Sandworm Accused of Cyberattack on Poland’s Power Grid
Polish authorities and reporting tied to ESET research attributed a disruptive cyber incident affecting Poland’s electricity grid to Russia-linked threat actors, with Sandworm named as the likely operator behind the operation in late 2025. The incident was characterized as a targeted attack on critical infrastructure, reinforcing ongoing concerns about state-aligned activity against European energy networks.
A separate malware-newsletter roundup recirculated the attribution as one of many items, while an unrelated CSO Online feature focused on forward-looking CISO predictions for 2026 and did not provide incident-specific details. Executive teams should treat the Poland grid activity as part of the broader pattern of Russian state-linked operations against OT/ICS environments, with emphasis on validating segmentation, monitoring for lateral movement into OT, and ensuring incident response playbooks cover grid/industrial disruption scenarios.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Reporting accuses Russian hackers of attacking Poland’s grid
By January 2026, news reporting said Russian hackers were accused of carrying out the attack on Poland’s power grid. One roundup specifically referenced reporting that Sandworm was behind the late-2025 incident.
Cyberattack hits Poland’s power grid in late 2025
A cyberattack targeted Poland’s electricity grid in late 2025. The incident was later cited in reporting and malware roundups as a significant attack on critical infrastructure.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


