Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

The First Successful Cyber Attack on an Electrical Grid

Author: Scarinci Hollenbeck, LLC

Date: January 20, 2016

Key Contacts

Back

Experts have long warned about the exposure of industrial control systems to cyber attack. These systems, like those used in our electrical grid, usually are not regularly updated.

Their failure would cause significant social disruption. They are the soft underbelly of our modern world. For example, Stuxnet exploited a Siemens industrial controller not designed to withstand cyber attack. In another case, original, 1960’s 8 inch, floppy disks control parts of the launch systems for U.S. nuclear missiles.[1] Indeed, most homes still have traditional circuit breakers.

distribution electric substation with power lines and transformers, at sunset

The first known instance of malware causing a disruption in major electrical service took place on December 23, 2015 in Ukraine. At least three regional substations were disconnected from the grid. While not in the U.S., the Ukrainian methods and apparatuses for delivering electricity to the end-user are not significantly different. In all, around 700,000 homes lost power as a result of this attack.

The cyber attack happened when many Ukrainian power stations became infected by the malware package “BlackEnergy.” The package’s original purpose was to spy on various business groups, such as media organizations, power companies, and telecoms. However, the malware used in this attack contained several important upgrades to its functionality—most notably: making the infected machine unbootable, wiping all data on the infected machine, and backdooring a secure shell (SSH) utility, which gave the attackers permanent access to the infected machines. Researchers suspect that the attackers used the SSH to gain access to the systems and shut them down. Meanwhile, the program wiped all the data on the systems, making their recovery much more lengthy and difficult. Finally, the attackers waged denial-of-service attacks (DDoS) on the target’s internet and phones systems to prevent power company personnel from learning about the outages.

The group behind BlackEnergy is known as the “Sandworm Gang.”

In the past, this group has spied on NATO, Eastern European agencies, and European commercial and industrial groups. Research suggests that the group operates from Russia, although confirmation has been slippery, and even if they did operate from Russia, it is not clear who is directing them. Whoever this group is though, they possess enough sophistication to run a three pronged attack: shutting down electric service, wiping data on the system computers, and coordinating a DDoS attack on internet and phone systems. No one of these three prongs is necessarily a difficult attack. However, the coordination of all three indicates that, without hyper-sophisticated malware, attackers can use a variety of low-sophistication attacks in tandem to produce a high-level result.

The infection most likely, although not confirmed, occurred through Microsoft Word macros. These sorts of attacks are considered “social engineering” attacks, which rely on duping an end-user into installing malware or taking an action they otherwise would not and should not take. This particular kind is simple and insidious. For example, the end-user receives an email from his boss saying to review the attached document ASAP. The email looks legitimate, and not wanting to disappoint the boss, the user opens the attachment. As the Word document opens, it runs a macro that installs the malicious software, unbeknownst to the end-user.

Despite experts’ warnings, attacks on these sorts of systems have been rare and usually done only for specific discrete reasons. However, with the now real threat that these attacks could become more widespread and more frequent, we will have to acknowledge that any device with a computer connected to a system, must be secured and monitored for cyber-attack.

[1] Oddly enough, this is currently a pretty secure way to operate these missiles as the technology is so old that it is impervious to the advancements in cyber attack software. However, once someone does develop an exploit, the whole system will need to change.

Related Article:
Cyber Insecurity: The Dark Web

The Quantum Computer And The Obsolence of Current Encryption

What Is Cyber Security? It Starts With Cryptology

Cyber Insecurity: Ashley Madison Encrypted Passwords Cracked.

Survey Reveals Many Business Executives Lack Cybersecurity Confidence

Top Cybersecurity Threats Unveiled by Hackers – Is Anyone Safe?

Additional information and resources:
Cyber Security And Data Protection Group

Intellectual Property And Technology

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Scarinci Hollenbeck, LLC, LLC

    Related Posts

    See all
    How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide post image

    How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide

    Closing your business can be a difficult and challenging task. For corporations, the process includes formal approval of the dissolution, winding up operations, resolving tax liabilities, and filing all required paperwork. Whether you need to understand how to dissolve a corporation in New York or New Jersey, it’s imperative to take all of the proper […]

    Author: Christopher D. Warren

    Link to post with title - "How to Dissolve a Corporation in New Jersey: A Step-by-Step Guide"
    Gross Lease vs. Net Lease: Understanding the Key Differences post image

    Gross Lease vs. Net Lease: Understanding the Key Differences

    Commercial leases can take a variety of forms, which is often confusing for both landlords and tenants. Understanding the different types, especially the gross lease structure, is important when selecting the lease that best suits your needs. One key distinction between lease types is how rent is calculated and paid. This article addresses the two […]

    Author: Robert L. Baker, Jr.

    Link to post with title - "Gross Lease vs. Net Lease: Understanding the Key Differences"
    What to Do If You Are Impacted by a Retailer Bankruptcy Part 2 post image

    What to Do If You Are Impacted by a Retailer Bankruptcy Part 2

    Over the past year, brick-and-mortar stores have closed their doors at a record pace. Fluctuating consumer preferences, the rise of online shopping platforms, and ongoing economic uncertainty continue to put pressure on the retail industry. When a retailer seeks bankruptcy protection, a myriad of other businesses are often impacted. Whether you are a supplier, customer, […]

    Author: Brian D. Spector

    Link to post with title - "What to Do If You Are Impacted by a Retailer Bankruptcy Part 2"
    The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business post image

    The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business

    Since his inauguration two months ago, Donald Trump’s administration and the Congress it controls have indicated important upcoming policy changes. These changes will impact financial services policies and priorities. The changes will particularly affect cryptocurrency, as well as banking rules and regulations. Key Regulatory Changes in Cryptocurrency For example, in the burgeoning cryptocurrency business environment, […]

    Author: Dan Brecher

    Link to post with title - "The Current Administration's Proposals for the Financial Services and Banking Industries Will Affect Your Business"
    Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1 post image

    Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1

    The retail sector has experienced a wave of bankruptcy filings over the last year. Brick-and-mortar businesses in financial distress include big-name brands like Big Lots, Party City, The Container Store, and Vitamin Shoppe. When large retailers seek bankruptcy protection, they are not the only businesses impacted. Landlords can be particularly hard hit. While commercial landlords […]

    Author: Brian D. Spector

    Link to post with title - "Tips for Commercial Landlords Impacted by Wave of Retailer Bankruptcies Part 1"

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Sign up to get the latest from our attorneys!

    Explore What Matters Most to You.

    Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

    Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

    Let`s get in touch!

    * The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form.

    Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!

    Please select a category(s) below: