Poland's power grid
Incident posture
Linked entities
- Victim
- Poland's power grid
- Threat actors
- 2 actors
- Sources
- 7 sources
Timeline
Summary
Russian military intelligence-affiliated hackers launched a destructive cyberattack against Poland's energy sector at the end of December, targeting two combined heat and power plants along with a renewable energy management system overseeing wind and solar farms. The attackers exploited weak security practices, including default credentials and the absence of multi-factor authentication, to deploy DynoWiper, a data-erasing malware designed to render monitoring and control systems inoperable. The attacks were thwarted before causing a blackout or widespread outage, though authorities estimated that success might have disrupted service to roughly half a million households. Cybersecurity firms attributed the operation to the notorious Sandworm group with ties to Russia's GRU, while Polish officials pointed to Russian state-sponsored actors as responsible for what the energy minister called the strongest assault on the country's power infrastructure in years.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On December 29 and 30, 2025, Poland's energy sector experienced a coordinated cyberattack targeting two combined heat and power (CHP) plants along with a renewable energy management system responsible for overseeing electricity generated from wind turbines and solar farms. Polish Energy Minister Milosz Motyka characterized the incident as the "strongest attack" on the country's energy infrastructure in years, noting that it departed from prior attack patterns by focusing on communication links between renewable installations and power distribution operators rather than large power units or transmission networks. Initial local media reporting suggested that a successful attack could have disrupted heat and power for approximately 500,000 households, though Prime Minister Donald Tusk later clarified that critical infrastructure, including transmission networks, was never actually threatened.
The attackers gained access to the targeted systems by exploiting significant security weaknesses. According to a technical report published by Poland's Computer Emergency Response Team (CERT), part of the Ministry of Digital Affairs, the compromised systems relied on default usernames and passwords and had multi-factor authentication disabled. Once inside, the hackers deployed wiper malware designed to erase data and render the affected systems inoperable. The specific malware, dubbed DynoWiper (also identified as Win32/KillFiles.NMO), was designed to delete critical files and destroy computer functionality, with the apparent intent of causing a power outage. Poland's CERT described the operations as "purely destructive in nature" and comparable to "deliberate acts of arson."
Cybersecurity firm ESET obtained a copy of the DynoWiper malware and analyzed it following the incident. The firm attributed the attack to the Russian state-sponsored advanced persistent threat (APT) group known as Sandworm, also referred to as APT44, BlackEnergy Lite, Seashell Blizzard, Telebots, and Voodoo Bear. ESET's attribution was made with medium confidence based on a strong overlap between the tactics, techniques, and procedures (TTPs) observed in the DynoWiper samples and those previously linked to Sandworm, including the group's historical use of destructive wiper malware against Ukrainian energy infrastructure. However, researchers noted that unlike Sandworm's earlier Industroyer malware, which specifically targeted operational technology (OT) environments, the DynoWiper samples examined were confined to IT environments, representing a deviation from the group's typical mode of operation that contributed to the medium (rather than high) confidence assessment. The attack's timing, occurring nearly exactly a decade after Sandworm's 2015 BlackEnergy assault on Ukraine's power grid, was highlighted as a notable connection by multiple researchers.
Although Poland's CERT officially attributed the campaign to a different Russian government hacking group known as Berserk Bear (also called Dragonfly) typically associated with cyberespionage rather than destructive attacks, ESET and Dragos both publicly identified Sandworm as the likely perpetrator. The incident reflects an escalating pattern of Russian cyber operations against Polish critical infrastructure since the start of the war in Ukraine in February 2022, with Poland's digital affairs minister reporting that Russia's military intelligence had tripled its resources dedicated to such actions against Poland in 2025. Of the 170,000 cyber incidents identified in Poland during the first three quarters of 2025, a significant portion was attributed to Russian actors.
Polish authorities successfully detected and contained the attack before it could achieve its intended disruptive effects. The wiper malware was stopped at the targeted heat-and-power plants, though it successfully rendered inoperable the monitoring and control systems at the affected wind and solar farms. Despite the deployment of destructive malware, the attacks failed to disrupt power at any of the targeted facilities, and the Polish government confirmed there was no blackout or other negative consequences. The Computer Emergency Response Team's technical report concluded that even if the attack had succeeded, it would not have affected the overall stability of the Polish power system during the period in question. Prime Minister Tusk stated publicly that Poland's cybersecurity defenses had functioned effectively and that critical infrastructure remained secure throughout the incident, while Energy Minister Motyka confirmed that the attack had been thwarted before causing harm.
Sources
Sources available to members: 7 sources.