Full Breakdown
Poland Attributes Cyberattacks to Russian FSB
1/31/2026, 9:41:32 PM
Overview of the Cyberattacks
In late December 2025, Poland experienced a series of cyberattacks targeting its energy infrastructure, specifically affecting 30 renewable energy facilities, a manufacturing firm, and a combined heat and power plant serving nearly 500,000 customers. Polish officials have attributed these attacks to Russia's Federal Security Service (FSB), describing them as the most severe cyber incident in recent years. The attacks coincided with severe winter weather conditions in Poland, raising concerns about the potential for widespread power outages.
Attribution and Analysis
The report from Poland's Computer Emergency Response Team (CERT Polska) indicated that the attacks were "purely destructive in nature," aiming to irreversibly damage data within the targeted facilities. Although the attackers sought to destroy critical data, security measures prevented the full extent of the damage. The FSB hacking operation involved in these attacks is known by several names, including "Berserk Bear" and "Dragonfly." An August 2025 FBI report linked these groups to the FSB's specialized unit, Center 16, which has historically focused on the energy sector.
However, there is some debate among cybersecurity experts regarding the attribution of the malware used in these attacks. The Slovakia-based cybersecurity firm ESET has suggested that the malware overlaps with previous operations attributed to a different Russian military intelligence unit known as Sandworm. ESET's analysis indicates that while the FSB may have been involved, other hacking groups could have contributed to the operation.
Implications and Concerns
John Hultquist, chief analyst at Google Threat Intelligence Group, noted that if the attacks are indeed linked to Berserk Bear, it marks a significant shift from espionage to destructive actions. He expressed concerns about the implications for global security, particularly in light of the upcoming Winter Olympics, where Russia has previously attempted to disrupt events through cyberattacks.
Poland's Energy Minister Milosz Motyka reported that the country has faced an increasing number of cyber threats since Russia's invasion of Ukraine in February 2022. Deputy Prime Minister Krzysztof Gawkowski warned that Poland came "very close" to experiencing power outages due to these attacks. Prime Minister Donald Tusk convened an urgent meeting on January 15 to address the situation, acknowledging evidence of Russian intelligence services' involvement, although definitive proof remains elusive.
Official Responses
The Russian government has consistently denied any involvement in cyberattacks against Poland or other nations. The Russian embassy in Washington did not respond to requests for comment regarding these specific allegations.
Conflicting Reports and Gaps
While Polish officials attribute the cyberattacks to the FSB, ESET's analysis raises questions about the involvement of multiple hacking groups, including Sandworm. This discrepancy highlights the complexities of attributing cyberattacks and the challenges in establishing definitive proof of responsibility.
Verbatim Quotes
- "This period coincided with low temperatures and snowstorms affecting Poland, shortly before New Year's Eve." — CERT Polska Report
- "They have the means, the question was always did they have the motivation." — John Hultquist, Google Threat Intelligence Group
- "Disruptive cyberattacks are a very real threat." — John Hultquist, Google Threat Intelligence Group
