On the afternoon of 23 December 2015, an operator at Prykarpattyaoblenergo, the company that distributes electricity across Ukraine's Ivano-Frankivsk region, watched the mouse pointer on his screen begin to move without him. It crossed the control interface and started switching breakers off. When he tried to take the machine back he was logged out, and the password had been changed. The same hands worked through three regional distributors that afternoon — Prykarpattyaoblenergo, Kyivoblenergo and Chernivtsioblenergo. Kyivoblenergo said afterwards that thirty of its substations, seven at 110 kV and twenty-three at 35 kV, had been opened, leaving 80,000 of its own customers without power; the Ivano-Frankivsk company was worse hit. About 225,000 customers in all lost power for between one and six hours, two days before Christmas, in a Ukrainian winter. The count is of customers rather than of people, so the number sitting in the dark was larger.
Everything else done that afternoon was designed to keep the lights off longer. Automated calls flooded a utility's call centre so that customers could not report the outage. The uninterruptible power supply feeding a control centre was switched off, taking the dispatchers' own room down with the grid. KillDisk, a wiper carried in by the BlackEnergy backdoor, destroyed files on the operator workstations. And the firmware in the converters that let the control rooms speak to the substations over serial links was overwritten with junk — which is why engineers eventually drove out and closed the breakers by hand. Power returned within hours precisely because the Ukrainian system was still manual enough to be worked that way, a point the industry has been making about its own automation ever since.
The attack was in December; the understanding arrived through January, in pieces. On 4 January ESET's Robert Lipovsky and Anton Cherepanov published what had been found on the energy companies' machines and wrote that the KillDisk component was "theoretically capable" of shutting critical systems down — a possibility, not a verdict. In the first full week the SANS industrial-control team's Michael Assante posted the confirmation: a coordinated, intentional attack, whose missing component was direct interaction by an adversary rather than the work of malware. America's ICS-CERT said at first only that a BlackEnergy 3 variant was present and that it could not confirm a causal link to the outage. On 18 January Ukrainian officials said the same family had been found on a workstation at Kyiv's Boryspil airport, caught early.
Ukraine's security service had blamed Russia within days — an accusation, not a finding — and the month's appetite for grid disasters outran its evidence. On 26 January in Tel Aviv, Israel's energy minister, Yuval Steinitz, told a conference of a severe cyber-attack on the Electricity Authority; by evening the Israeli grid was under assault in headlines. It was ransomware, opened from a phishing email inside a regulator of some thirty staff that operates no power lines. The confirmation that counted came on 25 February, when the Department of Homeland Security's ICS-CERT reported that the outages had been caused by remote cyber intrusions at three regional distributors, put the figure at about 225,000 customers, and noted that all were still running under constrained operations. This archive dates the first confirmed cyber-caused blackout to that afternoon.
The month of the backdoor
Juniper Networks had ended 2015 by admitting that unauthorised code sat inside ScreenOS, the software on its NetScreen firewalls: one allowed administrative logins with a particular password, another let an eavesdropper decrypt VPN traffic. On Friday 8 January its chief information officer, Bob Worrall, announced the remedy — Juniper would strip out Dual_EC, the random-number generator long suspected of carrying a back door, and the ANSI X9.31 generator meant to sit behind it, replacing both with the code used in Junos. Academics had shown why it mattered: a bug meant the X9.31 stage never ran, so raw Dual_EC output went onto the wire. The next day it was Fortinet's turn: an anonymous post to the Full Disclosure list carried a working script that logged into FortiGate firewalls over SSH as Fortimanager_Access with a hard-coded passphrase. Fortinet said on 12 January that this was a management authentication issue rather than a malicious back door, patched in July 2014; within a fortnight it found the same code in FortiSwitch, FortiAnalyzer and FortiCache, by which time the SANS Internet Storm Center was reporting scans coming almost entirely from two addresses in China.
Cards, passwords and a Friday
The month's ordinary crime kept its usual hours. Hyatt had found card-stealing malware on 30 November and announced it on 23 December; on 14 January it published the result of the investigation — cards used at 250 Hyatt-managed properties in some fifty countries between 13 August and 8 December 2015, mostly at hotel restaurants. On 27 January Wendy's confirmed, in answer to questions from the reporter Brian Krebs about a fraud pattern banks had traced to its restaurants, that it was investigating; the count grew through 2016, and the banks' claims settled in 2019 for $50 million. Time Warner Cable spent the first week of the month asking as many as 320,000 email customers to change passwords the FBI had found circulating, while saying its own systems showed no sign of a breach. And on Friday 29 January, payday for much of Britain, a denial-of-service attack kept HSBC's UK online banking down for most of the day. The bank said it had successfully defended the attack and restored service by evening; earlier that month the same service had failed for two days through a fault of its own.
After Pathankot, the graffiti war
The year began with gunfire. Before dawn on 2 January, attackers India said had crossed from Pakistan entered the air force station at Pathankot in Punjab; the fighting ran to 5 January and killed seven Indian security personnel, a civilian and six attackers. Among the dead was Lieutenant Colonel Niranjan Kumar, a National Security Guard bomb-disposal officer from Kerala, killed on 3 January. India blamed Jaish-e-Mohammed; Pakistan condemned the attack, sent investigators to the base in March, and they later disputed India's account. On 7 January a Kerala group calling itself Indian Black Hats claimed the defacement of seven Pakistani websites, among them the Pakistan Bar Council's, dedicating the work to Niranjan's eighteen-month-old daughter and saying it had deleted nothing, only uploaded pictures — "not cyber war but sending a message", by its own account. The claims and the counts were the hackers' own.
Defacement is graffiti; analysts reviewing these exchanges later, Recorded Future among them, described a retaliatory pattern rather than a campaign. The harder question went unasked. India's own memory of darkness was 30 and 31 July 2012, when the northern, eastern and north-eastern grids failed across twenty-two states and left close to 620 million people in the dark on the second day; the enquiry blamed overloaded transmission and a load-shedding scheme that did not act; no attacker was involved. The body meant to guard such systems was new: the National Critical Information Infrastructure Protection Centre, notified under section 70A of the Information Technology Act on 16 January 2014, turned two that month, power and energy first on its list of sectors. India's education in code with physical consequences was eighteen months away, at Nhava Sheva.
AlphaGo's five games kept quiet since October
On 27 January 2016 Nature published "Mastering the game of Go with deep neural networks and tree search", and DeepMind disclosed what it had kept quiet since October: at its London office, over five days from 5 October 2015, its AlphaGo program had beaten the European champion Fan Hui five games to nil, the first time a professional had lost to a machine on a full board without handicap. With it Demis Hassabis announced a five-game match in Seoul in March against Lee Sedol; Mark Zuckerberg had posted the day before that Facebook's Go effort, Darkforest, was getting close. AlphaGo won that million-dollar match 4–1, Lee retired in 2019 citing an entity that could not be defeated, and DeepMind's protein work brought Hassabis a share of a Nobel Prize in 2024. The month's other news was quieter. Marvin Minsky, who had founded MIT's artificial intelligence laboratory with John McCarthy, died in Boston on 24 January, aged 88; the day after, Microsoft moved its Computational Network Toolkit to GitHub under an MIT licence, later renamed and, within four years, retired.
Symantec alone again, and a thirty-second audit
On 29 January 2016 Symantec completed the sale of Veritas to investors led by the Carlyle Group and became a security company again. The price had been cut earlier that month, from the $8 billion agreed in August 2015 to about $7.4 billion, for uncertainties left unspecified; Symantec kept roughly $5.3 billion after tax. The shape held until November 2019, when the enterprise half went to Broadcom and the remainder became NortonLifeLock. Tavis Ormandy of Google's Project Zero, fresh from AVG's Web TuneUp extension in December, opened the year on Trend Micro: its consumer antivirus installed a Password Manager that listened on local HTTP ports and exposed some seventy APIs, one of which handed whatever a web page sent it to ShellExecute. Finding it took him, he wrote, about thirty seconds. Reported on 5 January and public on 11 January, it was closed by a mandatory update that Trend Micro said had followed its standard process; in June the same researcher would find Symantec's own engine unpacking files in the kernel, "as bad as it gets".
⏳ Time capsule — January 2016
- David Bowie died in New York on 10 January, aged 69, two days after his birthday and the release of his final album, Blackstar; the illness had been kept private until the announcement.
- On 16 January the nuclear agreement with Iran reached Implementation Day: the International Atomic Energy Agency verified that Tehran had carried out its side, and United Nations and European nuclear sanctions were lifted or suspended, unfreezing assets held abroad.
- Konstantin Batygin and Michael Brown of Caltech published their case for a ninth planet on 20 January — roughly ten Earth masses, inferred from the clustered orbits of six distant objects rather than seen. "Until Planet Nine is caught on camera it does not count as being real," Batygin said. "All we have now is an echo."
- Sania Mirza and Martina Hingis won the Australian Open women's doubles on 29 January, beating Andrea Hlaváčková and Lucie Hradecká 7–6(1), 6–3 for their third consecutive Grand Slam title as a pair.
The first time
A decade on, 23 December 2015 still holds the title this edition gives it, and nothing found since has displaced it. The sequel came inside a year: a substation north of Kyiv switched off on 17 December 2016 for a little over an hour, this time by malware that spoke the grid's own protocols directly, which ESET and Dragos would name Industroyer the following June. In October 2020 the United States indicted six officers of the GRU's Unit 74455 over both grid attacks, NotPetya and the sabotage of the 2018 Winter Olympics; none has been arrested. When the full invasion came in February 2022 the wipers went into Ukrainian networks hours before the tanks, and an updated Industroyer walked back into a transmission substation that April and was caught.
The month's quieter threads ran as far. Juniper finished removing Dual_EC from ScreenOS later in 2016; the question its unauthorised code raised — who wrote it, and for whom — has never been publicly answered. Fortinet's management authentication issue opened an argument about what a security vendor owes its customers that has not closed; in the later editions of this archive, the appliances at the network edge become the intruder's favourite door. India's hacktivists went on trading defacements across the border; the country's real shock arrived at a container terminal in 2017, and its answer took the form of a reporting rule measured in hours. This is the oldest edition The Vault holds: the archive begins here and continues backwards, December 2015 and the years before it still to be restored.