Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Why AI’s Rise Makes Protecting Personal Data More Critical Than Ever

February 6, 2026

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm
News

Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm

Team-CWDBy Team-CWDJanuary 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A cyber-attack on Poland’s energy infrastructure in late 2025 has been attributed to a prolific Russian state-backed APT group.

Sandworm (aka UAC-0113, APT44, and Seashell Blizzard) is thought to be part of the Russian military intelligence service known as GRU. ESET claimed in a brief statement on Friday that the group was responsible for a series of attacks on Poland’s power grid in late December.

“The attackers deployed a wiper, which we analyzed and named DynoWiper. We’re not aware that any successful disruption occurred as a result of this attack,” explained ESET principal threat intelligence researcher, Robert Lipovsky.

“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed.”

Read more on Sandworm: Russian APT Sandworm Disrupted Power in Ukraine Using Novel OT Techniques.

The campaign against Polish energy assets is still being investigated, but Lipovsky said the timing of the “coordinated cyber-attack” might be deliberate.

“It’s the 10-year anniversary of the Sandworm-orchestrated attack against the Ukrainian power grid – the first ever malware-facilitated blackout in December 2015,” he said. “When the APT group used the BlackEnergy malware to gain access to critical systems at several electrical substations, around 230,000 people were left without electricity for several hours.”

Sandworm has been highly active since Russia’s invasion of Ukraine in 2022, targeting energy infrastructure inside Ukraine on multiple occasions. In March 2024 it hit energy, heating and water facilities in 10 regions of the war-torn country in a bid to amplify the impact of missile strikes.

Then in both Q2 and Q3 2025 it deployed data wipers such as Zerolot and Sting against government, energy and logistics entities. The long-term goal of such attacks is to weaken the economy and demoralize the population, forcing the government to give in to the demands of the Putin administration.

Poland on High Alert

Polish prime minister, Donald Tusk, revealed earlier this month that the country had successfully repelled the destructive attack on its own energy infrastructure a few weeks earlier.

“The systems we have in Poland today proved effective,” he said. “At no point was critical infrastructure threatened, meaning the transmission networks and everything that determines the safety of the entire system.”

However, the government is rushing to finalize a National Cybersecurity System Act – its implementation of NIS2 – to mandate stricter requirements for risk management, IT and OT security, and incident response.

“I hope to implement this act as soon as possible,” said Tusk. “We will be equipping Polish institutions with tools to protect the market against systems and devices that would make it easier for foreign states to interfere and obtain information. We are striving for the autonomy and Polonization of security systems.”

The attack itself took place on December 29 and 30, 2025,  and apparently targeted two combined heat and power (CHP) plants and a renewable energy system.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleZoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Next Article North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
Team-CWD
  • Website

Related Posts

News

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026
News

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
News

SolarWinds Web Help Desk Vulnerability Actively Exploited

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

What is it, and how do I get it off my device?

September 11, 2025

How cybercriminals are targeting content creators

November 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.