Poland’s Computer Emergency Response Team reported that a destructive cyber incident in December 2025 compromised OT/ICS environments across the country’s energy sector, including renewable energy plants (wind and photovoltaic), a combined heat and power facility, and at least one manufacturing organization. The intrusion reportedly began through vulnerable internet-facing edge devices, after which the actor deployed wiper malware that damaged remote terminal units (RTUs), destroyed data on human-machine interfaces (HMIs), and corrupted firmware on OT devices—resulting in a loss of operator “view and control” even where renewable generation continued producing power but could not be monitored or controlled as designed. Reporting indicated the activity overlapped with infrastructure associated with a Russian government-linked hacking group.
CISA issued an alert to U.S. critical infrastructure organizations to amplify the Polish findings and emphasize mitigations for energy-sector OT/ICS defenders, highlighting the ongoing risk from end-of-support edge devices and the need to harden remote access paths, credential hygiene (including default credentials), and incident response planning for scenarios where OT devices may become inoperable or permanently damaged due to firmware corruption. Separate industry commentary and a Dark Reading article provided broader context on the evolution of OT threats (e.g., lessons from Ukraine’s 2015 grid attack and emerging “living-off-the-plant” techniques), but did not add incident-specific details about the Poland event beyond reinforcing the general trend of increasing attacker capability and interest in industrial environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Following the Poland incident, the UK's National Cyber Security Centre issued a severe cyberthreat alert to critical infrastructure operators, warning that similar targeting could escalate quickly. The guidance urged resilience improvements including vulnerability management, secure configuration, access controls, monitoring, threat hunting, and segmentation.
By mid-February 2026, public reporting highlighted conflicting attribution assessments linking the operation to Russia-associated actors including Static Tundra/Berserk Bear, Sandworm, and Dragos's Electrum cluster. The failed but potentially harmful attack also triggered debate over whether such cyber operations meet legal or strategic thresholds for retaliation under NATO and international law.
On 2026-02-10, CISA published an alert to amplify CERT Polska's findings and warn critical infrastructure operators about OT and ICS security gaps exposed by the Poland incident. The agency emphasized risks from unsupported edge devices and default credentials, and recommended mitigations such as firmware verification, password changes, and OT-focused incident response planning.
On 2026-01-30, CERT Polska published its report on the December 2025 incident, describing three parallel campaigns and warning that the attack could have left nearly half a million residents without heat if it had succeeded. The report characterized the operation as technically unprecedented in scale and highlighted overlap with Russia-linked infrastructure.
The attackers gained access through vulnerable or misconfigured internet-facing edge devices and, in some cases, default credentials, then pivoted into OT environments. They deployed wiper malware that damaged RTUs, destroyed HMI data, and corrupted OT device firmware, causing loss of view and control between facilities and operators even though power generation continued.
Beginning on 2025-12-29, attackers targeted Poland's energy infrastructure, including more than 30 wind and photovoltaic farms, a combined heat-and-power plant, and related organizations. The operation occurred during severe winter conditions and was later described by Polish authorities as one of the country's most aggressive cyber incidents in years.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
lawfaremedia.org
Open sourcedarkreading.com
Open sourcevulnu.com
Open sourcebankinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcecyberscoop.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.