Case summary
Discovered in 2010, Stuxnet is the first known cyber-physical weapon, built to physically destroy centrifuges at the Natanz uranium enrichment facility. Using four zero-day exploits, the worm targeted Siemens S7 industrial control systems. The public technical analysis is solid; the attribution to a joint US–Israel operation has never been officially acknowledged.
Timeline
- 2009-06Compile timestamps of early variants point to this period.
- 2010-01IAEA inspectors logged an abnormal rise in centrifuge replacement at Natanz.
- 2010-06-17Belarusian firm VirusBlokAda first reported the malware.
- 2010-09Symantec and Langner analyses showed the target was centrifuge frequency converters.
- 2012-06-01The New York Times published its investigation describing the 'Olympic Games' programme.
People and connections
- Natanz
The uranium enrichment facility that was targeted.
- Symantec (W32.Stuxnet Dossier)
Author of a detailed public technical analysis.
- Ralph Langner
The ICS specialist who decoded the PLC payload's purpose.
- Siemens S7-315/417
The targeted PLC models; cascade and rotor-speed manipulation.
- Siemens S7-315/417 to NatanzThe payload triggered only on a specific cascade configuration
- Ralph Langner to Symantec (W32.Stuxnet Dossier)Independent analyses converged on the same target conclusion
Findings
That the malware targeted specific centrifuge cascades at Natanz is verified at code level.
Four zero-days and stolen code-signing certificates were used; this implies state-level resources.
Attribution to a joint US–Israel operation ('Olympic Games') is supported by named-source journalism but never officially confirmed.
The count of destroyed centrifuges (≈1,000) is an estimate derived from IAEA data; the exact figure is unknown.
Documents
Sources
Locations
- Natanz enrichment facility33.72°, 51.73°
Researcher's note
Interpretation: two distinct confidence levels are interleaved in the Stuxnet file: what the code did (certainty) versus who commissioned it (journalism plus context). Flattening the two into one sentence is the most common reporting error about this case.
Recent checks
- 2026-03-15Symantec report link updated after its move to Broadcom.

