
Sep 18, 2026 · 34 min
Ukraine’s grid attack ended the era of infrastructure taboos
The Cisco root route.
The episode traces how critical-infrastructure threats moved from expert warnings and theoretical scenarios to adversaries directly manipulating industrial systems.
- 1The 2015 Ukraine power-grid attack showed that long-discussed infrastructure threats could produce real-world consequences.
- 2Industroyer demonstrated how attackers could learn industrial protocols and interact directly with grid equipment.
- 3Legacy systems became more exposed as automation and internet connectivity were layered onto poorly understood infrastructure.
Don't miss
Dave Bittner and Maria Vermozis connect the Ukraine power-grid attack and Industroyer to the collapse of assumptions that industrial systems were off limits.
The brief
Dave Bittner and Maria Vermozis use a decade of critical-infrastructure incidents to examine how cyberattacks crossed from warnings into direct disruption.
The 2015 Ukraine power-grid attack became a turning point: a threat long discussed by industrial-control experts had moved from theory into a real attack on essential services.
Earlier warnings from The Loft Crew imagined small groups causing sweeping internet disruption, but the hosts focus on a deeper shift: attackers began targeting industrial systems themselves.
The old assumption that public-facing systems and critical infrastructure were off limits collapsed as adversaries exploited legacy environments, newer connectivity, and security through obscurity.
Industroyer, also known as Crash Override, marked the practical consequence: attackers learned industrial-control protocols and used them to interact directly with grid equipment.