Poland's Energy Sector Faced Coordinated Cyberattacks Targeting Renewable Facilities and Deploying Wiper Malware
EUROPE - The U.S. Cybersecurity and Infrastructure Security Agency issued an advisory on February 10 highlighting a destructive cyber incident in Poland’s energy sector from late December.
The attacks targeted operational technology and industrial control systems at over 30 wind and solar farms, a combined heat and power plant serving nearly half a million customers, and a manufacturing firm producing energy components.
“The malicious cyber activity caused loss of view and control between facilities and distribution system operators, destroyed data on human machine interfaces (HMIs), and corrupted system firmware on OT devices. While the affected renewable energy systems continued production, the system operator could not control or monitor them according to their intended design.” - CISA
Attackers exploited vulnerable FortiGate firewalls with default credentials to access networks, then used remote desktop protocol and virtual network computing for lateral movement before deploying custom wiper malware called DynoWiper to encrypt files and disrupt communications.
While no interruptions to power or heat occurred, the event exposed risks in distributed renewable energy systems and prompted recommendations for enhanced edge device security.
CERT Polska’s incident report from January 30 detailed the assaults occurring in morning and afternoon hours on December 29. The malware aimed to cause irreversible data destruction, but endpoint detection tools at the combined heat and power plant blocked execution.
Polish authorities attributed the operation to the Russian-linked group Static Tundra, also known as Electrum or Berserk Bear, based on infrastructure overlaps and tactics matching prior campaigns.
Incident Details
The cyberattacks affected a broad segment of Poland’s energy infrastructure on December 29. Over 30 renewable facilities, mainly wind and solar farms, lost communication with distribution system operators due to compromised remote terminal units.
A large combined heat and power plant experienced attempts to erase data across internal devices, preceded by prolonged infiltration and exfiltration of operational information. An unrelated manufacturing company was also struck in what appeared to be an opportunistic extension of the campaign.
Despite the scale, operations remained uninterrupted with no blackouts or heat losses reported. Low temperatures and snowstorms at the time amplified potential risks, but swift response contained the threats. The incidents marked a shift toward destructive actions in the group’s activities.
Official Statements
U.S. Cybersecurity and Infrastructure Security Agency (CISA), February 10, 2026: “A December 2025 cyberattack on Poland’s Energy Sector targeted OT & ICS at renewable energy plants, a combined heat & power plant, and a manufacturer, using vulnerable edge devices to deploy wiper malware.”
CERT Polska, January 30, 2026: “On 29 December 2025, in the morning and afternoon hours, coordinated attacks took place in Polish cyberspace. They were directed at more than 30 wind and solar farms, a company manufacturing components for the energy industry, and a major combined heat and power plant.”
Polish Minister of Digital Affairs Krzysztof Gawkowski, January 13, 2026: “Poland thwarted a significant cyberattack targeting the nation’s energy grid as 2025 ended, warding off a blackout that could have affected millions.”
Polish Energy Minister Miłosz Motyka, January 8, 2026: “The unsuccessful cyberattacks at the end of 2025 targeted one combined heat and power plant and numerous individual renewable energy installations across the country.”
Polish Prime Minister Donald Tusk, January 15, 2026: “Poland successfully defended itself, and there was no blackout or other negative consequences."
Full Report & Analysis
The full report includes expert analysis and risk assessment.
Full Report & Analysis →