Scarinci Hollenbeck, LLC
The Firm
201-896-4100 info@sh-law.comFirm Insights
Author: Scarinci Hollenbeck, LLC
Date: January 20, 2016
The Firm
201-896-4100 info@sh-law.comTheir failure would cause significant social disruption. They are the soft underbelly of our modern world. For example, Stuxnet exploited a Siemens industrial controller not designed to withstand cyber attack. In another case, original, 1960’s 8 inch, floppy disks control parts of the launch systems for U.S. nuclear missiles.[1] Indeed, most homes still have traditional circuit breakers.

The first known instance of malware causing a disruption in major electrical service took place on December 23, 2015 in Ukraine. At least three regional substations were disconnected from the grid. While not in the U.S., the Ukrainian methods and apparatuses for delivering electricity to the end-user are not significantly different. In all, around 700,000 homes lost power as a result of this attack.
The cyber attack happened when many Ukrainian power stations became infected by the malware package “BlackEnergy.” The package’s original purpose was to spy on various business groups, such as media organizations, power companies, and telecoms. However, the malware used in this attack contained several important upgrades to its functionality—most notably: making the infected machine unbootable, wiping all data on the infected machine, and backdooring a secure shell (SSH) utility, which gave the attackers permanent access to the infected machines. Researchers suspect that the attackers used the SSH to gain access to the systems and shut them down. Meanwhile, the program wiped all the data on the systems, making their recovery much more lengthy and difficult. Finally, the attackers waged denial-of-service attacks (DDoS) on the target’s internet and phones systems to prevent power company personnel from learning about the outages.
In the past, this group has spied on NATO, Eastern European agencies, and European commercial and industrial groups. Research suggests that the group operates from Russia, although confirmation has been slippery, and even if they did operate from Russia, it is not clear who is directing them. Whoever this group is though, they possess enough sophistication to run a three pronged attack: shutting down electric service, wiping data on the system computers, and coordinating a DDoS attack on internet and phone systems. No one of these three prongs is necessarily a difficult attack. However, the coordination of all three indicates that, without hyper-sophisticated malware, attackers can use a variety of low-sophistication attacks in tandem to produce a high-level result.
The infection most likely, although not confirmed, occurred through Microsoft Word macros. These sorts of attacks are considered “social engineering” attacks, which rely on duping an end-user into installing malware or taking an action they otherwise would not and should not take. This particular kind is simple and insidious. For example, the end-user receives an email from his boss saying to review the attached document ASAP. The email looks legitimate, and not wanting to disappoint the boss, the user opens the attachment. As the Word document opens, it runs a macro that installs the malicious software, unbeknownst to the end-user.
Despite experts’ warnings, attacks on these sorts of systems have been rare and usually done only for specific discrete reasons. However, with the now real threat that these attacks could become more widespread and more frequent, we will have to acknowledge that any device with a computer connected to a system, must be secured and monitored for cyber-attack.
[1] Oddly enough, this is currently a pretty secure way to operate these missiles as the technology is so old that it is impervious to the advancements in cyber attack software. However, once someone does develop an exploit, the whole system will need to change.
Related Article:
Cyber Insecurity: The Dark Web
The Quantum Computer And The Obsolence of Current Encryption
What Is Cyber Security? It Starts With Cryptology
Cyber Insecurity: Ashley Madison Encrypted Passwords Cracked.
Survey Reveals Many Business Executives Lack Cybersecurity Confidence
Top Cybersecurity Threats Unveiled by Hackers – Is Anyone Safe?
Additional information and resources:
Cyber Security And Data Protection Group
Intellectual Property And Technology
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

The Fort Monmouth redevelopment has entered its execution phase, and it is repositioning the broader Monmouth County real estate market. When Netflix and the Fort Monmouth Economic Revitalization Authority closed on the 292-acre Mega Parcel in December 2025, the transaction did more than hand over a deed. It marked the moment Fort Monmouth stopped being […]
Author: Donald M. Pepe

Owning a residential rental property in New Jersey involves more than finding tenants and collecting rent. Property owners must comply with a combination of state laws, municipal ordinances, building and housing codes, and zoning and land use regulations. These requirements can affect everything from the number of dwelling units permitted at a property to whether […]
Author: Donald M. Pepe

The five most common real estate disputes are breach of contract claims, landlord-tenant conflicts, zoning and land use disagreements, construction claims, and boundary disputes. Understanding why each arises, and taking preventive steps early, can help property owners, tenants, developers, and investors avoid costly litigation. Key Takeaways: Real estate transactions are complex endeavors involving numerous parties […]
Author: Paul Grossman

Once a child turns 18, parents lose the automatic legal authority to make medical and financial decisions on their behalf, even if the child still lives at home or remains on the family’s insurance. Three documents close that gap: a durable power of attorney, a health care proxy or directive, and a HIPAA authorization. For […]
Author: George McGowan

Business mediation is a confidential, voluntary process in which a neutral third party helps companies negotiate a resolution to a commercial dispute without going to trial. Because working with a mediator is very different from litigating in the courtroom, it is important to understand how commercial mediation works, when it makes sense for your dispute, […]
Author: Paul Grossman

The five most common causes of construction defect litigation are design defects, substandard materials, workmanship defects, code violations, and subsurface defects. Because these flaws can compromise a building’s integrity, functionality, or safety, they frequently lead to disputes involving multiple parties and high financial stakes. Key takeaways: What is Construction Defect Litigation? Construction litigation is complex, […]
Author: Paul Grossman
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.
Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.
Let`s get in touch!
Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!