Drooid Logo
Back to story perspectives

Full Breakdown

Cyberattack on Poland's Power Grid: An Analysis of the December 2025 Incident

1/29/2026, 2:53:07 AM

Overview of the Cyberattack

In late December 2025, Poland's power grid faced a significant cyberattack attributed to the Russian state-sponsored hacking group Sandworm. The attack, which occurred on December 29-30, targeted communication devices at approximately 30 energy facilities, including two combined heat and power plants and systems managing renewable energy sources. Although the attackers employed a new data-wiping malware named DynoWiper, they failed to disrupt power generation or transmission, thanks to Poland's robust cybersecurity measures.

Attack Details and Methodology

The cyberattack involved disabling remote terminal units (RTUs), which are crucial for monitoring and controlling energy systems. According to cybersecurity firm Dragos, the attack appeared opportunistic rather than meticulously planned, lacking the coordinated sequencing seen in previous Sandworm operations, such as the 2015 Ukraine blackout. The attackers exploited vulnerabilities in edge systems, like firewalls, to gain access to the RTUs, which were configured similarly across multiple sites, facilitating a broader compromise.

Attribution and Historical Context

Polish officials and cybersecurity experts have attributed the attack to Sandworm, a group linked to Russia's military intelligence agency, the GRU. ESET, a cybersecurity firm, confirmed this attribution with medium confidence, noting the overlap in tactics and techniques with previous Sandworm operations. The timing of the attack coincided with the 10th anniversary of Sandworm's infamous 2015 attack on Ukraine's power grid, which resulted in significant blackouts. This historical context raises concerns about the strategic implications of targeting Poland, a NATO member and supporter of Ukraine.

Official Responses and Implications

Poland's Prime Minister Donald Tusk characterized the incident as the most severe cyberattack on the country's energy infrastructure in years, emphasizing the need for heightened cybersecurity measures. He stated, “Everything indicates that these attacks were prepared by groups directly linked to the Russian services.” The Polish government has since initiated plans to strengthen its cybersecurity framework, including legislative changes aimed at enhancing protections for critical infrastructure.

Criticism and Concerns

Despite the successful defense against the attack, experts warn that the incident highlights the persistent threat posed by state-sponsored cyber actors. The attempt to disrupt communications between renewable energy installations and grid operators could have led to cascading failures during peak demand periods. Analysts emphasize the need for improved national and international cybersecurity cooperation to mitigate such risks in the future.

Conflicting Reports and Gaps

While the attack did not result in any confirmed outages, questions remain regarding the attackers' intentions and the effectiveness of Poland's cybersecurity defenses. ESET noted, “We’re not aware of any successful disruption occurring as a result of this attack,” but the exact reasons for the failure of DynoWiper remain unclear. This ambiguity underscores the complexities of assessing the impact of cyberattacks on critical infrastructure.

Verbatim Quotes

  • “Everything indicates that these attacks were prepared by groups directly linked to the Russian services.” — Donald Tusk, Prime Minister of Poland
  • “We’re not aware of any successful disruption occurring as a result of this attack.” — ESET Research

This incident serves as a critical reminder of the evolving landscape of cyber threats targeting energy infrastructure, necessitating ongoing vigilance and adaptation in cybersecurity strategies.