On December 29, 2025, Poland suffered one of the most coordinated cyberattacks against its critical energy infrastructure. The event highlighted how vulnerable modern energy networks can be and raised concerns about the security of critical infrastructure across Europe.
The attack simultaneously hit at least 30 Polish wind and solar plants, a major cogeneration plant that provides heating to approximately 500,000 customers, and a manufacturing company. The attackers, identified as a Russia-linked group known by various names including “Static Tundra,” “Berserk Bear,” and “Dragonfly,” managed to penetrate the systems through network devices exposed to the Internet. Specifically, they exploited VPN concentrators and Fortinet FortiGate firewalls that did not use multi-factor authentication. Once inside, they deployed destructive malware that damaged remote terminal units (RTUs), corrupted firmware on operational devices from manufacturers such as Hitachi Energy, Mikronika, and Moxa, and destroyed data on human-machine interfaces.
Fortunately, despite the sophistication of the attack, essential services were not interrupted: power generation and distribution continued, although operators temporarily lost the ability to monitor and control some systems. On January 30, 2026, CERT Poland confirmed the attack, followed by an alert from CISA (the American cybersecurity agency) on February 10-11, 2026.
The importance of this incident extends beyond Polish borders. It demonstrates how modern energy infrastructure, increasingly digitized, can be strategically targeted. The attackers’ ability to simultaneously target different types of energy plants suggests a well-planned operation, likely intended to test strategies or create significant disruption. If the attack had successfully interrupted energy supplies during winter, the consequences could have been severe for hundreds of thousands of people.
To protect against similar threats, companies managing critical infrastructure should urgently implement multi-factor authentication on all Internet-accessible systems, regularly update firmware and software, segment networks to isolate critical systems, and conduct frequent vulnerability assessments. It is also essential to develop and test incident response plans that allow essential services to remain operational even during an attack.
Key lessons from this incident:
• The lack of multi-factor authentication on network devices exposed to the Internet represents a critical vulnerability that can be easily exploited.
• Even if cyber attacks do not cause immediate service disruptions, the loss of monitoring and control capabilities represents a significant risk to operational safety.
• International collaboration between cybersecurity agencies, as demonstrated by the coordinated response from CERT Poland and CISA, is crucial for identifying and mitigating transnational threats.
Sources: cyberscoop.com, industrialcyber.co, notebookcheck.net, cybersecuritydive.com, helpnetsecurity.com, cybersecurity-review.com
Source: CISA Advisories