Case

Ukraine power grid attacks (2015-2016)

Ukraine power grid attacks (2015-2016) were Russian state cyber operations against Ukrainian civilian electricity infrastructure during the Russo-Ukrainian armed conflict. Official United States, United Kingdom and European Union records attribute both attacks to the Russian military intelligence Main Centre for Special Technologies, Unit 74455. The operations produced temporary outages and demonstrated an ability to manipulate operational technology; their technical methods and achieved effects differed.

Two operations

On 23 December 2015, attackers compromised 3 Ukrainian electricity distribution companies, remotely opened breakers and disrupted supporting systems. United States reporting records more than 225,000 affected customers, outages lasting 1 to 6 hours and manual restoration (Department of Homeland Security and Department of Energy, 2017). The operation combined BlackEnergy-enabled access, operator action and destructive KillDisk activity. The malware label alone does not describe the full mechanism.

On 17 December 2016, purpose-built Industroyer malware interrupted part of Kyiv for over an hour. ESET's analysis showed that the malware could communicate through electricity-control protocols (Cherepanov, 2017). Dragos later assessed that CRASHOVERRIDE's protection-relay capabilities created a risk of physical equipment damage (Lee and Conway, 2026). That conclusion is a practitioner assessment of likely capability and intent. The observed result was an outage, not confirmed equipment destruction.

Attribution and purpose

The United States charged 6 GRU officers in 2020 and alleged that the operations served Russia's strategic interest in destabilising Ukraine (Department of Justice, 19 October 2020). The indictment supplies detailed allegations, not convictions. The European Union separately listed Unit 74455 as responsible for the attacks (Council Regulation (EU) 2019/796). CISA also distinguishes the 2015 BlackEnergy and KillDisk operation from the 2016 CrashOverride deployment (CISA, 11 January 2022).

The United Kingdom's current GRU profile, published 13 July 2026, attributes both attacks to Unit 74455 and reports about 230,000 people affected in 2015 and one fifth of Kyiv in 2016 (United Kingdom government, 2026). These source-specific figures explain minor differences in public totals.

No authenticated Russian operational statement defines purpose. Disruption, capability development, signalling and degradation remain inferences from target choice, conflict setting, official attribution and technical design. A 2026 Dragos retrospective reinforces the defensive lessons: manual recovery limited outage duration, while loss of automation remained consequential (Lee and Conway, 2026).

See also

Economic statecraft · Digital economic warfare · Electricity grids and cross-border interconnectors · NotPetya, 2017 · Energy weaponisation · Russia · Ukraine

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Ukraine power grid attacks (2015-2016).' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/ukraine-power-grid-attacks-2015-2016/.

Suggest an edit