Power Grid

sPower wind and solar fleet — firewall denial-of-service

5 March 2019

United States (control center in Salt Lake City, Utah)

What happened

An attacker exploited a known, unpatched vulnerability in internet-facing Cisco firewalls at renewables operator sPower, forcing repeated reboots that cut communications between the control center and about a dozen wind and solar generation sites totalling roughly 500 MW. Interruptions lasted under five minutes each across about 12 hours. No generation was lost and no attribution was made, but Department of Energy records make it the first cyber event confirmed to have interrupted US electrical-system operations, and it exposed how exposed distributed renewable fleets can be. The marker is placed at the operator's Salt Lake City control center.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
40.7610°
Longitude
-111.8910°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. Cisco Firewall Exploited in Attack on U.S. Renewable Energy FirmSecurityWeek · Incident reporting