30 Wind and Solar Farms in Poland Faced Coordinated Cyberattacks
On December 29, 2025, a coordinated cyberattack targeted over 30 wind and solar farms in Poland, along with a large combined heat and power plant and a manufacturing facility. The attacks occurred amidst severe winter conditions, threatening the nation's…
On December 29, 2025, a coordinated cyberattack targeted over 30 wind and solar farms in Poland, along with a large combined heat and power plant and a manufacturing facility. The attacks occurred amidst severe winter conditions, threatening the nation's energy stability.
The operations were destructive in nature, aimed at damaging critical infrastructure without data theft. These strikes represent the first documented destructive operation by a sophisticated attack group against European energy infrastructure.
The assault targeted power substations that connect renewable energy sources to the distribution network. Industrial automation devices were primary objectives, including:
Remote terminal units managing telecontrol operations Human-machine interfaces displaying facility status Protection relays safeguarding against electrical damage Communication equipment such as routers and network switches
After gaining access to internal networks , attackers conducted detailed reconnaissance. They executed their plan using damaged firmware and custom-built wiper malware on December 29.
The attacks occurred amidst severe winter conditions, threatening the nation's energy stability.
Communication channels between energy farms and the distribution system operator were disrupted; however, electricity generation remained unaffected.
Cert.pl analysts identified infrastructure linked to the attack, showing overlap with known threat groups such as "Static Tundra," "Berserk Bear," "Ghost Blizzard," and "Dragonfly." Researchers noted the attackers' capabilities against industrial devices and their historical focus on energy sectors. This marks the first destructive campaign attributed to this activity cluster, indicating a tactical shift.
Wiper Malware Deployment and Infection Mechanism
The attackers used identical wiper malware across multiple targets, deploying custom-built destructive software after prolonged infiltration. The malware focused on irreversible data destruction on targeted networks.
Using compromised accounts and stolen information, attackers prepared automated attack sequences for simultaneous activation. At the combined heat and power plant, the malware's execution was blocked by endpoint detection and response technology.
The manufacturing facility experienced a similar coordinated assault, although the objectives differed from energy targets. This pattern demonstrated sophisticated planning, with the malware acting as the final payload following extensive reconnaissance over several weeks.
Based on reporting by Cyber Security News.
