Home
Home

Energy

Electricity, gas, steam and air conditioning supply

125
cyberattacks and operations

In the Russian-Ukraine war, why do cyberattacks on the Energy sector matter?

The energy sector provides essential services in countries, and cyberattacks against this sector can cause outages or shortages of energy, which also has repercussions on the ability of other sectors to function. Cyberattacks and disruptions of the sector will increase the pressure on the supply of energy in the wider market - which is interconnected regionally and globally - and heightens tensions geopolitically. For example, recent cyberattacks on European energy companies are believed to be linked to the recent imposition of sanctions on Russia. So called hacktivist collectives - acting in the name of activism - are also targeting energy companies by compromising their systems, exfiltrating data and publishing it online.

What types of attacks have been documented against the sector?

Which countries have seen attacks on the sector in the context of the war?

+
-

What impact do these attacks have on people?

The impact of destructive or disruptive cyberattacks on the energy sector are felt across society as a whole. If an attack leads to the downtime of critical infrastructure, this can result in the disruption of access to electricity and gas to thousands of households, public services (e.g. health, transport, education and emergency services), organizations and businesses.

Hack and leak attacks, leading to large volumes of data published online, can have repercussions on individuals whose personal information is exposed, putting them at risk from digital or physical attacks by actors seeking to exploit this information. Hack and leak operations, where information is weaponized and taken out of context to spread disinformation, can also sow distrust in organizations.

You've been the target of a cyberattack?Share details

What are the primary digital impacts observed on the sector by country?

Can history shed light on the impact of attacks on this sector?

23 December 2015 - Energy Distribution Companies, Ukraine

A cyberattack compromised the systems of three energy distribution companies in the Ivano-Frankivsk region of Western Ukraine. The attack marked the first known successful cyberattack against a power grid. Prior to the outage, the threat actors launched a telephone denial-of-service attack against customer call centers.

Societal harm/impact:

  • The attack impacted 16 substations, leaving them unresponsive to any remote commands from operators and led to power outages for approximately 230,000 consumers for 1-6 hours.
  • Customer call center telephone lines were also taken down preventing customers from calling in to report the outage and seek information.
  • The attack was viewed as an attempt to weaken the trust in Ukrainian power companies and / or the government.

Which threat actors have been linked to attacks on the sector during the conflict?

Name
Type
Origin
Number of attacks
NoName057(16)Collective
RU
54
People's CyberArmyCollective
RU
21
AnonymousCollective
Unknown
6
SandwormNation State
RU
5
IT Army of UkraineNation State
UA
4
KillNetCollective
RU
4
GURMONation State
UA
2
XakNetCollective
RU
2
Anonymous ItaliaCollective
Unknown
2
PhoenixCollective
UA
2
APT28Nation State
RU
2
Net Worker AllianceCollective
Unknown
2
DEV-0586Nation State
RU
1
DragonflyNation State
RU
1
Wizard SpiderCybercriminal
RU
1
NB65Collective
Unknown
1
Black BastaCybercriminal
Unknown
1
Anonymous-DepaixPorteurCollective
Unknown
1
Legion Cyber SpetsnazCollective
RU
1
GhostSecCollective
US
1
Team OneFistCollective
UA
1
Anonymous RussiaCollective
RU
1
KelvinSecurityUnknown
Unknown
1
RADISCollective
Unknown
1
Russian ClayCollective
Unknown
1
Netside GroupCollective
Unknown
1
BlueNet RussiaUnknown
Unknown
1
SolntsepekCollective
Unknown
1
Zulik GroupUnknown
Unknown
1
Explore and filter attacks on a mapGeopolitical map

Explore the data

Search anything
Browse the table
1 / 13
Event Name
Event Country
Event Date
Event Type
Impact Category
Impact Description
Threat Actor Name
DDoS attack against the website of a Ukrainian energy company
Ukraine
2023-12-21
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attack against the website of a Ukrainian energy company
Ukraine
2023-12-13
DDoSDisruptionDisrupted connectivity to the website. NoName057(16)
DDoS attack against the website of a Ukrainian gas station operator
Ukraine
2023-11-28
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attack against the website of a Maltese energy company
Malta
2023-10-28
DDoSDisruptionDisrupted connectivity to the website. NoName057(16)
Campaign: DDoS attack against the subdomain of an Estonian energy company
Estonia
2023-10-27
DDoSDisruptionDisrupted connectivity to the website.Zulik Group
DDoS attacks against three subdomains of a Ukrainian energy exchange company
Ukraine
2023-10-20
DDoSDisruptionDisrupted connectivity to the websites.People's CyberArmy
DDoS attack against the website of a Ukrainian gas supplier company
Ukraine
2023-10-19
DDoSDisruptionDisrupted connectivity to the website.People's CyberArmy
DDoS attack against the website of a Moldovan enterprise operating in the energy sector
Moldova
2023-09-25
DDoSDisruptionDisrupted connectivity to the website.People's CyberArmy
Camapaign: DDoS attack against the websites of four Moldovan companies operating in the energy sector
Moldova
2023-09-25
DDoSDisruptionDisrupted connectivity to the website.Net Worker Alliance
Campaign: DDoS attack against the website of a Moldovan gas station company
Moldova
2023-09-24
DDoSDisruptionDisrupted connectivity to the website.Net Worker Alliance
Donate