Coordinated Cyberattacks Hit 30 Wind and Solar Farms Across Poland
On Tue, Dec 29, 2025, Poland encountered a series of coordinated cyberattacks on its critical energy infrastructure. These attacks targeted over 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant, which…
On Tue, Dec 29, 2025, Poland encountered a series of coordinated cyberattacks on its critical energy infrastructure. These attacks targeted over 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant, which supplies heating to approximately 500,000 customers. The attack occurred during extreme winter conditions, exacerbating vulnerabilities due to high energy demand.
The attackers aimed to cause destruction, similar to deliberate physical damage. They targeted both IT systems and industrial control devices, but the effort did not achieve the intended disruption. Energy production at renewable facilities continued without interruption, and heat supply to end users was maintained.
The primary focus of the attack was on power substations, which act as grid connection points between renewable energy sources and distribution system operators. The attackers targeted several industrial automation devices, including:
Remote Terminal Units (RTUs) for telecontrol and supervision Human-Machine Interfaces (HMIs) for operational status visualization Protection relays for electrical systems Communication infrastructure, such as serial port servers and network switches
On Tue, Dec 29, 2025, Poland encountered a series of coordinated cyberattacks on its critical energy infrastructure.
The attack involved firmware corruption, system file deletion, and the use of custom-built wiper malware. Although RTU damage led to a communication loss between substations and the Distribution System Operator, energy production continued unaffected.
The attack on the combined heat and power plant showed signs of extensive pre-attack preparation, including infrastructure infiltration and operational data theft. Attackers used stolen credentials to gain privileged access, allowing lateral movement within the network. Despite efforts to execute a destructive plan, the organization's Endpoint Detection and Response (EDR) software prevented significant damage.
A simultaneous operation targeted an unrelated manufacturing company using the same wiper malware as in the energy sector attacks. This indicates coordinated timing rather than a unified strategic intent, as attackers appeared to conduct multiple parallel operations.
An analysis of the compromised infrastructure, including VPS servers and network traffic, shows overlap with known activity clusters such as "Static Tundra" (Cisco), "Berserk Bear" (CrowdStrike), "Ghost Blizzard" (Microsoft), and "Dragonfly" (Symantec). Although this is the first publicly attributed destructive campaign from this cluster, the threat actor's focus on the energy sector and industrial device attack capabilities is consistent with observed methodologies.
These incidents highlight the increasing risk of sabotage against critical infrastructure, especially during periods of operational stress and extreme environmental conditions. Organizations managing industrial control systems should prioritize the deployment of EDR solutions, network segmentation, and credential hygiene as essential defensive measures.
Based on reporting by GBHackers.
