Cyber Incident Victim: Poland's power grid
Timeline
Summary
Poland's power grid was targeted with wiper malware named DynoWiper in an attempt to disrupt electricity distribution, but the attack did not succeed in causing a blackout. The malware resembles previous Russian wiper tools such as BlackEnergy and AcidRain, which have been used against Ukrainian infrastructure. There is no indication of how or why the wiper failed to achieve its intended effect.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In late December 2025, during the last week of the month, Poland’s power grid experienced what officials described as the largest cyberattack targeting the country in years. The attack focused on the communication links between renewable energy installations and the distribution operators that manage electricity flow. Security analysis identified the malicious software used as a data‑wiping tool that ESET later named DynoWiper, which is detected as Win32/KillFiles.NMO. The SHA‑1 hash associated with this malware is 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6.

ESET researchers examined the malware and its associated tactics, techniques and procedures and attributed the intrusion to the Russia‑aligned Sandworm APT group with medium confidence, citing a strong overlap with previous Sandworm wiper activity. The timing of the attack coincided with the tenth anniversary of the Sandworm‑orchestrated cyberattack on Ukraine’s power grid in December 2015, which had used the BlackEnergy malware to cause the first known malware‑facilitated blackout affecting roughly 230,000 people. Sandworm has a documented history of deploying wiper malware against Ukrainian critical infrastructure, including universities and energy sector targets, throughout 2022 and 2025. These historical patterns informed the analysts’ assessment of the group’s involvement in the Polish incident.
Polish officials stated that the coordinated operation was successfully repelled and that it failed to cause a blackout or to compromise critical infrastructure. ESET researchers noted that they were not aware of any successful disruption resulting from the attack. The attack occurred during the last week of December 2025, as reported by multiple sources. No further details about specific containment or remediation steps were disclosed in the available sources.
