Ukrainian electric utilities suffered a coordinated cyberattack that caused power outages for civilians, marking one of the clearest cases of a cyber operation producing a real-world disruption of critical infrastructure. Reporting from iSIGHT Partners and SANS ICS assessed with high confidence that the outage was intentional and attributed the intrusion to Sandworm Team, citing the presence of BlackEnergy 3 malware in affected environments and the use of the destructive component KillDisk during the operation.
U.S. government industrial control system alerts later documented the incident as a cyberattack against Ukrainian critical infrastructure and tied it to a broader, ongoing malware campaign targeting ICS environments. The reporting said KillDisk may have been used less to trigger the outage than to hinder restoration and operator visibility after the attack, while flooding utility call centers with phone traffic likely complicated response efforts; the incident also fit Sandworm’s wider pattern of targeting Ukrainian entities, regional power organizations, and other government and media networks while showing sustained interest in SCADA and industrial control systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
CISA republished Update E of its alert on an ongoing sophisticated malware campaign compromising industrial control systems, preserving related historical reporting in its archive. The referenced campaign provides context for Sandworm's earlier ICS-focused activity.
CISA republished the historical incident response alert covering the cyberattack against Ukrainian critical infrastructure as part of its advisory archive. This was a republication of earlier government reporting rather than a new incident.
US-CERT/CISA published an incident response alert documenting the cyberattack against Ukrainian critical infrastructure. The alert formalized U.S. government reporting on the incident.
iSIGHT Partners and SANS ICS assessed with high confidence that the 2015 Ukrainian power outages were caused by a coordinated cyberattack and attributed the incident to Sandworm Team. The assessment framed the event as a milestone in cyber operations affecting civilian critical infrastructure.
Investigators found BlackEnergy 3 malware and related KillDisk destructive malware in environments affected by the Ukrainian power outage. Analysts assessed KillDisk may have been used to hinder restoration or operator visibility rather than directly cause the outage.
In 2015, Ukrainian power utilities suffered a coordinated, intentional cyberattack that caused power outages affecting civilians. The incident also involved phone flooding against utility support lines, which likely complicated response efforts.
Public reporting identified Sandworm Team's use of CVE-2014-4114 and highlighted the group's interest in industrial control systems. These findings became part of the attribution context for later attacks on Ukrainian critical infrastructure.
Before the 2015 outage, Sandworm Team had already been reported targeting Ukrainian organizations as well as EU, NATO, media, and regional power entities, including reconnaissance against SCADA and other critical infrastructure systems. This activity established the broader campaign context later tied to the power-sector incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
ics-cert.us-cert.gov
Open sourceus-cert.cisa.gov
Open sourcecisa.gov
Open sourceics-cert.us-cert.gov
Open sourcetheregister.co.uk
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.