Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptionoperational-disruptionindustrial-control-system-vulnerability

Destructive Cyberattack on Poland’s Energy Sector via Vulnerable Edge Devices

Updated 3mo agoFirst seen Feb 10, 202610 sources

Poland’s Computer Emergency Response Team reported that a destructive cyber incident in December 2025 compromised OT/ICS environments across the country’s energy sector, including renewable energy plants (wind and photovoltaic), a combined heat and power facility, and at least one manufacturing organization. The intrusion reportedly began through vulnerable internet-facing edge devices, after which the actor deployed wiper malware that damaged remote terminal units (RTUs), destroyed data on human-machine interfaces (HMIs), and corrupted firmware on OT devices—resulting in a loss of operator “view and control” even where renewable generation continued producing power but could not be monitored or controlled as designed. Reporting indicated the activity overlapped with infrastructure associated with a Russian government-linked hacking group.

CISA issued an alert to U.S. critical infrastructure organizations to amplify the Polish findings and emphasize mitigations for energy-sector OT/ICS defenders, highlighting the ongoing risk from end-of-support edge devices and the need to harden remote access paths, credential hygiene (including default credentials), and incident response planning for scenarios where OT devices may become inoperable or permanently damaged due to firmware corruption. Separate industry commentary and a Dark Reading article provided broader context on the evolution of OT threats (e.g., lessons from Ukraine’s 2015 grid attack and emerging “living-off-the-plant” techniques), but did not add incident-specific details about the Poland event beyond reinforcing the general trend of increasing attacker capability and interest in industrial environments.

Share:
Destructive Cyberattack on Poland’s Energy Sector via Vulnerable Edge Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 13, 20264mo ago

UK NCSC warns critical infrastructure after Poland attack

Following the Poland incident, the UK's National Cyber Security Centre issued a severe cyberthreat alert to critical infrastructure operators, warning that similar targeting could escalate quickly. The guidance urged resilience improvements including vulnerability management, secure configuration, access controls, monitoring, threat hunting, and segmentation.

Feb 11, 20264mo ago

Poland incident drives debate over attribution and response thresholds

By mid-February 2026, public reporting highlighted conflicting attribution assessments linking the operation to Russia-associated actors including Static Tundra/Berserk Bear, Sandworm, and Dragos's Electrum cluster. The failed but potentially harmful attack also triggered debate over whether such cyber operations meet legal or strategic thresholds for retaliation under NATO and international law.

Feb 10, 20264mo ago

CISA issues alert amplifying Poland incident and OT/ICS mitigations

On 2026-02-10, CISA published an alert to amplify CERT Polska's findings and warn critical infrastructure operators about OT and ICS security gaps exposed by the Poland incident. The agency emphasized risks from unsupported edge devices and default credentials, and recommended mitigations such as firmware verification, password changes, and OT-focused incident response planning.

Jan 30, 20265mo ago

CERT Polska publishes energy sector incident report

On 2026-01-30, CERT Polska published its report on the December 2025 incident, describing three parallel campaigns and warning that the attack could have left nearly half a million residents without heat if it had succeeded. The report characterized the operation as technically unprecedented in scale and highlighted overlap with Russia-linked infrastructure.

Dec 29, 20256mo ago

Attackers disrupt OT systems with wiper malware and edge-device compromise

The attackers gained access through vulnerable or misconfigured internet-facing edge devices and, in some cases, default credentials, then pivoted into OT environments. They deployed wiper malware that damaged RTUs, destroyed HMI data, and corrupted OT device firmware, causing loss of view and control between facilities and operators even though power generation continued.

Coordinated cyberattack begins against Poland's energy sector

Beginning on 2025-12-29, attackers targeted Poland's energy infrastructure, including more than 30 wind and photovoltaic farms, a combined heat-and-power plant, and related organizations. The operation occurred during severe winter conditions and was later described by Polish authorities as one of the country's most aggressive cyber incidents in years.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Affected products
9 linked
AndroidAndroidIosIosGoogle SearchSmartermailTelegramWindowsSignal
Organizations
33 linked
GoogleDeepseekFinancial TimesKasperskyOpenaiAppleDragosPoliticoShutterstockInformation Security Media GroupSmartertoolsTeam CymruFlashpointVolvo North AmericaEsetDark ReadingConduentiVerifyCable News NetworkFortinetMicrosoft CorporationTelegramHackmanacFortraCyberScoopTassThe VergeRecoBuchanan Ingersoll and Rooney PCNaukowa i Akademicka Sieć KomputerowaVegaSecurity.comEl Mundo
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.