> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reyhford.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Real Incidents

> Stuxnet, Triton, Colonial Pipeline, and other landmark ICS/OT cyber events.

Landmark incidents define how CISOs and National CERTs brief boards and ministries. They also map cleanly to techniques Reyhford tags on live indicators.

## Stuxnet (2010)

First widely known cyberweapon designed for **physical damage**. Targeted Siemens S7 PLCs controlling uranium centrifuges: intercepted S7 traffic, altered rotor speeds, and replayed “normal” values to operators.

**Takeaway for defenders:** proprietary ICS protocols are attack surfaces; process integrity must be monitored independently of HMI screens.

## Ukraine power grid (2015, 2016)

First confirmed cyberattacks to cause customer power outages (\~230,000 customers). Combined IT compromise with ICS-aware payloads (later Industroyer / Crashoverride lineage).

**Takeaway:** grid protocols and remote terminal units are strategic targets for nation-states.

## Triton / TRISIS (2017)

First malware purpose-built to disable **safety instrumented systems** at a petrochemical plant. Aimed at the last line of physical protection.

**Takeaway:** safety systems are not off-limits; T0814-class techniques matter as much as production setpoints.

## Colonial Pipeline (2021)

Ransomware on IT systems forced a major US fuel pipeline offline. \~\$4.4M ransom paid; East Coast fuel shortages followed.

**Takeaway:** OT risk includes IT dependencies — billing, scheduling, and corporate Active Directory.

## Industroyer2 (2022)

Deployed against Ukrainian high-voltage substations during wartime. Continues the Industroyer lineage against IEC-centric grid environments.

## How Reyhford uses this history

We do not claim every honeypot hit is a named APT. We **map observed protocol abuse** to MITRE ATT\&CK for ICS (especially T0855, T0814, T0830) so analysts can place live IoCs next to these incident classes in their playbooks.

See [Industrial Protocols](/protocols/modbus) and [MITRE ATT\&CK for ICS](/mitre/t0855).
