Tuesday 28 April, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Russia-linked Sandworm hackers blamed for failed attack on Poland’s power grid

A foiled cyberattack on Polish energy systems has been attributed to a long-running Russia-backed hacking group

Carly PagebyCarly Page
January 26, 2026
in News
city skyline during day time
Share on Linkedin

Russia-linked hackers with a track record of sabotaging infrastructure operations were behind a failed attempt to disrupt Poland’s power grid late last year, in what Warsaw has described as a deliberate cyberattack on the country’s energy infrastructure.

You Might Also Like

Europe’s armed forces are too reliant on US cloud providers, report finds

UNIVITY raises €27 million to build a 5G satellite constellation that can expand European communication networks

Jacek Siewiera: a future NATO conflict will be fought against civilian targets

Poland’s prime minister Donald Tusk said in a statement that systems had blocked cyberattacks on 29 and 30 December targeting parts of the national energy sector, including facilities linked to electricity generation and renewables. In a subsequent technical analysis, security firm ESET attributed the operation to Sandworm, a long-tracked hacking group widely associated with Russian military intelligence.

According to ESET, the attackers deployed a previously undocumented data-wiping malware strain, dubbed DynoWiper, during the campaign.

The firm said the tooling and behaviour observed during the intrusion showed “a strong overlap with numerous previous Sandworm wiper activity,” linking the incident to a pattern of destructive operations previously seen in Ukraine and elsewhere. ESET added that it was “not aware of any successful disruption occurring as a result of this attack.”

ESET noted that the attempted attack occurred almost exactly 10 years after Sandworm’s 2015 cyber operation against Ukraine’s power grid, the first known blackout caused by a cyberattack. That attack, widely attributed to Russian state-backed actors, is now routinely cited in discussions about the risk of cyber sabotage against civilian infrastructure.

Warsaw has been unusually direct about attribution.

“Everything indicates that these attacks were prepared by groups directly linked to the Russian services,” said a statement from Donald Tusk published by the Prime Minister’s Office — signalling that the government views the incident as a state-backed operation, not a run-of-the-mill criminal intrusion.

Tusk further warned that while Poland’s defences held, the attacks posed a serious risk to both energy security and the wider security of the state.

The government said the attempted intrusions targeted two combined heat and power plants, as well as systems used to manage electricity generated from renewable energy sources such as wind and solar. Existing protections prevented any outages or physical damage, officials said, but the attempted attack was still serious enough to be treated as a national security issue.

Tusk said he had instructed ministers and security services to operate at “full capacity” in response, adding that Poland must be prepared for further attempts against critical infrastructure.

The statement also pointed to planned legislative changes, including work on the Act on the National Cybersecurity System, aimed at strengthening protections across both IT and operational technology environments.

The incident adds to a growing list of Russia-linked cyber operations aimed at energy infrastructure, even outside Ukraine. Although Poland avoided disruption, the choice of target, timing, and tooling points to cyber activity being used as a means of strategic pressure on NATO and EU countries.

The incident also comes just weeks after a major power outage in Berlin, where a suspected arson attack on high-voltage cables knocked out electricity for around 45,000 households and more than 2,000 businesses over several days, marking the city’s longest blackout since World War II. 

Tags: CybersecurityInfrastructurePolandpower gridRussiasandwormsecurity
Previous Post

Weekend Read: ‘History tells us what may happen next with Brexit & Trump’ ten years on

Next Post

Grid Aero raises $20 million Series A to bring autonomous cargo drones to the front lines

Carly Page

Carly Page

Carly Page is a freelance journalist and copywriter with 10+ years of experience covering the technology industry, and was formerly a senior cybersecurity reporter at TechCrunch. Bylines include Forbes, IT Pro, LeadDev, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, & more.

Related News

German military uniform (Touko Aikioniemi from Unsplash)

Europe’s armed forces are too reliant on US cloud providers, report finds

byPaul Sawers
April 28, 2026

Europe’s defence systems depend heavily on US cloud infrastructure, leaving key military functions exposed to potential service disruptions during geopolitical...

UNIVITY raises €27 million to build a 5G satellite constellation that can expand European communication networks

UNIVITY raises €27 million to build a 5G satellite constellation that can expand European communication networks

byJohn Biggs
April 24, 2026

UNIVITY has raised €27 million to transition its space-based telecom infrastructure from a demonstration phase to an early industrial stage....

Jacek Siewiera: a future NATO conflict will be fought against civilian targets

Jacek Siewiera: a future NATO conflict will be fought against civilian targets

byResilience Media
April 24, 2026

The wars in Iran and Ukraine have underscored how civilian infrastructure will become a feature of future conflicts. And Poland’s...

Sten Tamkivi: Poland’s defence start-ups should be seen as future GDP drivers

Sten Tamkivi: Poland’s defence start-ups should be seen as future GDP drivers

byResilience Media
April 24, 2026

Sten Tamkivi, a partner at Plural and an early Skype executive, joined Resilience Media publisher Leslie Hitchcock on stage during...

Where are Poland’s defence unicorns?

Where are Poland’s defence unicorns?

byResilience Media
April 24, 2026

"Where are the Polish unicorns in defence?" asked Marcin Hejka, managing partner at OTB Ventures, one of Poland's largest deep-tech...

How to find the needle in the startup haystack in Ukraine: observations from an early-stage VC

How to find the needle in the startup haystack in Ukraine: observations from an early-stage VC

byLuke Smith
April 23, 2026

After an investor demo day in early 2022, Roman Sulzhyk, head of investment at early-stage venture capital firm Resist.UA, found...

Rivan raises €28.7M to increase synthetic fuel production in Europe

Rivan raises €28.7M to increase synthetic fuel production in Europe

byJohn Biggs
April 22, 2026

UK-based startup Rivan has raised €28.7 million to expand domestic synthetic fuel production across Europe. The round was led by...

black drone during daytime

In the era of precise mass, FPVs are outgrowing the pilot

byThomas Macaulay
April 22, 2026

No weapon has shaped the Russia-Ukraine War like the first-person-view drone. Commonly known as FPVs, these unmanned aircraft stream live...

Load More
Next Post
Grid Aero raises $20 million Series A to bring autonomous cargo drones to the front lines

Grid Aero raises $20 million Series A to bring autonomous cargo drones to the front lines

\UK Advances Project NYX, shortlists Euro firms to Build Autonomous Wingman Drones for Apache Helicopters

UK Advances Project NYX, shortlists Euro firms to build autonomous "wingman" drones

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Senai exits stealth to help governments harness online video intelligence

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • Home
  • Subscribe
  • About
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026
  • Startups
  • Venture
  • Weekly Digest

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.