What is the 2025 cyberattack on Poland’s energy system?
The cyberattack on Poland’s energy system was a coordinated sabotage operation on 29 and 30 December 2025 in which attackers used wiper malware and destructive commands against more than thirty wind and solar farms, a large combined heat and power (CHP) plant and a manufacturing company in Poland, bricking control equipment at the farms. The lights stayed on: the farms kept generating, but grid operators lost visibility and remote control of the installations. Dragos regards the incident as the first major, coordinated attack on distributed energy resources and as a clear escalation of Russian cyber sabotage inside the European Union. For anyone operating critical infrastructure, it is an instructive case of what goes wrong with default passwords and internet-facing VPN access.
🗓️ How did the attack unfold over time?
CERT Polska, Poland’s national CERT, published a detailed incident report on 30 January 2026. It shows that the destructive day was the culmination of months of preparation.
| Date | Event |
|---|---|
| March – May 2025 | First activity at the CHP plant: login to a jump host via a FortiGate perimeter device, then RDP to the domain controller |
| March – July 2025 | Reconnaissance focused on systems with “scada” in their names, an attempted credential dump from memory, a Kerberos attack and, in the second half of July, a full dump of the Active Directory database |
| 8 December 2025 | Attacker changes the configuration of HMI computers at the farms: administrative shares enabled, a firewall rule called “Microsoft Update” opened for TCP port 445 |
| 25 December 2025 | Network scans and login attempts against Mikronika RTUs at every affected farm |
| 29 December 2025 | Destructive actions in the morning and afternoon at the farms, the CHP plant and the manufacturer, during severe cold and snowstorms |
| 13 – 16 January 2026 | The Polish government speaks of Russian sabotage and an attack that came close to a blackout |
| 23 January 2026 | ESET discloses the DynoWiper malware and points to Sandworm |
| 28 January 2026 | Dragos links the attack to ELECTRUM |
| 30 January 2026 | CERT Polska publishes its technical incident report |
🏭 Which installations and devices were affected?
The attack hit three kinds of organisation. At the wind and solar farms, the focus was the grid connection point: the unmanned 110/30 kV substation through which the distribution system operator monitors and switches the site remotely via SCADA.
| Target | Affected components | Consequence |
|---|---|---|
| More than 30 wind and solar farms | Hitachi RTU560 RTUs, Linux-based Mikronika RTUs, Hitachi Relion 650 protection relays (IEDs), HMIs on Windows 10, Moxa NPort serial device servers, FortiGate firewalls | Communication with the distribution system operator and remote control were lost; electricity generation continued |
| CHP plant (heat for almost 500,000 customers) | Workstations and servers in the Windows domain | DynoWiper was pushed out via Group Policy, but EDR halted the overwriting on more than a hundred machines; heat supply was unaffected |
| Manufacturing company | Windows domain | PowerShell wiper LazyWiper deployed via Group Policy; CERT Polska describes this target as opportunistic |
According to transmission system operator PSE, the stability of the Polish power system was never at risk. Even if all thirty farms had tripped at once, the analysis found the grid would have coped. The government publicly referred to two CHP plants, whereas the CERT Polska report describes one in detail.
🔧 Which techniques did the attackers use?
What stands out is how few sophisticated exploits were required. Nearly every step relied on default settings:
- Access through the VPN — every farm had a FortiGate acting as VPN concentrator and firewall, with the VPN interface exposed to the internet and no MFA; some devices had been vulnerable for long periods, and accounts were often reused across several farms
- Corrupted RTU firmware — using the “Default” account on the web interface, the attacker uploaded tampered firmware that left the RTU560 stuck in a reboot loop; secure update with signature verification had existed since version 13.2.1 but was not enabled anywhere
- Deleting files on devices — Mikronika RTUs via SSH with root privileges, Relion relays via a default FTP account, after which the relays would no longer boot
- Factory reset as sabotage — every FortiGate was reset to factory settings; the Moxa servers were also given a new password and the unreachable IP address 127.0.0.1 after their reset, which slowed down remote recovery
- Lateral movement in the domain — at the CHP plant via jump hosts, PsExec, Impacket and stolen Active Directory data; the wiper reached every machine through a Group Policy object
- Theft from the cloud — with stolen credentials, the attacker downloaded documents on OT modernisation and SCADA from Microsoft 365
Destruction inside the substations was at least partly automated: devices were attacked in ascending order of IP address. In MITRE ATT&CK for ICS terms, the emphasis was on denying operators control and visibility rather than physically switching equipment as Industroyer did.
🕵️ Who was behind the attack?
Everyone involved holds Russia responsible, but views on the exact group differ. That is unusual and deserves an honest account:
| Organisation | Attribution | Confidence and reasoning |
|---|---|---|
| CERT Polska | Static Tundra, also known as Berserk Bear, Ghost Blizzard and Dragonfly; a cluster linked to Center 16 of Russia’s FSB security service | Strong overlap in attack infrastructure; the first publicly described destructive operation by this cluster |
| ESET | Sandworm (GRU) | Medium confidence; tradecraft resembles earlier Sandworm wipers in Ukraine, such as ZOV |
| Dragos | ELECTRUM, an OT-focused cluster that overlaps with Sandworm but which Dragos tracks separately | Moderate confidence |
CERT Polska does see similarities between DynoWiper and earlier Sandworm wipers, but considers them too weak to attribute the attack to Sandworm. Prime Minister Donald Tusk said there were many indications that the attacks had been prepared by groups directly linked to the Russian special services. Digital Affairs Minister Krzysztof Gawkowski described an attack that came “very close to a blackout”.
☀️ Why are distributed energy resources a new attack surface?
A conventional coal or gas plant has a staffed control room, a security team and one well-guarded network perimeter. A wind or solar farm is usually unmanned and managed entirely remotely by an operator, a maintenance contractor and the grid operator. That creates a different risk profile:
- Many small perimeters — hundreds of farms, each with its own firewall and VPN, often run by a small organisation
- Shared passwords — installers use the same accounts at dozens of sites, so one leaked password opens many doors
- Equipment left on factory settings — RTUs, relays and serial servers are rarely hardened because they sit “behind the firewall”
- Scale as a weapon — one farm is insignificant to the grid, but a simultaneous attack on hundreds of installations may not be
The same concern applies to solar inverters, which are often managed through the manufacturer’s cloud; see Solar Inverter Cybersecurity. In Poland grid stability was not threatened, but as the share of distributed generation grows, the potential impact of such an attack increases every year.
🛡️ What can Dutch and European energy companies learn from it?
Dutch energy companies large enough to fall under the Cybersecurity Act have had to take appropriate measures since 15 August 2026, including an early warning of any significant incident within 24 hours, followed by an incident notification within 72 hours. Energy is a sector of high criticality, supervised by the RDI. Whether an individual farm is in scope depends on the size of its operator, but the lessons apply to everyone:
- Secure remote access — MFA on every VPN, no management interfaces facing the internet, unique accounts per site and fast patching of edge devices; see also internet-exposed OT.
- Harden every field device — change default passwords, disable unnecessary services such as FTP and web interfaces, and actually switch on signed firmware updates.
- Segment inside the substation — network segmentation stops whoever controls the firewall from reaching the RTU, relays and HMI straight away.
- Keep configurations and firmware offline — an immutable backup of RTU projects, relay settings and firewall configurations makes fast recovery after a factory reset possible.
- Monitor small sites too — EDR on Windows systems stopped the wiper at the CHP plant; passive network monitoring helps you spot scans such as those on 25 December in time.
- Rehearse manual operation — plan how you will run or safely disconnect farms without remote control, and know how long replacing a bricked RTU takes.
❓ Frequently asked questions
Did the cyberattack in Poland cause a power outage?
No, the cyberattack on Poland’s energy system did not cause a power cut. The wind and solar farms kept supplying electricity, but the grid operator lost visibility and control of more than thirty installations. At the CHP plant, EDR stopped the wiper before heat supply was put at risk.
What is DynoWiper?
DynoWiper is the wiper malware used in the cyberattack on Poland’s energy system against HMI computers at the farms and workstations at the CHP plant. The name was given by ESET; the malware overwrites and deletes files without demanding a ransom. A second wiper, the PowerShell-based LazyWiper, was used at the manufacturing company.
Who attacked the Polish power grid?
The attack on the Polish power grid is attributed to Russia, but the specific group is disputed. CERT Polska points to Static Tundra, a cluster linked to the FSB, while ESET names Sandworm and Dragos names ELECTRUM, both with medium or moderate confidence.
How did the attackers get into the wind and solar farms?
The attackers got in through FortiGate firewalls whose VPN was exposed to the internet without multi-factor authentication. They then used default passwords on RTUs, protection relays, HMIs and serial servers to render those devices unusable.
Could a similar attack happen in the Netherlands?
An attack like the one on Poland’s energy system could also happen in the Netherlands, which has many distributed wind and solar farms managed remotely. Dutch operators use comparable RTUs, firewalls and VPN solutions, so the same weaknesses may well exist here.
Why does this attack matter for OT security?
According to Dragos, the cyberattack on Poland’s energy system is the first major, coordinated attack on distributed energy resources, and CERT Polska calls it the first publicly described destructive operation by the cluster involved. It shows that attackers do not need exotic OT malware when default settings, reused passwords and VPNs without MFA leave the door open.
📌 In summary
The December 2025 cyberattack on Poland’s energy system destroyed control equipment at more than thirty wind and solar farms and tried to wipe a CHP plant, without causing a power cut. The attackers exploited VPNs without MFA and default passwords on RTUs, relays and HMIs. If you manage distributed installations, start with secure remote access, hardened field devices, offline backups and monitoring at every site.
