CSIDB logo
Incident

Poland's renewable energy facilities

Incident posture

Attack window
Dec 2025
Location
Poland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 14:27

Linked entities

Victim
Poland's renewable energy facilities
Threat actors
4 actors
Sources
2 sources

Timeline

Occurred
Dec 2025
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

Attackers breached Poland's renewable energy facilities by exploiting internet-exposed FortiGate VPN devices that lacked multi-factor authentication and used default credentials. They accessed industrial control systems at wind and solar farms, a combined heat and power plant, and a manufacturing firm, corrupting firmware, deleting files, resetting devices to factory settings, and deploying wiper malware on Windows hosts. The actions disrupted communication with grid operators but did not halt electricity generation, and the intrusions were linked by Polish CERT to a Russia‑linked threat group also identified by other vendors as Sandworm or Electrum.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On 29 December 2025 a series of coordinated cyberattacks unfolded across Poland’s critical infrastructure, striking numerous wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant that supplies heat to nearly half a million customers. The attackers gained their initial foothold through internet‑exposed FortiGate perimeter devices configured as VPN concentrators and firewalls, where the VPN interface was reachable from the Internet and allowed authentication to accounts defined in the configuration without multi‑factor authentication. In the renewable energy sector at least 30 wind and photovoltaic facilities were targeted, with the focus on grid connection point substations where the plants interface with distribution system operators. After gaining access, the attackers compromised industrial control systems including RTU controllers, protection relays, HMI computers, and serial device servers from vendors such as Hitachi Energy, Mikronika, and Moxa. Destructive actions observed on these devices included uploading corrupted firmware, deleting operating files, and resetting the equipment to factory settings, which caused a loss of communication between the facilities and their distribution system operators while electricity generation continued.

On the same day the attackers directed a wiper malware campaign against the CHP plant, aiming for irreversible data loss across the organization’s internal network; evidence indicated that the intrusion had been preceded by months of unauthorized access, internal reconnaissance, and theft of sensitive operational information, during which privileged Active Directory credentials were obtained enabling lateral movement. A custom wiper named DynoWiper was later deployed via Group Policy Objects distributed from a domain controller, and an EDR platform detected and blocked its execution, limiting the scope of damage. In parallel, the attackers attempted to disrupt operations at the private manufacturing company by exploiting a Fortinet device whose configuration had been stolen and publicly disclosed on a criminal forum; after establishing access they modified device settings to preserve persistence, moved laterally to achieve administrative rights in the Windows domain, and deployed a PowerShell‑based wiper referred to as LazyWiper through Group Policy Objects with the goal of destroying business‑critical data.

The attack had begun as early as March 2025 with reconnaissance, credential‑harvesting, and unauthorized data access detected through July, and each targeted facility was found to have Fortinet FortiGate devices exposed to the Internet using default credentials and lacking multi‑factor authentication. On 29 December the threat actors initiated disruptive and destructive actions, some of which were partially automated, targeting RTU560 remote terminal units and Relion protection relays from Hitachi Energy, RTUs and HMIs from Mikronika, and Moxa NPort serial device servers, using default credentials and exposed web interfaces to reset devices, change passwords, and assign IP addresses that blocked legitimate access. Polish officials publicly blamed Russia for the incident, while cybersecurity firm ESET attributed the activity with medium confidence to the APT group Sandworm based on malware analysis, and Dragos attributed it with moderate confidence to a group it tracks as Electrum, noting Sandworm’s ties to Russian military intelligence and its history of destructive attacks such as the 2016 Ukraine power grid incident. CERT Polska assessed that all incidents were carried out by the same threat actor and were purely destructive in nature, noting that although no electrical outages occurred, the level of access obtained posed a risk of disrupting electricity generation at the affected sites. The combined loss of capacity across the approximately 30 facilities would not have affected the stability of the Polish power system during the period in question. No evidence of zero‑day vulnerabilities was reported by the involved vendors, with Mikronika confirming that the attackers leveraged only default credentials. The indicators associated with the intrusion had been present earlier in 2025, indicating sustained access and preparation before the destructive phase. The EDR detection and subsequent blocking of the wiper malware limited the overall impact, preserving monitoring and remote‑control capabilities despite the loss of communication at the targeted substations.

Sources

Sources available to members: 2 sources.

CSIDB