Full Breakdown
Coordinated Cyberattacks Target Poland's Energy Infrastructure
2/1/2026, 8:25:07 PM
Overview of the Cyberattacks
On December 29, 2025, Poland experienced a series of coordinated cyberattacks that targeted over 30 wind and solar farms, a major combined heat and power (CHP) plant, and a manufacturing company. The attacks were executed during severe winter weather, aiming to disrupt communications and remote control of the energy infrastructure. Despite the scale of the attacks, electricity generation and heat supply remained uninterrupted, as confirmed by CERT Polska, the Polish computer emergency response team.
Attribution and Threat Actor
CERT Polska attributed the attacks to a threat cluster known as Static Tundra, which is linked to Russia's Federal Security Service (FSB) Center 16. This attribution is supported by various cybersecurity firms, including Cisco, CrowdStrike, and Microsoft, which have tracked the group under multiple names such as Berserk Bear and Dragonfly. However, other firms like ESET and Dragos have suggested that the malware used in the attacks may also be associated with Sandworm, a Russian military intelligence hacking unit. The attribution remains contested, with some analysts noting that while there are similarities between the malware used, the evidence is not definitive.
Attack Methodology
The attackers exploited vulnerabilities in FortiGate VPN/firewall devices, often lacking multi-factor authentication, to gain initial access. They employed a combination of known vulnerabilities and reused credentials to move laterally across the targeted sites. The attacks involved the deployment of destructive malware, specifically DynoWiper and LazyWiper, designed to erase data and disrupt operations. DynoWiper was executed directly on human-machine interface (HMI) computers, while LazyWiper was distributed via PowerShell scripts within Active Directory environments.
Impact and Response
The Polish government has responded to these incidents by enhancing cybersecurity measures and initiating new legislative initiatives aimed at protecting critical infrastructure. Polish Energy Minister Milosz Motyka reported that the country faced close calls with power outages due to these cyberattacks. Prime Minister Donald Tusk convened an urgent meeting to address the situation, acknowledging the potential involvement of Russian intelligence services while noting the lack of definitive proof.
Criticism and Concerns
The incident has raised alarms about the vulnerability of distributed energy resources (DERs) and the need for improved operational technology (OT) and information technology (IT) security within the energy sector. Analysts have expressed concerns about the evolving nature of cyber threats, highlighting a shift from espionage to overt sabotage. John Hultquist, chief analyst at Google Threat Intelligence Group, emphasized the seriousness of the situation, suggesting that the motivation for such attacks has escalated.
Verbatim Quotes
- "This is the first publicly described destructive activity attributed to this cluster." — CERT Polska
- "The attacker gained access to the infrastructure using multiple accounts that were statically defined in the device configuration and did not have two-factor authentication enabled." — CERT Polska
- "The malware used in the incident involving renewable energy farms was executed directly on the HMI machine." — CERT Polska
Conclusion
The coordinated cyberattacks on Poland's energy infrastructure represent a significant escalation in the targeting of critical systems. As investigations continue, the incident underscores the urgent need for enhanced cybersecurity measures to protect against future threats.
