Friday 14 August, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Poland’s energy networks hit by ‘digital arson’ after basic firewall failures, report finds

CERT Polska’s technical analysis shows how attackers exploited weak remote access controls to disrupt wind, solar, and heat generation sites in a coordinated campaign last December

Carly PagebyCarly Page
February 2, 2026
in Cyber, European Defence, News
white windmills
Share on Linkedin

CERT Polska has described December’s cyberattack on Poland’s energy sector as an act of “digital arson.” A report from the government group, which provides emergency response to IT-related incidents, reveals that — contrary to earlier reports that attributed the cyberattack to sophisticated zero-day exploits — attackers gained access through a much more straightforward route: exposed firewalls with no multi-factor authentication.

You Might Also Like

Fibre-optic drones: flying in the face of reason

Australia puts speed ahead of perfection in new defence technology strategy

Chinese tech in Royal Navy drones exposes UK defence supply chain dilemma

The report offers the clearest technical account yet of what happened on 29 December, when multiple energy and industrial sites across Poland were hit in a coordinated campaign that prioritised destruction over disruption.

At least 30 wind and solar installations were affected, along with a large combined heat and power plant that supplies heat to hundreds of thousands of homes and a manufacturing company.

While electricity generation continued, operators temporarily lost remote visibility and control at several sites after attackers deliberately severed communications and damaged operational systems.

According to CERT Polska, the attackers didn’t weaponise a zero-day or exploit a supply chain; they walked in through internet-facing firewalls and VPNs that lacked multi-factor authentication and, in some cases, weak or reused passwords.

That access was sufficient to move laterally into internal systems and onward to operational technology that should never have been reachable from the public internet.

CERT Polska says the attackers moved quickly from access to damage, attempting to corrupt firmware, delete data, and disable remote terminal units responsible for monitoring and control. There was no indication of espionage or data theft, only deliberate destruction.

An analysis published by industrial cybersecurity firm Dragos provides additional context on the incident, particularly regarding the selection of targets.

Dragos researchers described the operation as “the first major cyberattack targeting distributed energy resources,” warning that wind farms, solar installations, and other decentralised assets present a growing and under-secured attack surface. Unlike traditional power plants, these sites are often designed for remote management at scale, using standardised hardware and configurations that make them efficient to run but easier to compromise en masse.

That assessment helps explain the attackers’ apparent focus. According to Dragos, once the adversary worked out how to access one site, the same approach could be replicated across many others using similar equipment. The result was a broad, coordinated impact that did not bring down the national grid but knocked out monitoring and control at dozens of locations simultaneously. Some equipment was damaged severely enough to require manual intervention and replacement, resulting in a longer recovery effort.

On attribution, CERT Polska diverges from some earlier assessments.

While ESET and Dragos linked the attacks to Sandworm, the Russia-backed group notorious for physically destructive attacks, CERT Polska’s analysis of the attack infrastructure found a high degree of overlap with activity publicly tracked under names such as “Berserk Bear” and “Dragonfly”, two other Russia-backed groups. It describes this as the first publicly documented case of destructive activity attributed to that group, which is better known for traditional cyberespionage.

Perhaps the most uncomfortable takeaway from the CERT Polska report is how preventable much of the intrusion appears to have been. The attack didn’t succeed because of sophisticated tradecraft, but because basic safeguards were missing. Multi-factor authentication, proper segmentation, and stricter controls on exposed devices would have significantly complicated operations, rather than leaving critical systems easy to reach.

We have reached out to industry sources for reaction and will update this post as we learn more.

Tags: cyberattackCybersecurityPolandRussiasandwormsecurity
Previous Post

The second valley of death

Next Post

The future of fuel: A conversation with Tim Böltken of Ineratec

Carly Page

Carly Page

Carly Page is a freelance journalist and copywriter with 10+ years of experience covering the technology industry, and was formerly a senior cybersecurity reporter at TechCrunch. Bylines include Forbes, IT Pro, LeadDev, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, & more.

Related News

Fibre-optic drones: flying in the face of reason

Fibre-optic drones: flying in the face of reason

byJohn Biggs
August 14, 2026

  The image is arresting: a once-pristine Ukrainian forest is now strung with plastic fibre-optic cable, gossamer lines spanning trees...

A helicopter flying next to a flag flying in the sky

Australia puts speed ahead of perfection in new defence technology strategy

byCarly Page
August 13, 2026

Australia has unveiled a 10-year plan to overhaul how it develops and buys military technology, with AI, autonomous systems and...

Image credit: Kraken

Chinese tech in Royal Navy drones exposes UK defence supply chain dilemma

byCarly Page
August 12, 2026

Britain’s push for cheaper, faster military technology comes with a catch: somewhere inside that shiny new British-built drone, there may...

grey concrete wall

Material issue: the sovereign supply chain Europe is trying to build

byPaul Sawers
August 11, 2026

Drones need carbon fibre, buildings need cement, and shells need TNT -- meet the startups helping Europe to make its...

Welcome to Resilience Media

One year in: What we’ve learned about the Resilience Media audience

byAnna Escherand1 others
August 5, 2026

In the last 12 months, Resilience Media expanded its newsroom and shifted from a Substack newsletter to a standalone website...

UK-based OLIX raises $312 million Series B to build better AI infrastructure

UK-based OLIX raises $312 million Series B to build better AI infrastructure

byJohn Biggs
August 4, 2026

London-based OLIX has raised a $312 million Series B at a $3.3 billion valuation, one of the largest in the...

Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom

Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom

byCarly Page
August 4, 2026

Amsterdam-based Ore Energy has raised $43 million (£32 million) in Series A funding to commercialise its iron-air battery technology, betting...

Taiwan’s defence plans are up in the air

Taiwan’s defence plans are up in the air

byHarry Saunders
July 31, 2026

For an island nation with no regional ambitions and territory roughly the size of the Netherlands, Taiwan has an impressive...

Load More
Next Post
The future of fuel: A conversation with Tim Böltken of Ineratec

The future of fuel: A conversation with Tim Böltken of Ineratec

UK startup Refute secures £5M to take AI fight to disinformation campaigns

UK startup Refute secures £5M to take AI fight to disinformation campaigns

Top stories

Confirmed: Cambridge Aerospace raised $300M at a $3.4B valuation
Drones & UAS

Confirmed: Cambridge Aerospace raised $300M at a $3.4B valuation

August 10, 2026
Image credit: Kraken
News

Chinese tech in Royal Navy drones exposes UK defence supply chain dilemma

August 12, 2026
grey concrete wall
NATO

Material issue: the sovereign supply chain Europe is trying to build

August 11, 2026
UK MoD tests British-built anti-Shahed system in Jordan
News

SCOOP: Cambridge Aerospace is closing in on $300M at a $3.4B valuation

July 15, 2026

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.