{"id":11642,"date":"2017-01-29T14:28:13","date_gmt":"2017-01-29T14:28:13","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2017\/01\/29\/how-a-power-grid-got-hacked\/"},"modified":"2026-08-08T17:29:37","modified_gmt":"2026-08-08T17:29:37","slug":"how-a-power-grid-got-hacked","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","title":{"rendered":"Hackers&#8217; methods feel familiar in Ukraine power grid cyberattack"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The temperature measured about 30 degrees Fahrenheit \u2013 with passing clouds, snow showers and a light breeze out of the west \u2013 just before midnight in Kiev, Ukraine, when the power went out.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At 11:53 p.m. local time on Dec. 17, 2016, remote terminal units (RTUs) used to monitor and control circuit breakers in Pivnichna (North) electrical substation went offline unexpectedly.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The North substation, a 330-kV transmission stepdown located just outside the city, serves Kiev&#8217;s power distribution system. If the substation experienced a service disruption, it <a href=\"https:\/\/ics.sans.org\/blog\/2016\/12\/20\/how-do-you-say-ground-hog-day-in-ukrainian\" target=\"_blank\">could cause<\/a> cascading blackouts throughout the city and potentially beyond.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As it happened, the RTUs&#8217; failure resulted in <a href=\"https:\/\/www.facebook.com\/permalink.php?story_fbid=1798082313797621&amp;id=100007876094707\" target=\"_blank\">power losses<\/a> in the northern right bank section of Kiev. By 1:05 a.m. on Dec. 18, the power was restored.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ukrenergo&#8217;s engineers were perplexed by the potential cause of the incident. Engineers might assume equipment failure had this happened anywhere else in the world. But this is Ukraine.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Dec. 17-18 incident eerily resembled another from one year before \u2013 nearly to the day.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That incident, which affected three regional electricity companies on Dec. 23, 2015, resulted in power outages to <a href=\"https:\/\/ics.sans.org\/media\/E-ISAC_SANS_Ukraine_DUC_5.pdf\" target=\"_blank\">225,000 customers<\/a> and was the first known time a cyberattack caused blackouts in a country&#8217;s power grid.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ukrenergo&#8217;s engineers had to consider equipment failure but also the possibility of another cyberattack.\n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A Tale of Two Cyberattacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The December 2016 incident occurred amid a flurry of <a href=\"http:\/\/www.darkreading.com\/attacks-breaches\/ukraine-suffered-6500-cyberattacks-in-two-months-president-says\/d\/d-id\/1327824\" target=\"_blank\">6,500 cyberattacks over two months<\/a>, according to Ukraine&#8217;s President Petro Poroshenko. Poroshenko said the attacks indicated Russian &#8220;<a href=\"http:\/\/www.reuters.com\/article\/us-ukraine-crisis-cyber-idUSKBN14I1QC\" target=\"_blank\">cyberwar<\/a>.&#8221;\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Investigators and journalists have reported on key similarities and differences between the 2015 and 2016 cyberattacks, which include:\n<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Similarity: BlackEnergy malware and KillDisk, a data deletion program, were used in both attacks. Importantly, experts said these tools did not cause the power outages in 2015 because they lack the necessary functionality. Hackers\u0092 \u0093direct interaction\u0094 with control systems caused the blackouts.<\/li><li>Difference: In 2015, hackers attacked multiple distribution substations (seven 110 kV and twenty-three 35 kV). In 2016, hackers attacked a single transmission substation.<\/li><li>Similarity: In both incidents, hackers targeted substation components called RTUs.<\/li><li>Difference: Booz Allen Hamilton researchers said the 2015 hackers used malicious firmware to permanently disable the RTUs after opening breakers and then used KillDisk to damage operators\u0092 terminals, which prevented remote repair of the RTUs. In 2016, the hackers merely deactivated the RTUs, which made restoration \u0093easier,\u0094 investigators said.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Common Attack Vector: Remote Terminal Units<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">RTUs are electronic devices that link sensors and actuators on physical objects to industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. ICS\/SCADA systems allow engineers in centralized locations to monitor and control distributed assets. RTUs, which are similar to programmable logic controllers (PLCs), are key components of ICS\/SCADA systems.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dale Peterson, Founder and CEO of Digital Bond, an ICS\/SCADA cybersecurity consulting firm, explained, &#8220;A RTU passes commands from an operator in a control room to numerous actuators that perform control functions and sensors that monitor system status at a physical site, such as a substation. Many RTUs today can run programs or logic, so the difference between a RTU and PLC can be minimal.&#8221;\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RTU and PLC use is common and even necessary in almost any control system, from the power grid and public transit to building automation systems. This is significant, Peterson said, because, &#8220;Until recently, just the past year, these devices were &#8216;insecure by design.&#8217; We used to say, &#8216;access equals control.&#8217; If you had access [to the RTU], you didn&#8217;t have to hack it by exploiting a vulnerability. You could do anything you wanted using documented features and functions.&#8221;\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Peterson said more secure RTUs are coming to market and he&#8217;s watching whether companies will upgrade old devices.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Ukraine 2015 highlighted the easiest way to compromise these systems: Vulnerability from remote access,&#8221; Peterson said. &#8220;Once you&#8217;re on the system, attackers are limited only by their engineering and automation capability.&#8221;\n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Anatomy of an Attack<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Over the past year, security researchers have pieced together how the 2015 incident unfolded. Initial research on the 2016 incident provides fresh information. It&#8217;s unknown if the same hackers carried out both cyberattacks. Using public reports on the cyberattacks, it&#8217;s possible to reconstruct how hackers likely worked.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just as many professionals employ &#8220;best practices,&#8221; so too do elite hackers. Experts call this the cyber kill chain. Michael Assante and Robert M. Lee of the SysAdmin, Audit, Networking and Security (SANS) Institute have developed the <a href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/ICS\/industrial-control-system-cyber-kill-chain-36297\" target=\"_blank\">ICS Kill Chain<\/a>.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following narrative, which uses the ICS Kill Chain as a framework and incorporates facts and findings currently known about the 2015 and 2016 attacks, provides a hypothetical account.\n<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Planning  Oleksii Yasynskyi, head of ISSP Labs and an investigator hired by Ukrenergo, told the BBC that multiple groups were involved in the 2016 attack.\r The hackers\u0092 first step would have been to gather information about Ukrenergo. Information of interest falls into several categories:\r People: Hackers would have identified employees who hold key positions within and knowledge about Ukrenergo, such as system administrators and engineers. Hackers also would have identified target victims. Detailed information could have been gathered online, such as from social media sites.\r Enterprise IT environment: Hackers would have gathered information such as devices, operating systems and business applications used throughout Ukrenergo, which can be gleaned by, for instance, looking at employee LinkedIn job descriptions and skill sets. Particularly valuable would be IT credentials, account details, weak passwords and organizational processes\/procedures. Hackers could have found some of this accidentally published online or it could have been guessed or cracked with relative ease.  Critical infrastructure environment: Hackers could have started learning about their ultimate targets by using the Shodan search engine to find Ukrenergo infrastructure exposed to the public internet. Vendors\u0092 technical manuals and marketing collateral are valuable. Detailed information on the RTUs and ICS targeted in the 2015 attack was readily available online, according to SANS. <\/li><\/ol>\n\n\n\n<ol class=\"wp-block-list\"><li>Preparation\r  Preparing can include weaponization and targeting.Details on these aspects of the 2016 attack are still sparse. In 2015, hackers weaponized Microsoft Word files with malicious macros. Hackers probably customized attacks to targeted victims, such as recipients of spear-phishing emails.<\/li><li>Cyber Intrusion\r  Next, the hackers would have gained access to Ukrenergo\u0092s network.Investigators have not yet revealed the initial attack vector for the 2016 incident. Yasynskyi told the BBC the 2015 and 2016 cyberattacks are \u0093not much different,\u0094 except the 2016 hack was \u0093more complex\u0094 and \u0093better organized.\u0094\r Marina Krotofil, lead cybersecurity researcher at Honeywell, and Yasynskyi presented initial findings of the 2016 investigation at the S4x17 Conference on Jan. 10. They said the hackers used clever coding techniques to obfuscate methods and evade signature-based attack detection. The hackers also used macros to detect security technologies in Ukrenergo\u0092s environment, including intrusion prevention systems and sandboxes.\r The 2015 incident began with a spear-phishing email. Notably, security researchers wrote that no custom exploit code was used in the 2015 intrusions. Hackers gained access using native functionality in Microsoft Word (i.e., macros) to download BlackEnergy 3.<\/li><\/ol>\n\n\n\n<ol class=\"wp-block-list\"><li>Management and Enablement\r  Again, details on the 2016 attack are not yet public, but investigators said the tools and methods were similar to 2015.If the 2016 attack was conducted like the 2015 attack, BlackEnergy malware downloaded to a victim\u0092s computer via spear phishing would have \u0093called back\u0094 to the hackers\u0092 remote command and control (C2) infrastructure. The C2 infrastructure would have allowed hackers to extract data from Ukrenergo\u0092s network, download additional tools onto Ukrenergo\u0092s network and issue commands remotely to compromised Ukrenergo systems.<\/li><li>Sustainment, Entrenchment, Development and Execution\r  With C2 established, hackers most likely would have created multiple back doors into Ukrenergo\u0092s network to allow ongoing access.Next, hackers would have begun to harvest administrator credentials for Ukrenergo\u0092s IT infrastructure. In the 2015 attack, hackers installed additional BlackEnergy plugins. This would have allowed hackers to map Ukrenergo\u0092s internal networks and to move laterally across systems and subnets.\r Failure to catch hackers early in an intrusion can be costly. According to a 2016 report by cybersecurity firm Mandiant, hackers remained on victim networks in 2015 a median of 146 days prior to discovery. No one immediately noticed the hackers\u0092 network presence in the 2015 or 2016 Ukraine attacks.\r In the 2015 attack, hackers spent months exploring IT environments, eventually finding and accessing the virtual private network, which lacked two-factor authentication and along with a misconfigured firewall, allowed hackers entry into and ongoing access to the ICS\/SCADA system network.\r Investigators told Motherboard the 2016 hackers remained on Ukrenergo\u0092s network for months, gathering system logs, monitoring network traffic and studying the behavior of system administrators.\r In both incidents, hackers skillfully hid their network presence. Investigators said the 2016 hackers \u0093lived off the land,\u0094 a technique whereby intruders use the same credentials and tools as system administrators to avoid detection.\r In the S4x17 Conference presentation, Krotofil stressed the importance of early detection, warning, \u0093It is critical to detect malicious invasion at early stages. Discovering KillDisk in your network is already too late. The attackers already hav[e] a very reliable, distributed foothold in your network. Cleanup\/eradication is almost impossible.\u0094<\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Were These Cyberattacks Merely a Prelude?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers investigating the 2016 attack have alluded to an ominous trend, suggesting it was merely &#8220;<a href=\"https:\/\/motherboard.vice.com\/read\/ukrainian-power-station-hacking-december-2016-report?trk_source=homepage-lede\" target=\"_blank\">training<\/a>.&#8221;\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In early January 2017, as investigators were piecing together the 2016 incident, Russian cybersecurity firm Kaspersky Lab ICS-CERT reported a then-ongoing &#8220;<a href=\"https:\/\/ics-cert.kaspersky.com\/2016\/12\/16\/spear-phishing-attack-hits-industrial-companies\/\" target=\"_blank\">targeted attack<\/a>&#8221; against 500 organizations in 50 countries. Kaspersky wrote:\n<\/p>\n\n\n\n\n\n<p class=\"wp-block-paragraph\">Investigators said the cyberattack against Ukrenergo began in summer 2016. Kaspersky said the spear-phishing campaign began in August 2016. To date, no publicly available evidence links the campaigns, threat actors or attack signatures.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to cybersecurity firm FireEye, as of mid-2016, <a href=\"https:\/\/www2.fireeye.com\/rs\/848-DID-242\/images\/ics-vulnerability-trend-report-final.pdf\" target=\"_blank\">33 percent<\/a> of 1,552 publicly disclosed ICS vulnerabilities had no available security patch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.<\/p>\n","protected":false},"author":7,"featured_media":32487,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":29,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[106,31,33],"tags":[],"coauthors":[503],"class_list":["post-11642","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters"],"acf":{"subheadline":"","legacy_arc_id":"QW3TSK4ATVECDCKAUFMFWHJ65U","arc_canonical_url":"\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Hackers&#039; methods feel familiar in Ukraine power grid cyberattack - Federal Times<\/title>\n<meta name=\"description\" content=\"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers&#039; methods feel familiar in Ukraine power grid cyberattack\" \/>\n<meta property=\"og:description\" content=\"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-29T14:28:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T17:29:37+00:00\" \/>\n<meta name=\"author\" content=\"Brad D. Williams\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Brad D. Williams\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Hackers&#8217; methods feel familiar in Ukraine power grid cyberattack\",\n\t            \"datePublished\": \"2017-01-29T14:28:13+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:29:37+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/\"\n\t            },\n\t            \"wordCount\": 1582,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-466919703.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/\",\n\t            \"name\": \"Hackers' methods feel familiar in Ukraine power grid cyberattack - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-466919703.jpg.jpg\",\n\t            \"datePublished\": \"2017-01-29T14:28:13+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:29:37+00:00\",\n\t            \"description\": \"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-466919703.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-466919703.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/home\\\/2017\\\/01\\\/29\\\/how-a-power-grid-got-hacked\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Gallery\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/gallery\\\/\",\n\t                    \"ad_zone\": \"gallery\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Hackers&#8217; methods feel familiar in Ukraine power grid cyberattack\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hackers' methods feel familiar in Ukraine power grid cyberattack - Federal Times","description":"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","og_locale":"en_US","og_type":"article","og_title":"Hackers' methods feel familiar in Ukraine power grid cyberattack","og_description":"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","og_site_name":"Federal Times","article_published_time":"2017-01-29T14:28:13+00:00","article_modified_time":"2026-08-08T17:29:37+00:00","author":"Brad D. Williams","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Brad D. Williams","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Hackers&#8217; methods feel familiar in Ukraine power grid cyberattack","datePublished":"2017-01-29T14:28:13+00:00","dateModified":"2026-08-08T17:29:37+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/"},"wordCount":1582,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-466919703.jpg.jpg","articleSection":["Daily Brief","Home","Newsletters"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/","name":"Hackers' methods feel familiar in Ukraine power grid cyberattack - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-466919703.jpg.jpg","datePublished":"2017-01-29T14:28:13+00:00","dateModified":"2026-08-08T17:29:37+00:00","description":"The temperature measured about 30 degrees Fahrenheit \u0096 with passing clouds, snow showers and a light breeze out of the west \u0096 just before midnight in Kiev, Ukraine, when the power went out.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-466919703.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-466919703.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/home\/2017\/01\/29\/how-a-power-grid-got-hacked\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Gallery","item":"https:\/\/one.sightlinemg.com\/federaltimes\/gallery\/","ad_zone":"gallery"},{"@type":"ListItem","position":3,"name":"Hackers&#8217; methods feel familiar in Ukraine power grid cyberattack"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-466919703.jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/11642","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=11642"}],"version-history":[{"count":3,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/11642\/revisions"}],"predecessor-version":[{"id":39603,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/11642\/revisions\/39603"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/32487"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=11642"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=11642"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=11642"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=11642"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}