Skip to main content
QUIETLYTIC
Campaign

2015 Ukraine Electric Power Attack

Sandworm Team's use of BlackEnergy3 and KillDisk to disrupt transmission and distribution substations within the Ukrainian power grid in December 2015 — the first major public cyberattack on a power grid.

Threat Level
CRITICAL
Status
Resolved
Actors Involved
Sandworm Team
Targets
Ukrainian electric power transmission and distribution substations

Overview

The 2015 Ukraine Electric Power Attack (MITRE ATT&CK ID C0028) was conducted by Sandworm Team using BlackEnergy3 and KillDisk to target and disrupt transmission and distribution substations within the Ukrainian power grid, per MITRE’s campaign profile. MITRE documents this as the first major public attack conducted against the Ukrainian power grid by Sandworm Team, and it is widely cited elsewhere as the first confirmed cyberattack to cause a physical power outage — though the specific customer-impact figures reported at the time come from contemporaneous public reporting outside MITRE’s own campaign data, not from MITRE’s dataset itself.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from December 2015 to January 2016.

Actors and malware involved (per MITRE ATT&CK relationship data)

MITRE ATT&CK attributes this campaign to Sandworm Team. Malware documented in this campaign includes BlackEnergy (specifically the BlackEnergy3 variant) and KillDisk, used together to gain access to grid control systems and then destroy data on affected machines to hamper recovery.

What we don’t have

MITRE’s ingested data doesn’t include the full technical detail of how BlackEnergy3 was initially delivered to victim organizations. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no confirmation of the exact restoration timeline for affected substations beyond MITRE’s documentation of the attack itself.

Frequently Asked Questions

What was the 2015 Ukraine Electric Power Attack? A campaign, per MITRE ATT&CK, in which Sandworm Team used BlackEnergy3 and KillDisk malware to disrupt Ukrainian power grid substations in December 2015, causing a widely documented outage.

Who was behind the 2015 Ukraine Electric Power Attack? Sandworm Team, per MITRE ATT&CK’s relationship data.

Was this the first cyberattack to cause a power outage? It is widely regarded as the first publicly confirmed case of a cyberattack directly causing a physical power outage, per MITRE’s documentation, and MITRE separately tracks a second, related Sandworm Team attack on the Ukrainian grid the following year.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0028, aggregated September 20, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools