The Cyber Attack on the Ukrainian Electrical Infrastructure: Another Warning | INSS
go to header go to content go to footer go to search
INSS logo The Institute for National Security Studies, Strategic, Innovative, Policy-Oriented Research, go to the home page
INSS
Tel Aviv University logo - beyond an external website, opens on a new page
  • Campus
  • Contact
  • עברית
  • Support Us
  • Research
    • Topics
      • Israel and the Global Powers
        • Israel-United States Relations
        • Glazer Israel-China Policy Center
        • Russia
        • Europe
        • Antisemitism and Delegitimization
      • Iran and the Shi'ite Axis
        • The Campaign Against Iran and the Shiite Axis
        • Iran
        • Lebanon and Hezbollah
        • Syria
        • Yemen and the Houthi Movement
        • Iraq and the Iraqi Shiite Militias
      • Conflict to Agreements
        • Israeli-Palestinian Relations
        • Hamas and the Gaza Strip
        • Peace Agreements and Normalization in the Middle East
        • Saudi Arabia and the Gulf States
        • Turkey
        • Egypt
        • Jordan
      • Israel’s National Security Policy
        • Military and Strategic Affairs
        • Societal Resilience and the Israeli Society
        • Jewish-Arab Relations in Israel
        • Climate, Infrastructure and Energy
        • Terrorism and Low Intensity Conflict
      • Cross-Arena Research
        • Data Analytics Center
        • Law and National Security
        • Advanced Technologies and National Security
        • Foreign Information Manipulation and Interference
        • Economics and National Security
    • Projects
      • Preventing the Slide into a One-State Reality
      • India-Middle East-Europe Economic Corridor (IMEC)
  • Publications
    • -
      • All Publications
      • INSS Insight
      • Policy Research and Papers
      • Special Publication
      • Strategic Assessment
      • Technology Platform
      • Memoranda
      • Posts
      • Books
      • Archive
  • Database
    • Surveys
    • Spotlight
    • Maps
    • Dashboards
  • Events
  • Team
  • About
    • Vision and Mission
    • History
    • Research Disciplines
    • Chairman of the Board
    • Board of Directors
    • Fellowship and Prizes
    • Annual Reports
    • Internships
  • Media
    • Communications
    • Video gallery
    • Press Releases
  • Podcast
  • Newsletter
  • Campus
Search in site
  • Research
    • Topics
    • Israel and the Global Powers
    • Israel-United States Relations
    • Glazer Israel-China Policy Center
    • Russia
    • Europe
    • Antisemitism and Delegitimization
    • Iran and the Shi'ite Axis
    • The Campaign Against Iran and the Shiite Axis
    • Iran
    • Lebanon and Hezbollah
    • Syria
    • Yemen and the Houthi Movement
    • Iraq and the Iraqi Shiite Militias
    • Conflict to Agreements
    • Israeli-Palestinian Relations
    • Hamas and the Gaza Strip
    • Peace Agreements and Normalization in the Middle East
    • Saudi Arabia and the Gulf States
    • Turkey
    • Egypt
    • Jordan
    • Israel’s National Security Policy
    • Military and Strategic Affairs
    • Societal Resilience and the Israeli Society
    • Jewish-Arab Relations in Israel
    • Climate, Infrastructure and Energy
    • Terrorism and Low Intensity Conflict
    • Cross-Arena Research
    • Data Analytics Center
    • Law and National Security
    • Advanced Technologies and National Security
    • Foreign Information Manipulation and Interference
    • Economics and National Security
    • Projects
    • Preventing the Slide into a One-State Reality
    • India-Middle East-Europe Economic Corridor (IMEC)
  • Publications
    • All Publications
    • INSS Insight
    • Policy Research and Papers
    • Special Publication
    • Strategic Assessment
    • Technology Platform
    • Memoranda
    • Posts
    • Books
    • Archive
  • Database
    • Surveys
    • Spotlight
    • Maps
    • Dashboards
  • Events
  • Team
  • About
    • Vision and Mission
    • History
    • Research Disciplines
    • Chairman of the Board
    • Board of Directors
    • Fellowship and Prizes
    • Internships
    • Annual Reports
    • Privacy Policy and Terms of Use
  • Media
    • Communications
    • Video gallery
    • Press Releases
  • Podcast
  • Newsletter
  • Campus
  • Contact
  • עברית
  • Support Us
bool(false)

Publications

Home Publications INSS Insight The Cyber Attack on the Ukrainian Electrical Infrastructure: Another Warning

The Cyber Attack on the Ukrainian Electrical Infrastructure: Another Warning

INSS Insight No. 798, February 17, 2016

Follow us on Google
עברית
Gabi Siboni
Zvi Magen
On December 23, 2015, malfunctions were reported in portions of the electrical network in western Ukraine, after the operations of 27 distribution stations and three power plants were disrupted, causing the electricity supply system to crash. This was not a routine power outage: the Ukrainian authorities believe that a cyber attack originating in Russia caused the malfunction, and the Security Service of Ukraine has blamed Russia for the power outages. The conclusions of several security companies confirm the suspicion linking the attack to Sandworm, which according to the security company iSight is a Russian group affiliated with the Russian government. Hypotheses regarding a possible motive also support the suspicion that Russia is the party responsible for the attack, perhaps as part of the Russian campaign against cutting off the Crimean Peninsula, annexed by Russia, from electricity supplied by Ukraine. Cyberspace operations also enable Russia to continue denying its involvement in Ukraine, while at the same time persisting in efforts to attack it.

For some time, security experts have warned that critical services – for example, electricity and water supplies – can be attacked through cyberspace. The assumption is that such action requires sophisticated capabilities in cyber intelligence, technology, and operations, and possession of such capabilities is usually attributed to countries that have invested heavily in their development. Until now, even if in possession of such capabilities, most countries have shown restraint in using cyber tools to materially disrupt essential services and critical infrastructure in enemy countries. Events in Ukraine, however, question whether this assumption of restraint is still valid. On December 23, 2015, malfunctions were reported in portions of the electrical network in western Ukraine, after the operations of 27 distribution stations and three power plants were disrupted, causing the electricity supply system to crash. Many homes were cut off from the network. This was not a routine power outage: the Ukrainian authorities believe that a cyber attack originating in Russia caused the malfunction, and the Security Service of Ukraine (SBU) has blamed Russia specifically for the power outages.

It is difficult to prove with certainty who was behind the attack, but presumably the relevant authorities in Ukraine, with the help of Western agencies, will ultimately uncover the attacker’s identify. The Ministry of Energy in Kiev has appointed a committee to investigate the affair. Thus far assessments concerning the party responsible for the attack are based on forensic examinations carried out on the damaged computers, which indicates that components in them were previously used by Russian groups. Furthermore, not surprisingly the technological capabilities point to a Russian element.

The conclusions of several security companies confirm the suspicion linking the attack to Sandworm, which according to the security company iSight is a Russian group affiliated with the Russian government. iSight has monitored Sandworm for over a year, and discovered that the group has collected information from the computers of Ukrainian administration officials, and from agencies in the European Union and NATO. Other security experts reported that the group was also focusing on attacking industrial control systems. According to the security company ESET, located in Bratislava, the attackers used backdoor software that makes it possible to conduct operations on the target computers through a remote control server. In the Ukrainian case, use was made of a BlackEnergy component – a Trojan horse used as early as 2014 – to spy on Ukrainian administration computers and plant a malware program called KillDisk on power station computers in western Ukraine.

Hypotheses regarding a possible motive also support the suspicion that Russia is the party responsible for the attack, perhaps as part of the Russian campaign against cutting off the Crimean Peninsula, annexed by Russia, from electricity supplied by Ukraine. In addition, there is a great deal of information about the presence of advanced cyber warfare capabilities possessed by Russia and affiliated organizations, with Russia taking the lead in developing a combat doctrine that encompasses both kinetic and cybernetic activity. In the case of Ukraine, cyberspace operations enable Russia to continue denying its involvement in its neighbor, while at the same time persisting in efforts to attack it.

Effective wielding of the cyber weapon against sensitive targets in another country, in this case Ukraine, is likely to have far reaching consequences, not only for the future course of the particular conflict, but also for conflicts between other countries, or between countries and non-state organizations able to procure both offensive and defensive cyber capabilities. To be sure, similar cases of cyber attacks were recorded in the past. One of the best known examples of attack against infrastructure facilities that caused actual physical damage was the attack on Iranian nuclear installations with the Stuxnet software – alleged by some to have been carried out by Israel and the United States. Attacks in the Baltic states designed to prevent service were attributed to Russia. Nevertheless, the cyber attack in western Ukraine clearly reflects the use of this weapon against critical civilian infrastructure on a larger scale. This event, a precedent tantamount to crossing the Rubicon, is liable to serve as a model for imitation by other countries and perhaps organizations as well, while eroding the barriers of restraint that previously existed. In other words, it appears that the Ukraine incident is a sign that an especially important threshold has been crossed. Espionage, the theft of commercial information, financial crime, and denial of services are tolerable; although bothersome, they do not materially and directly harm the substance of daily life. An attack against the electrical infrastructure, however, can damage critical infrastructure and jeopardize human life. It therefore constitutes a quantum leap in the will to cause damage, in this case by a state.

Like other countries threatened in cyberspace, Ukraine will have to consider how to improve its defensive capabilities against similar events in the future. Israel can provide an example here. Over the past decade, Israel has been able to develop advanced defensive capabilities for its critical infrastructure. Its defensive envelope includes gathering and analyzing intelligence and distributing it to the relevant agencies, as well as monitoring by the Israel Security Agency. This has created an environment of ongoing improvement and enhancement in defensive capabilities. Still, the proliferation of cyber capabilities, which has accelerated in recent years, enables new-old players – terrorist organizations and criminal elements – to acquire capabilities previously considered the exclusive province of nations. Concern is therefore growing that these non-state actors, which lack restraint mechanisms and state-like considerations, will attempt to imitate the model demonstrated in the attack on the electricity infrastructure in Ukraine.

Disruption of the supply of electricity is no trivial matter. It is enough to recall the events in Israel in late 2015 resulting from natural causes, and not a cyber attack: harsh winter weather caused serious disruptions over widespread areas lasting for many days. Israel is especially vulnerable in this aspect, due to the concentrated topology of its electricity grid. It is therefore necessary to continue monitoring related developments in Israel’s strategic environment and throughout the world to assess whether there is a growing trend of cyber attacks able – despite sophisticated defensive measures – to inflict serious damage, and to prepare accordingly.

The opinions expressed in INSS publications are the authors’ alone.
Publication Series INSS Insight
TopicsAdvanced Technologies and National SecurityRussia
עברית

Events

All events
Israel’s National Security Conference
27 July, 2026
10:00 - 14:00

Related Publications

All publications
Shutterstock
The Next Battle for Artificial Intelligence: Should Israel Become a Chip Manufacturing Powerhouse?
The global race for artificial intelligence is fundamentally reshaping how states perceive technological infrastructure. While competition in recent decades revolved around control over data, digital platforms, and AI models, it has become clear that a nation’s strategic advantage will now largely be determined by its control over the physical AI value chain—spanning critical minerals, advanced chip manufacturing, high-performance computing (Compute) infrastructure, data centers, energy, and frontier models. The competition is no longer over a single component of the AI system, but over the ability to hold significant stakes across the entire AI Stack.
29/07/26
Generated with AI
From Red to Blue-and-White: The Strategic Necessity of Developing the Israeli Drone Industry
Chinese-made drones pose a range of security, technological, and geopolitical challenges for Israel. What measures should Israel take to mitigate the risks involved?
07/07/26
Shutterstock
The Battle over Access to Artificial Intelligence: Israel’s Next Strategic Challenge
The restrictions recently imposed on Anthropic — including the U.S. administration’s directive to limit access to certain models for users and entities outside the United States on national security grounds[1] — constitute a significant milestone in the evolving relationship between technology, national security, and foreign policy. Whereas over the past decade, the discourse surrounding digital sovereignty has focused on issues such as privacy, data localization, regulation, and cloud infrastructure, recent developments point to a transition to a new phase in which access to advanced artificial intelligence capabilities is becoming a strategic asset in itself. In this reality, not only data or chips are becoming objects of government policy, but also the models themselves. This article argues that the Anthropic case is not an isolated incident but rather a manifestation of a broader trend, in which artificial intelligence is becoming a central component of national power. As a result, access to advanced models may in the future become a policy tool, a mechanism of geopolitical influence, and a means of advancing strategic interests. For Israel, this development necessitates a reassessment of its approach to technological sovereignty and its policies in the fields of artificial intelligence, computing, and infrastructure, as well as a rethinking of its broader security paradigm. [1] The directive conveyed to Anthropic on June 12 by the Trump administration required the company to terminate access to its Fable 5 and Mythos 5 models for all foreign users, including the company’s foreign employees, users outside the United States, and international clients. According to reports, the company was given a very short timeline to implement the directive, under the threat of civil and criminal sanctions in the event of non-compliance. At a later stage, a limited exemption was granted, allowing the use of Mythos 5 for a small number of critical infrastructure organizations within the United States, while Fable 5 remained restricted.  
01/07/26

Stay up to date

Registration was successful! Thanks.
  • Research

    • Topics
      • Israel and the Global Powers
      • Israel-United States Relations
      • Glazer Israel-China Policy Center
      • Russia
      • Europe
      • Antisemitism and Delegitimization
      • Iran and the Shi'ite Axis
      • The Campaign Against Iran and the Shiite Axis
      • Iran
      • Lebanon and Hezbollah
      • Syria
      • Yemen and the Houthi Movement
      • Iraq and the Iraqi Shiite Militias
      • Conflict to Agreements
      • Israeli-Palestinian Relations
      • Hamas and the Gaza Strip
      • Peace Agreements and Normalization in the Middle East
      • Saudi Arabia and the Gulf States
      • Turkey
      • Egypt
      • Jordan
      • Israel’s National Security Policy
      • Military and Strategic Affairs
      • Societal Resilience and the Israeli Society
      • Jewish-Arab Relations in Israel
      • Climate, Infrastructure and Energy
      • Terrorism and Low Intensity Conflict
      • Cross-Arena Research
      • Data Analytics Center
      • Law and National Security
      • Advanced Technologies and National Security
      • Foreign Information Manipulation and Interference
      • Economics and National Security
    • Projects
      • Preventing the Slide into a One-State Reality
      • India-Middle East-Europe Economic Corridor (IMEC)
  • Publications

    • All Publications
    • INSS Insight
    • Policy Research and Papers
    • Special Publication
    • Strategic Assessment
    • Technology Platform
    • Memoranda
    • Database
    • Posts
    • Books
    • Archive
  • About

    • Vision and Mission
    • History
    • Research Disciplines
    • Chairman of the Board
    • Board of Directors
    • Fellowship and Prizes
    • Internships
    • Annual Reports
    • Support
    • Privacy Policy and Terms of Use
  • Media

    • Communications
    • Video Gallery
    • Press Release
    • Podcast
  • Home

  • Events

  • Database

  • Team

  • Contact

  • Newsletter

  • עברית

INSS logo The Institute for National Security Studies, Strategic, Innovative, Policy-Oriented Research, go to the home page
40 Haim Levanon St. Tel Aviv, 6997556 Israel | Tel 03-640-0400 | Fax 03-744-7590 |
Developed by Daat ,Yael Group.
Accessibility Statement
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.