CSIDB logo
Incident

Polish Power Grid

Incident posture

Attack window
Dec 2025
Location
Poland
Status
Resolved
CIA posture
Available to members
Updated
2026-08-13 01:44

Linked entities

Victim
Polish Power Grid
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
Dec 2025
Discovered
Undetermined
Disclosed
Jan 2026
Resolved
Jan 2026

Summary

Poland's power grid was hit by a cyberattack that deployed data-wiping malware dubbed DynoWiper, which analysts linked to the Russia-aligned Sandworm APT with medium confidence. The operation aimed to disrupt communications between renewable energy installations and distribution operators but was repelled, resulting in no blackout or lasting impact on electricity delivery.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late December 2025, specifically the last week of December, Poland's power grid experienced a cyberattack that targeted the communication links between renewable energy installations and distribution operators. The attack involved data-wiping malware identified by ESET as DynoWiper, detected as Win32/KillFiles.NMO with SHA-1 hash 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6. ESET researchers attributed the malware to the Russia-aligned APT group Sandworm with medium confidence based on overlap with previous Sandworm wiper activity. Polish officials described the incident as the largest cyberattack targeting the country's power system in years and stated that the coordinated operation was successfully repelled, failing to cause a blackout or compromise critical infrastructure. The attack occurred on the 10th anniversary of the Sandworm-orchestrated BlackEnergy attack against the Ukrainian power grid in December 2015, which had resulted in the first known malware-facilitated blackout affecting approximately 230,000 people for several hours.

Despite the use of wiper malware intended to erase data and disrupt operations, ESET researchers reported that they were not aware of any successful disruption resulting from the attack on Poland's grid. Polish officials confirmed that the attack did not lead to a loss of electricity delivery or any compromise of essential infrastructure. The incident was part of a broader pattern of Sandworm activity; ESET's APT Activity Report for April to September 2025 noted regular wiper attacks against targets in Ukraine. Additionally, the group had previously deployed wipers such as AcidRain in 2022 that disabled 270,000 satellite modems in Ukraine. Furthermore, ESET reported that Sandworm had unleashed multiple wipers on universities and critical infrastructure in the preceding year. No further technical details about the attack's execution or the specific systems affected beyond the communication links were disclosed in the available sources.

Sources

Sources available to members: 3 sources.

CSIDB