Menu
Browse
Date:

Mar 2024

Location:

North Macedonia

Summary

The Electricity Transmission System Operator of North Macedonia (MEPSO) confirmed a cyberattack targeting its systems, though critical energy infrastructure remained secure and fully operational with no compromise to the power grid or electricity supply. The company reported the incident to relevant authorities and is collaborating with cybersecurity experts to mitigate effects and restore normal operations, noting it had implemented extensive safeguards but still experienced recent disruptive incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Electricity Transmission System Operator of the Republic of North Macedonia (MEPSO) confirmed on March 1, 2024, that it was actively addressing a cyberattack against its systems. In a press release issued on Thursday, February 29, 2024, MEPSO clarified that the incident did not target critical energy infrastructure components responsible for electricity transmission. The company assured the public that both the operational integrity of the national power grid and the continuity of electricity supply remained fully intact throughout the incident. MEPSO emphasized its critical infrastructure remained secure and fully functional despite the cyber intrusion. The attack occurred in recent days prior to the March 1 public disclosure, though the exact start date and initial detection method were not specified in the announcement. No operational disruptions or power outages resulted from the incident, confirming the containment of impacts to non-critical systems. MEPSO did not identify the specific IT systems compromised or the nature of the attackers' activities beyond classifying the event as a cyberattack.

Cyber Incident Image

MEPSO acknowledged implementing extensive pre-existing cybersecurity measures prior to the attack but confirmed these defenses were challenged during the incident. The organization followed national cybersecurity regulations by formally reporting the attack to relevant authorities, though these agencies were not named in the press release. Internal MEPSO technical teams collaborated with external cybersecurity experts to mitigate the attack's effects and restore normal operations across affected systems. The company prioritized resolving residual technical issues to resume standard business functions, though no timeline for full recovery was provided. Public communications emphasized transparency regarding infrastructure security while withholding technical details that could compromise ongoing remediation or investigation efforts. No data breaches, ransomware notes, or financial motives were disclosed in the initial statement. MEPSO maintained its operational responsibilities throughout the response without requiring external grid management support.

Sources
Sources available to members
1 source