At the end of December 2025, the Polish energy sector was targeted by a sophisticated cyber attack. The incident, attributed to the Russian group Sandworm, attempted to strike critical infrastructure but was fortunately thwarted without causing operational disruptions.
On December 29-30, 2025, hackers targeted two combined heat and power (CHP) plants and a renewable energy management system in Poland using malware called “DynoWiper” (identified as Win32/KillFiles.NMO). This malicious software was designed to erase critical data within energy systems. According to ESET researchers, the attack was attributed with “medium confidence” to the Sandworm group, also known as APT44 or UAC-0113, sponsored by the Russian government. The timing of the attack is not coincidental: it coincides with the tenth anniversary of Sandworm’s BlackEnergy attack on the Ukrainian power grid in 2015.
The relevance of this event is considerable, even though it did not cause power outages or service disruptions. Attacks on energy infrastructure represent a particularly serious threat as they could potentially cause large-scale blackouts, compromise essential services, and generate social instability. This attempt demonstrates how geopolitical tensions can manifest through cyber operations targeting critical sectors. The fact that the attack was attributed to a state-sponsored group further highlights how cybersecurity has become a fundamental component of national security.
To protect against similar threats, companies in the energy sector should implement robust cybersecurity measures, including regular system updates, training staff to recognize potential threats, and implementing intrusion detection systems. It is also crucial to isolate industrial control systems from external networks when possible and adopt a “zero trust” approach in network architectures. Collaboration between the private sector, government entities, and intelligence agencies remains essential to promptly identify and neutralize sophisticated threats such as that of Sandworm.
- Key points to remember:
- The attack on the Polish energy sector in December 2025 was thwarted without causing operational disruptions, demonstrating the importance of solid cyber defense systems.
- The DynoWiper malware used in the attack was linked to the Russian-backed Sandworm group, highlighting how cybersecurity has become an extension of geopolitical conflicts.
- Protecting energy infrastructure requires a multi-layered approach that combines advanced technologies, staff training, and public-private collaboration.
Sources:
ESET Research, SecurityAffairs, The Hacker News, TechCrunch, Rescana, Zetter-ZeroDay
Source: Security Affairs