Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm
News

Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm

Team-CWDBy Team-CWDJanuary 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A cyber-attack on Poland’s energy infrastructure in late 2025 has been attributed to a prolific Russian state-backed APT group.

Sandworm (aka UAC-0113, APT44, and Seashell Blizzard) is thought to be part of the Russian military intelligence service known as GRU. ESET claimed in a brief statement on Friday that the group was responsible for a series of attacks on Poland’s power grid in late December.

“The attackers deployed a wiper, which we analyzed and named DynoWiper. We’re not aware that any successful disruption occurred as a result of this attack,” explained ESET principal threat intelligence researcher, Robert Lipovsky.

“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed.”

Read more on Sandworm: Russian APT Sandworm Disrupted Power in Ukraine Using Novel OT Techniques.

The campaign against Polish energy assets is still being investigated, but Lipovsky said the timing of the “coordinated cyber-attack” might be deliberate.

“It’s the 10-year anniversary of the Sandworm-orchestrated attack against the Ukrainian power grid – the first ever malware-facilitated blackout in December 2015,” he said. “When the APT group used the BlackEnergy malware to gain access to critical systems at several electrical substations, around 230,000 people were left without electricity for several hours.”

Sandworm has been highly active since Russia’s invasion of Ukraine in 2022, targeting energy infrastructure inside Ukraine on multiple occasions. In March 2024 it hit energy, heating and water facilities in 10 regions of the war-torn country in a bid to amplify the impact of missile strikes.

Then in both Q2 and Q3 2025 it deployed data wipers such as Zerolot and Sting against government, energy and logistics entities. The long-term goal of such attacks is to weaken the economy and demoralize the population, forcing the government to give in to the demands of the Putin administration.

Poland on High Alert

Polish prime minister, Donald Tusk, revealed earlier this month that the country had successfully repelled the destructive attack on its own energy infrastructure a few weeks earlier.

“The systems we have in Poland today proved effective,” he said. “At no point was critical infrastructure threatened, meaning the transmission networks and everything that determines the safety of the entire system.”

However, the government is rushing to finalize a National Cybersecurity System Act – its implementation of NIS2 – to mandate stricter requirements for risk management, IT and OT security, and incident response.

“I hope to implement this act as soon as possible,” said Tusk. “We will be equipping Polish institutions with tools to protect the market against systems and devices that would make it easier for foreign states to interfere and obtain information. We are striving for the autonomy and Polonization of security systems.”

The attack itself took place on December 29 and 30, 2025,  and apparently targeted two combined heat and power (CHP) plants and a renewable energy system.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleZoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Next Article North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

A phishing attack that doesn’t steal your password

June 15, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.