Power Grid

Kyiv Pivnichna substation — Industroyer/CrashOverride grid attack

17 December 2016

Kyiv region, Ukraine

What happened

Custom malware known as Industroyer (also CrashOverride) opened circuit breakers at the Pivnichna 330 kV transmission substation outside Kyiv, cutting power to a portion of the capital — roughly one-fifth of the city by some accounts — for about an hour before operators restored supply manually. It was the first known malware purpose-built to disrupt electric grid operations, speaking industrial protocols including IEC-101, IEC-104 and IEC-61850 directly to substation equipment. ESET called it the biggest threat to industrial control systems since Stuxnet. The marker is placed at the substation; coordinates are approximate.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
50.6150°
Longitude
30.4350°

Attribution

Attributed to Sandworm (Russian military intelligence)

ESET analyzed the malware; the US later indicted GRU Unit 74455 (Sandworm) officers for the 2015 and 2016 Ukraine grid attacks.

Sources

  1. Industroyer: Biggest threat to industrial control systems since StuxnetESET WeLiveSecurity · Incident reporting