/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant: Russia-tied Sandworm carried out a third successful attack on Ukraine's electric utility in October 2022, coinciding with a series of missile strikes

Russia's most notorious military hackers successfully sabotaged Ukraine's power grid for the third time last year.

Wired Andy Greenberg

Context & Ripple Effects

Mandiant’s attribution adds a third confirmed grid-sabotage episode to a campaign that earlier coverage described as repeated attacks on Ukraine’s power system, framed as testing offensive cyber capabilities against Ukraine’s electricity system. The reported timing alongside missile strikes makes the incident significant as part of a broader pressure campaign on essential services.

The attribution is also consistent with Sandworm’s established connection to Russia’s GRU-linked Main Center for Special Technology in the U.S. attribution. Later reporting on malware used against a Lviv heating utility shows that utility-sector targeting remained an active concern in the subsequent Lviv heating attack.

First-order effects

  • Ukraine’s electric-utility operators and incident responders must treat the October 2022 outage as a confirmed Sandworm sabotage event, rather than an isolated disruption during missile strikes.
  • Mandiant’s finding strengthens the operational case for correlating cyber incidents with concurrent physical attacks on power infrastructure.

Second-order effects

  • Other utilities facing Russia-linked threats have a clearer reason to integrate cyber monitoring, grid operations, and physical-security response; attacks on German wind operators had already shown that energy-sector disruption can extend beyond Ukraine to remote wind-turbine control systems.
  • Security vendors and government defenders are likely to prioritize detection and incident-response work tied to Sandworm’s utility-targeting tradecraft, while operators face greater pressure to test continuity plans for compound disruptions.

Third-order effects

  • If cyber sabotage continues to accompany kinetic operations, electricity networks will increasingly be defended as conflict infrastructure rather than as standalone civilian IT environments.
  • The pattern points toward a durable energy-security model in which grid resilience depends on coordinated cyber and physical defense, though the corpus does not establish how broadly that model will be adopted outside the region.

The trend: This is one data point in the convergence of cyber operations and physical attacks against essential energy infrastructure during interstate conflict.

Discussion

  • @ericgeller Eric Geller on x
    @Mandiant The outages occurred on Oct. 10 and 12, 2022 — overlapping with Russian missile strikes on cities including the one where the outage occurred. The Russians may have timed these attacks to coincide — Mandiant says they had access to control systems “for up to three month…
  • @ericgeller Eric Geller on x
    New: Hackers working for Russia's military intelligence agency caused a power outage in Ukraine late last year with a “novel technique” for breaching industrial control systems, and then wiped IT systems to cover their tracks, according to @Mandiant. https://www.mandiant.com/... …
  • @danwblack Dan Black on x
    New today from @Mandiant detailing a new class of cyber physical attack from Sandworm to disrupt Ukraine's grid This attack departs from the group's history of using OT-specific malware, instead opting for a harder to detect living off the land approach https://www.mandiant.com/.…
  • @big_bad_w0lf_ John on x
    Hot off the press is a new @Mandiant blog. This blog covers a Sandworm operation that targeted a Ukrainian critical infrastructure organization with OT living off the land techniques as well as Caddywiper. https://www.mandiant.com/...
  • @ravirockks Ravi Nayyar on x
    '[Sandworm] first used OT-level living off the land (LotL) techniques to likely trip the victim's substation circuit breakers, causing an unplanned power outage that coincided [!!!] with mass missile strikes on critical infrastructure across Ukraine. https://www.mandiant.com/...