Skip to main content
Landmark incidents define how CISOs and National CERTs brief boards and ministries. They also map cleanly to techniques Reyhford tags on live indicators.

Stuxnet (2010)

First widely known cyberweapon designed for physical damage. Targeted Siemens S7 PLCs controlling uranium centrifuges: intercepted S7 traffic, altered rotor speeds, and replayed “normal” values to operators. Takeaway for defenders: proprietary ICS protocols are attack surfaces; process integrity must be monitored independently of HMI screens.

Ukraine power grid (2015, 2016)

First confirmed cyberattacks to cause customer power outages (~230,000 customers). Combined IT compromise with ICS-aware payloads (later Industroyer / Crashoverride lineage). Takeaway: grid protocols and remote terminal units are strategic targets for nation-states.

Triton / TRISIS (2017)

First malware purpose-built to disable safety instrumented systems at a petrochemical plant. Aimed at the last line of physical protection. Takeaway: safety systems are not off-limits; T0814-class techniques matter as much as production setpoints.

Colonial Pipeline (2021)

Ransomware on IT systems forced a major US fuel pipeline offline. ~$4.4M ransom paid; East Coast fuel shortages followed. Takeaway: OT risk includes IT dependencies — billing, scheduling, and corporate Active Directory.

Industroyer2 (2022)

Deployed against Ukrainian high-voltage substations during wartime. Continues the Industroyer lineage against IEC-centric grid environments.

How Reyhford uses this history

We do not claim every honeypot hit is a named APT. We map observed protocol abuse to MITRE ATT&CK for ICS (especially T0855, T0814, T0830) so analysts can place live IoCs next to these incident classes in their playbooks. See Industrial Protocols and MITRE ATT&CK for ICS.