Lyce · Hybrid Watch

hw_4052adac811a8084

Breach of a Canadian gas pipeline’s control network by Russian-linked hackers with intent to sabotage.

According to leaked U.S. intelligence documents, a pro-Russian hacking group codenamed “Zarya” – believed to be collaborating with Russia’s FSB security service – penetrated the industrial control system of a Canadian natural gas pipeline facility in early 2023. In intercepted communications with their FSB handler, the hackers claimed they could trigger a pipeline explosion: they had the ability to “increase valve pressure, disable alarms, and initiate an emergency shutdown” at the station. The FSB officer overseeing the operation allegedly encouraged them to maintain access, anticipating that a successful sabotage would cause a devastating blast. Ultimately, no physical damage occurred – the Canadian Prime Minister later acknowledged a cyber incident had taken place but confirmed “no physical damage to any Canadian energy infrastructure” resulted. The breach was a wake-up call: it demonstrated Russian-affiliated actors’ reach into North American critical infrastructure and their intent to inflict kinetic effects via cyber means. Canada’s cybersecurity agency treated it as a serious near-miss, urging energy operators to strengthen defenses. Western analysts noted that if the hackers’ claims were true, it would mark the first known instance of a Russian hacktivist group gearing up to inflict destructive sabotage on Western industrial systems – blurring the line between state-directed cyber warfare and proxy cybercrime.

Occurrence
2023-02-25
Publication
2023-02-24T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
CA
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-02-24T23:00:00Z

    According to leaked U.S. intelligence documents, a pro-Russian hacking group codenamed “Zarya” – believed to be collaborating with Russia’s FSB security service – penetrated the industrial control system of a Canadian natural gas pipeline facility in early 2023. In intercepted communications with their FSB handler, the hackers claimed they could trigger a pipeline explosion: they had the ability to “increase valve pressure, disable alarms, and initiate an emergency shutdown” at the station. The FSB officer overseeing the operation allegedly encouraged them to maintain access, anticipating that a successful sabotage would cause a devastating blast. Ultimately, no physical damage occurred – the Canadian Prime Minister later acknowledged a cyber incident had taken place but confirmed “no physical damage to any Canadian energy infrastructure” resulted. The breach was a wake-up call: it demonstrated Russian-affiliated actors’ reach into North American critical infrastructure and their intent to inflict kinetic effects via cyber means. Canada’s cybersecurity agency treated it as a serious near-miss, urging energy operators to strengthen defenses. Western analysts noted that if the hackers’ claims were true, it would mark the first known instance of a Russian hacktivist group gearing up to inflict destructive sabotage on Western industrial systems – blurring the line between state-directed cyber warfare and proxy cybercrime.