Fact check
Is it true: Ukraine power-grid BlackEnergy attack (Dec 23 2015)?
Yes — this is confirmed.
US-CERT IR-ALERT-H-16-056-01 (Feb 2016) formally attributed the attack to Sandworm with published indicators of compromise. Ukrainian SBU concurred. ESET, Dragos, and multiple academic analyses independently confirm the attack chain, BlackEnergy/KillDisk tooling, and SCADA compromise methodology. Impact — 230,000 customers, 1-6 hours without power — is documented by the affected utilities. The follow-on Industroyer/Crash Override attack (Dec 2016) confirms a sustained Sandworm campaign against Ukrainian grid infrastructure.
The claim
On 23 December 2015, cyberattackers disrupted electricity supply to approximately 230,000 customers in Ukraine's Ivano-Frankivsk Oblast for one to six hours — the first publicly confirmed successful c
Key evidence
KillDisk wiper: deliberate destruction beyond operational disruption
US-CERT IR-ALERT-H-16-056-01: formal attribution to Sandworm
Conspirafy steelmans each claim, then follows the evidence. How we reach a verdict · Check another claim