Russian spies behind cyberattack on Ukrainian power grid in 2022 - researchers


  • World
  • Thursday, 09 Nov 2023

FILE PHOTO: A hooded man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017. REUTERS/Kacper Pempel/Illustration/File Photo

LONDON (Reuters) - Russian cyber spies were behind a hack which disrupted part of Ukraine's power grid in late 2022, U.S. cybersecurity firm Mandiant, part of Google, said in a report on Thursday, in a rare and advanced form of cyberwarfare.

Successful hacks against industrial control systems are relatively unique, with Russia one of the few countries with the capabilities to carry out such cyberattacks.

“This attack represents the latest evolution in Russia’s cyber physical attack capability, which has been increasingly visible since Russia’s invasion of Ukraine,” said the report, which did not identify the specific facility against which the attack had been carried out.

Last October, a massive wave of Russian missile strikes on Ukraine's power network caused blackouts in many parts of the country, prompting Kyiv to halt electricity exports and leaving four regions temporarily without electricity.

The hacking group, known in cybersecurity research circles by the moniker “Sandworm”, was able to cause a power cut in an unidentified area of Ukraine by tripping circuit breakers at an electrical substation at the same time as the missile strike, the report said. The group then deployed data-wiping malware in a bid to cover their tracks, the report added.

Sandworm has been previously identified as a cyberwarfare unit of Russia’s GRU military intelligence agency.

Russia’s foreign ministry did not respond to a request for comment. The GRU could not be reached for comment. Ukraine’s foreign ministry and its SBU intelligence agency did not provide comment.

Sandworm hackers rose to prominence in 2015 after a separate cyberattack against Ukraine’s power grid which cut off power for around 255,000 people. The disruptive, digital, intrusion was widely considered to be one of the first, known, successful cyberattacks against a power network.

“There have only been a handful of incidents similar to this, with the majority carried out by Sandworm,” Mandiant analyst Nathan Brubaker said.

(Reporting by James Pearson in London; Additional reporting by Christopher Bing in Washington; Editing by Sharon Singleton)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In World

German president dissolves parliament to pave way for Feb. 23 snap elections
Azerbaijan Airlines flight to Russia turns back to Baku after airspace closure, TASS says
At least 69 migrants dead after boat sank off Morocco on Dec. 19, Mali says
South Korea parliament majority votes to impeach acting president Han
Putin says Slovakia could host peace talks with Ukraine
Malaysians thought to be involved in fatal bus crash in Norway
South Korea's parliament impeaches acting president Han, as Yoon goes on trial
S. Korea's spy agency confirms an injured N. Korean soldier in custody, Yonhap reports
Richard Parsons, American media and finance troubleshooter, dies at 76
Two sailors killed during Australian yacht race

Others Also Read