked as Dragonfly 2.0, Energetic Bear and Berserk Bear.
