A reconstruction of the cyberattack on the US power grid from 2016 to 2018, which targeted contractors and trade publications, and which the US blamed on Russia
Wall Street Journal : Tweets: @dnvolz , @ericgeller , and @amy_siskind Tweets: Dustin Volz / @dnvolz : NEW: @WSJ investigation reconstructs Russia's 2017 campaign of cyber intrusions into the U.S. electric grid, showing how hackers broke in through contractors and subcontractors of utilities before climbing up the supply chain https://www.wsj.com/... Eric Geller / @ericgeller : How does a supply chain cyberattack on the U.S. energy sector actually work? This WSJ story provides great examples. “Russian government hackers likely remain inside some systems, undetected and awaiting further orders.” http://www.wsj.com/... http://twitter.com/... @amy_siskind : Russian hackers were able to penetrate US electric grid in 2018: “The hackers planted malware on sites of online publications frequently read by utility engineers. They sent out fake résumés with tainted attachments, pretending to be job seekers” & MORE! http://www.wsj.com/...
Context & Ripple Effects
The reconstruction ties together a thread that had been building for two years: after researchers documented how Crash Override took down Ukraine's power grid and warned that repeated strikes on Kiev looked like live testing of offensive capabilities, DHS escalated its own accounting, saying hundreds of victims — not a few dozen — had been hit in Russian intrusions into utility control-room networks.
What the WSJ adds is the mechanism: hackers entered through contractors and subcontractors of utilities, then climbed the supply chain, with some reportedly still inside awaiting orders. The piece lands just months before reports that US Cyber Command began deploying offensive malware inside Russia's power grid under 2018 authorities — making the grid a two-way theater rather than a one-sided target.
First-order effects
- US electric utilities and their contractor networks are the immediate affected parties: the vendor-and-subcontractor layer, previously treated as peripheral IT, is now confirmed as the primary entry point, forcing access audits across supplier relationships.
- Utilities that assumed the intrusion count was small must re-baseline against DHS's 'hundreds of victims' figure, with the possibility that attackers remain resident in some control-room-adjacent systems.
Second-order effects
- The attribution to Russian government hackers gives Washington grounds for the reciprocal move already reported — Cyber Command planting malware in Russia's grid — converting defense into declared deterrence by punishment.
- Industrial-control vendors and energy-sector suppliers face customer-driven security requirements and liability pressure, since a compromise at any subcontractor now propagates up to the utility itself.
Third-order effects
- If the pattern holds — Ukraine as proving ground, US utilities as target, German wind operators' remote-control shutdowns as the next iteration — critical-infrastructure security structurally shifts from perimeter defense to continuous supply-chain assurance, with governments treating grids as standing cyber battlefields.
- Persistent-access operations on both sides raise the risk that a future physical outage is ambiguous between accident and attack, pushing regulators toward mandatory intrusion-detection and disclosure regimes for grid operators.
The trend: State-sponsored cyber operations are turning national power grids into persistently contested territory, with supply chains as the preferred entry vector and each side's intrusion licensing the other's.