Power Grid

Polish wind, solar and CHP sites — coordinated wiper attack

29–30 December 2025

Poland (30+ wind and photovoltaic farms; CHP plant serving ~500,000)

What happened

Coordinated intrusions hit more than 30 wind and photovoltaic farms, a large combined heat and power plant supplying heat to nearly half a million customers, and a manufacturing company across Poland. Attackers entered through internet-exposed FortiGate VPN and firewall devices — many without multi-factor authentication and running unpatched firmware — reused credentials, moved laterally, and deployed destructive wiper malware tracked as DynoWiper and LazyWiper against industrial systems. CERT Polska reported that detonation attempts largely failed and no interruption of electricity or heat supply occurred, though communications and monitoring at multiple sites were disrupted. The incident is regarded as the most serious attack on Polish energy infrastructure to date and highlighted the exposure of distributed renewable assets. The marker is a country-level reference.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
52.1000°
Longitude
19.4000°

Attribution

Attributed to Russia's FSB Centre 16

The United Kingdom and EU member states formally attributed the attack to Russia's FSB Centre 16 on 13 July 2026. CERT Polska had previously found infrastructure overlap with the Static Tundra/Berserk Bear/Ghost Blizzard/Dragonfly cluster; Russia did not acknowledge the operation.

Sources

  1. Energy Sector Incident Report — 29 December 2025CERT Polska; UK National Cyber Security Centre · Incident reporting