IT experts say Ukraine blackout caused by a cyberattack

Image
AFP Kiev
Last Updated : Jan 06 2016 | 12:57 AM IST
A power failure that plunged parts of western Ukraine into the dark last month was caused by a cyberattack, IT experts said today, and one source called it a world first.
The blackout, which hit a large part of the western region of Ivano-Frankivsk on December 23, was due to a computer virus, they said.
The local electricity company, Prikarpattiaoblenergo, said at the time that the breakdown was caused by "the intervention of unauthorised persons ... In the remote access system" and its technicians had had to restore power manually.
But Ukraine's SBU security service later said it found malware -- programmes designed to take over or damage systems -- on the networks of several regional electricity companies.
"A virus which we've never seen before was detected... It causes damage. The automated systems stopped functioning and computers shut down," said a Ukrainian source familiar with the incident on condition of anonymity.
A spokeswoman for the Ivano-Frankivsk SBU office Maria Rymar, said the agency was still working on the case.
"For the moment, we can't say who did it and for what purpose," she said.
The IT security firm ESET pinned the blame on a programme called KillDisk that was introduced onto the electricity company's computers on an infected Excel spreading document via "phishing" -- tempting an employee to open an inocuous-looking file.
The company, which has been monitoring the spread of KillDisk and a companion programme, said the virus deleted files in the computer systems, making them inoperable, and also contained code to sabotage industrial systems.
"It was a world first" in bringing down civilian infrastructure, ESET's French subsidiary said in a statement.
"This attack can only confirm what professionals have been fearing -- cyber-criminals are more and more powerful and cyber-attacks will be more and more numerous in 2016."
IT experts have been warning for years about cyber-security in vital civilian infrastructure such as power grids and transport.
Iran's nuclear refining facilities were hobbled in 2010 by a virus called Stuxnet, which is suspected to have been developed by the United States and Israel.
That was believed to the first virus designed not just to steal information or hijack computers, but to damage equipment.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jan 06 2016 | 12:57 AM IST

Next Story