Skip to content
Knowledge base Updated: February 12, 2026

Cyberattack on Polish Energy Sector (December 2025): Lessons for Corporate Boards

The December 2025 cyberattack on Polish energy infrastructure exposed critical vulnerabilities. Discover what happened and the key lessons for every company board.

On December 29, 2025, in the middle of the heating season, someone pressed the button. Not metaphorically — they literally launched destructive software that simultaneously attacked over 30 wind and photovoltaic farms, a combined heat and power plant responsible for heating 500,000 people, and a manufacturing facility. The attack was not aimed at extorting a ransom. It was not about stealing data. The goal was destruction — permanent damage to systems, data erasure, and paralysis of infrastructure at the most vulnerable moment of the year.

CERT Polska compared the incident to arson. The Prime Minister publicly confirmed the attack. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to its own critical infrastructure operators. Intelligence services attributed the operation to Russian intelligence. And CEOs of energy companies across Poland had to answer, for the first time, a question that had until then seemed theoretical: what do we do when someone doesn’t want money — they want destruction?

What actually happened on December 29, 2025?

The attack was coordinated with a precision that points to months of preparation. According to the CERT Polska report published in January 2026, the attackers gained access to the victims’ infrastructure well in advance — most likely in the autumn of 2025. For weeks, they conducted reconnaissance, mapped internal networks, and prepared for a simultaneous strike.

On December 29, a Sunday between Christmas and New Year’s — when staffing levels are minimal and response times naturally extended — they launched destructive software later named DynoWiper. The program did not encrypt files awaiting a ransom. It overwrote data with random character strings, rendering it permanently unreadable. The attackers leveraged Windows domain management mechanisms (Group Policy) to simultaneously propagate the destructive code to all connected workstations and servers.

The list of targets included over 30 wind and photovoltaic farms scattered across Poland, a combined heat and power plant that was the sole source of heating for half a million residents, and a manufacturing facility. The attack primarily affected IT systems — workstations, servers, and management systems. In some cases, the attackers also reached industrial control systems (OT), exploiting default passwords in controllers that had never been changed since installation.

Thanks to the rapid response of security teams and endpoint protection tools that detected and blocked part of the destructive code, there were no interruptions to heat supply or energy blackouts. But the damage to IT infrastructure was severe — restoring systems from backups took weeks. The fact that the attack did not achieve its full objectives was largely due to luck and the preparedness of a few, not the systemic resilience of the sector.

📚 Read the complete guide: IAM / Zero Trust: Zarządzanie tożsamością i dostępem - od podstaw do Zero Trust

Why did a single VPN provider become a gateway to over 30 organizations?

This is a question that should keep every CEO of a company operating in the critical infrastructure sector awake at night. The attackers did not need to breach the defenses of 30 organizations separately. A single weak link was enough — FortiGate VPN devices that were exposed to the internet without multi-factor authentication (MFA).

What’s worse, the same login credentials — the same passwords — were shared across multiple locations. A single set of stolen credentials opened the door to dozens of wind farms simultaneously. This is not an exotic supply chain attack scenario from industry reports. This is the everyday reality of the Polish energy sector — centralized management of multiple distributed facilities through a single integrator, a single vendor, a single set of tools.

I’ve been having conversations with companies in the energy sector for years. I see the same pattern repeating across dozens of clients — a company invests in securing its headquarters but forgets about distributed facilities. Wind farms, transformer stations, pumping stations — they all run on the same VPN, often with identical passwords set during installation. And because “it works,” no one sees a reason to change it. Until someone exploits that vulnerability in the middle of the heating season.

The problem is not limited to the energy sector. Any organization that manages distributed infrastructure through a central access point should ask itself: what happens if someone compromises our VPN provider? How many locations will be compromised simultaneously? The answer in December 2025 was: over thirty.

How much does an hour of downtime cost for a CHP plant serving half a million recipients?

This is the question I ask every CEO whenever the conversation turns to the cybersecurity budget. The answers can be surprising — not because the amounts are low, but because many boards have never calculated them.

In the case of the December attack, there was no complete interruption of heat supply. But the scenario was real — and it’s worth calculating what it would have cost. A combined heat and power plant serving 500,000 recipients at the peak of the heating season is not a system you can turn off and on like a computer. Disrupting the operation of district heating systems at sub-zero temperatures means the risk of freezing installations, damage to transmission infrastructure, and — in an extreme scenario — a threat to people’s health and lives.

The direct costs of restoring IT systems after a wiper attack are significantly higher than after typical ransomware, where there is at least a theoretical possibility of recovering data after paying the ransom. With a destructive attack, that option doesn’t exist — the only path is restoration from backups, which across dozens of compromised locations takes weeks. On top of that come the costs of forensic investigation, external consultants, replacement of hardware with damaged firmware, regulatory penalties, and — increasingly — compensation proceedings from contractors affected by supply disruptions.

The IBM Cost of a Data Breach 2025 report estimates the average cost of a breach in the energy sector at $5.29 million. But that refers to data confidentiality breaches. A destructive attack on critical infrastructure is an entirely different cost category. Research by the Ponemon Institute from 2024 indicates that the average cost of OT system downtime in the industrial sector exceeds $500,000 per day, and in the energy sector these amounts can be many times higher due to the cascading effect and regulatory obligations.

The paradox is that the annual cybersecurity budget that could have prevented such an attack — multi-factor authentication, network segmentation, 24/7 monitoring, regular audits — is a fraction of the cost of a single serious incident. But that math only makes sense when the board treats cybersecurity as an investment in business continuity, not as an IT department expense.

How does a destructive attack differ from ransomware from the board’s perspective?

Most corporate boards already have some idea of what ransomware looks like. Someone encrypts data, demands a ransom, we negotiate or restore from backups — the scenario is familiar, and business decisions are relatively predictable. The December attack on Poland’s energy sector forces a revision of that mental model.

A destructive attack — a wiper — leaves no option for negotiation. There is no other party to talk to. There is no decryption key that can be purchased. The data is permanently destroyed. It’s like the difference between a kidnapping and a murder — in the first case, there is room for action; in the second, only managing the aftermath remains.

From the board’s perspective, this difference is fundamental. With ransomware, the key question is: “do we pay or not?” With a wiper, the question is: “how quickly can we get back to operations, and do we even have anything to restore systems from?” A business continuity plan that only accounts for a ransomware scenario is insufficient in 2026.

In recent months, I’ve observed a clear shift in conversations with clients. Just a year ago, the main topic was: “how do we defend against ransomware?” Today, I increasingly hear: “what if someone doesn’t want money?” The December attack made that concern tangible. Polish companies saw for the first time that a large-scale destructive cyberattack is not a scenario from Ukraine or the Baltic states — it’s something that can happen here, in our sector, in our supply chain.

An additional problem is the fact that destructive attacks increasingly masquerade as ransomware. The software displays a ransom demand, but the decryption key never existed — it’s merely a delay so the victim wastes critical hours on negotiations instead of immediately restoring from backups. This was precisely what WhisperGate did when it struck Ukrainian government institutions in January 2022 — it looked like ransomware but was a pure wiper.

Why did CERT Polska compare this incident to arson?

The comparison is deliberate and precise. When CERT Polska in its January 2026 report described the December attack as the digital equivalent of arson, three things were meant: the intent to destroy, the absence of a financial motive, and the scale of the simultaneous strike.

An arsonist does not negotiate. They don’t leave a phone number with a ransom demand. Their goal is destruction — and that was exactly the profile of the December attack. The destructive software DynoWiper contained no mechanism for contacting the victim, no negotiation infrastructure, no cryptocurrency wallet. The program’s sole function was to permanently damage as many systems as possible in the shortest time.

Security services attributed the attack to the Static Tundra group — a unit of the Russian FSB intelligence service (Center 16), also known as Berserk Bear and Dragonfly. ESET, an independent security firm, linked the operation to the Sandworm group (GRU), which has specialized in attacks on energy infrastructure since 2015 — from the Kyiv blackout in December 2015, through the attack on the Ukrainian power grid in 2016, to a series of over 19 different destructive malware families used since the beginning of the full-scale invasion of Ukraine in 2022.

For the board of a critical infrastructure company, attribution to a foreign state’s intelligence services changes the risk calculus. We are not defending against a criminal group seeking profit — we are defending against a state-sponsored operation with an unlimited budget, a multi-year planning horizon, and geopolitical objectives. It’s a different adversary, different tools, and an entirely different scale of preparation.

The arson comparison carries one more message — arson can be prevented. Fire alarm systems, smoke detectors, fire-resistant materials, evacuation procedures. The same applies to cybersecurity: network monitoring, segmentation, offline backups, recovery plans. The December attack showed which organizations had these “fire prevention systems” and which did not.

What does the supply chain have to do with your company’s security?

The December attack exposed a problem that the cybersecurity industry has been talking about for years, but which for many boards still remains an abstraction — supply chain risk. In practice, this means that your company’s security is only as strong as the weakest link among your vendors, integrators, and technology partners.

In the case of the attack on Poland’s energy sector, that weakest link was VPN devices from a single manufacturer, managed by a single integrator, with the same credentials across multiple locations. The attackers didn’t need to breach the defenses of each wind farm individually. It was enough to compromise the central management point to gain access to the entire network of facilities.

This model — one vendor, one solution, many locations — is the standard in the Polish energy sector. And not only there. Manufacturing companies, water utilities, transportation firms — wherever infrastructure is distributed, management is centralized. This is rational from an operational cost perspective. But from a security perspective, it creates a single point of failure whose compromise immediately propagates to all managed facilities.

The NIS2 Directive, which I discuss in more detail later in this article, explicitly requires critical infrastructure operators to manage supply chain risk. This is no longer a best practice — it is a legal requirement. Organizations must conduct security assessments of their vendors, require minimum protection standards, and monitor whether they are being followed.

In conversations with clients, I see three approaches to this problem. The first group — those who, after the December attack, immediately conducted an audit of their VPN providers and began implementing access segmentation. The second — those who “plan to do it in next year’s budget.” And the third — those who believe it doesn’t apply to them because “we’re not in the energy sector.” This third group concerns me most, because a supply chain attack knows no sector boundaries.

Key takeaway: Supply chain lessons

  • A single compromised VPN account gave access to over 30 organizations simultaneously
  • Shared credentials across locations multiply the impact of every breach
  • NIS2 imposes a legal obligation to manage vendor risk
  • Centralized management = operational efficiency, but also a single point of failure
  • Vendor audits are not a one-time project — they require continuous monitoring

How does NIS2 change board accountability for cyberattacks on critical infrastructure?

The NIS2 Directive, in force since October 18, 2024, has fundamentally changed the accountability framework for cybersecurity in critical infrastructure sectors. And — crucially — it has shifted that accountability from the IT department to the board.

In the context of the December attack on Poland’s energy sector, NIS2 regulations have three direct consequences. First — reporting obligations. An essential entity (and energy operators unquestionably qualify) must report a significant incident within 24 hours of detection, provide an initial impact assessment within 72 hours, and deliver a full report with root cause analysis within one month. The December attack affected over 30 organizations simultaneously — that means over 30 parallel reporting processes, requiring coordination between multiple entities, their vendors, and CERT Polska.

Second — financial penalties. For essential entities, the maximum penalty is EUR 10 million or 2% of global annual turnover — whichever is higher. For important entities: EUR 7 million or 1.4% of turnover. But the penalties alone are not the end of it.

Third — and this is the change I observe as the most transformative in conversations with boards — personal liability of board members. NIS2 allows sanctions to be imposed directly on management, including personal fines, legal proceedings, and — in extreme cases — temporary bans from holding management positions. This is not theory. This is law that has been in force for over a year.

I see how this shift is affecting the dynamics of security conversations in companies. Just two years ago, I had to convince boards that cybersecurity was an important topic. Today, it is increasingly CEOs and CFOs who initiate these conversations — because their lawyers told them that personal liability for cybersecurity negligence is not a risk they can ignore. NIS2 has fundamentally changed the dynamics of these conversations. The security budget is no longer the problem — the problem has become whether we’re spending it the right way.

For companies that have not yet adapted to NIS2 requirements, the December attack should be a wake-up call. If the regulator decides to enforce the regulations based on this incident — and the political pressure following the Prime Minister’s public confirmation of the attack is significant — the consequences could be severe not only financially but also personally.

Why do energy companies continue to postpone investments in OT security?

During the December attack, the attackers reached industrial control systems (OT) and exploited default passwords in controllers — passwords that had never been changed since the devices were installed. This is not an exception. This is the norm in the Polish energy sector and, more broadly, across the entire critical infrastructure sector.

The reasons why companies postpone OT security investments are repetitive, and I’ve been hearing them in conversations for years. The first and most common: “the system works, don’t touch it.” Many OT systems in Poland’s energy sector are 15–20 years old and were never designed with cybersecurity in mind. Their operators — justifiably — fear that updates or configuration changes might disrupt the continuity of production processes. The paradox is that this same fear of change leads to maintaining default passwords and a lack of segmentation between OT and IT networks — precisely the weaknesses that the attackers exploited in December.

The second reason is organizational structure. In many energy companies, the IT department is responsible for IT, while the maintenance or automation department handles OT. These two worlds rarely communicate, and even more rarely share a common security strategy. Attackers know this and exploit it — they move from the IT network (where they may be detected by modern security tools) to the OT network (where such tools often don’t exist at all).

The third reason is cost. Securing an OT environment requires specialized expertise, dedicated tools, and — most challenging of all — maintenance windows during which systems must be shut down. For a CHP plant operating continuously, such a window is a logistical operation requiring weeks of planning. But — and here we return to simple math — the cost of a planned two-day maintenance window to implement segmentation and change passwords is disproportionately lower than the cost of weeks of recovery after a destructive attack.

The December incident should be a turning point. Default passwords in critical infrastructure OT systems are not “technical debt” — they are an invitation for anyone capable of running a basic network scan. CISA — the U.S. cybersecurity agency — in its warning issued after the Polish attack explicitly identified default ICS credentials as a critical gap for immediate elimination.

What patterns do I see in conversations with CEOs after the December attack?

Since January 2026, I’ve been having dozens of conversations with boards of companies in the energy, manufacturing, and utilities sectors. I see three distinct response patterns to the December incident — and these patterns say more about an organization’s maturity than any audit.

The first group consists of companies that responded immediately. Within the first two weeks of January, they conducted emergency audits of their VPN connections, forced password changes on all access devices, deployed or accelerated MFA implementation, and commissioned external reviews of IT/OT network segmentation. These companies don’t ask me “could this affect us?” They ask “what else should we be doing?” This is the attitude that builds real resilience.

The second group consists of companies that treated the December attack as ammunition in internal budget negotiations. IT directors and CISOs finally got hard justification for the investments they had been advocating for months. These conversations sound like: “We have this attack as a case study. The board is finally listening. We need a concrete proposal to push the budget through for Q2.” This is a positive dynamic, but with risk — between “the board is listening” and “budget approved,” months can pass, and attackers don’t wait for the end of the quarter.

The third group — and this one concerns me the most — consists of companies that treat the December attack as “an energy sector problem.” I hear: “we’re not critical infrastructure,” “our sector isn’t a target,” “that was an intelligence operation, it doesn’t apply to us.” This mindset ignores the fact that the supply chain knows no sector boundaries. A manufacturing company that supplies components to the energy sector is part of the same ecosystem. A logistics company that handles fuel transport is a potential attack vector. A supply chain attack means that if your client or vendor is a target — so are you.

I see yet another pattern that has emerged for the first time — companies that have started treating cybersecurity as an element of contractual negotiations with partners. They require ISO 27001 certifications, audit reports, confirmation of NIS2 compliance. This is a mature response that changes the entire ecosystem for the better.

Where should the board of a critical infrastructure company start?

I’m not a proponent of “10 steps to security” lists. Every organization is different and requires an individual approach. But after the December attack, several priorities are universal — and they stem directly from the vectors used in this specific incident.

Priority number one: an immediate review of all remote access points. VPN, RDP, remote desktops, management console access — every device exposed to the internet without multi-factor authentication is an open door. The December attack proved this beyond any doubt. MFA is not “nice-to-have” — it’s the minimum without which no service should be exposed to the internet.

Priority number two: elimination of shared credentials. If the same login and password grant access to multiple locations — that is not secured infrastructure. It’s a single lock with a single key, whose copy hangs on a bulletin board. Every location, every device, every administrator should have unique credentials.

Priority number three: IT and OT network segmentation. The attackers in December moved from the IT network to industrial control systems. If these networks had been physically or logically separated, reaching OT would have required breaching an additional layer of defenses. Segmentation does not eliminate risk — but it drastically increases the cost and complexity of an attack.

Priority number four: offline backups. A wiper destroys everything it can access — including backups, if they’re connected to the network. The only guarantee of recovery is a copy that is physically inaccessible from the attacked infrastructure. The 3-2-1-1 strategy (three copies, two media types, one copy offsite, one copy immutable) is a standard that should be mandatory after December.

Priority number five: a business continuity plan that accounts for a destructive scenario. Most BCP plans assume a ransomware scenario — there’s a key, you can recover data. A plan that doesn’t account for the variant “all data destroyed, no key exists” is incomplete after December 2025.

Key takeaway: Five priorities after the December attack

  • Review and secure all remote access points (VPN, RDP) — MFA mandatory
  • Eliminate shared passwords across locations
  • IT/OT network segmentation — separate control systems from office infrastructure
  • Offline backups (3-2-1-1 strategy) — inaccessible from the production network
  • Update BCP plans to include destructive attack scenarios (not just ransomware)

How to assess cybersecurity maturity in the context of destructive attacks?

In conversations with corporate boards, questions often arise about how their organization compares to the rest of the industry. The table below is a tool that helps quickly assess where a company stands in terms of resilience against destructive attacks — the same vectors that were used in December 2025.

AreaLevel 1 — reactiveLevel 2 — baselineLevel 3 — managedLevel 4 — advanced
Remote access (VPN/RDP)Static passwords, no MFA, shared accountsMFA partially deployed, shared accounts still used for some locationsMFA on all access points, unique accounts, login monitoringZero trust network access, just-in-time access, continuous behavioral monitoring
IT/OT segmentationFlat network, IT and OT in one segmentBasic VLAN segmentation, firewall between IT and OTDedicated DMZ zones for OT, traffic monitoring at the boundary, limited privilegesMicrosegmentation, separated management domains, dedicated SOC for OT
OT password managementDefault manufacturer passwords, no rotationPasswords changed after installation, no rotationRegular rotation, unique passwords per device, access registryPrivileged access management (PAM), session monitoring, automated rotation
BackupsOnline backup, no restore testingOnline + offsite backup, testing once a year3-2-1-1 strategy, immutable storage, quarterly restore testingAir-gapped backup, automated integrity testing, RTO/RPO verified for wiper scenario
Business continuity (BCP)None or outdatedPlan for ransomware, does not account for destructive attackPlan includes wiper scenario, annual exercisesDedicated playbooks for destructive attacks, exercises with board participation, supply chain scenarios
Supply chainNo vendor assessmentContracts with security clauses, no verificationRegular vendor audits, MFA and segmentation requirementsContinuous monitoring of vendor security, joint incident response exercises
NIS2 complianceNo awareness or at the requirements analysis stageGap analysis completed, implementation plan in preparationMost requirements implemented, incident reporting establishedFull compliance, regular reviews, board actively engaged in governance

Most companies in the energy sector that I talk to fall between Level 1 and Level 2. The December attack demonstrated that Level 2 is not enough to survive a coordinated state-sponsored operation. The target should be at least Level 3 in each of these areas — and not in some distant future, but within the next 12 months.

What does the December attack say about the future of cyber threats to Polish business?

The December attack on Poland’s energy sector was not an isolated incident. It fits into a clear trend of escalating cyber operations targeting critical infrastructure in NATO countries — a trend that has been systematically intensifying since 2022.

The Sandworm group, to which some researchers attribute the December attack, has deployed over 19 different destructive malware families since February 2022 — primarily against Ukraine. The DynoWiper used in Poland is the first confirmed instance where the same techniques and tools were directed against a NATO member state. This is a qualitative change, not a quantitative one.

A 2023 Fortinet report pointed to a 53 percent increase in the use of destructive malware globally in the fourth quarter of 2022 alone. In 2025, ESET investigated more than 10 incidents involving wipers attributed to Sandworm — almost all in Ukraine. The attack on Poland signals that the geography of these operations is expanding.

At the same time, the boundary between ransomware and wipers is blurring. New criminal platforms — such as Anubis RaaS, which emerged in December 2024 — offer a “wiper mode” as an option alongside traditional encryption. If the victim doesn’t pay, data is permanently destroyed. This means that even organizations that consider themselves “too small” for state-sponsored attacks can fall victim to a destructive attack carried out by a criminal group.

For Polish business, the message is clear: the era in which a cyberattack meant “someone will steal our customer data” is over. In 2026, a cyberattack can mean weeks of production shutdown, interruption of energy supply, and destruction of IT infrastructure with no possibility of recovery. And — as December showed — it can be a deliberate act of aggression by a foreign state, not the work of a criminal group seeking profit.

Frequently asked questions

Did the December attack on Poland’s energy sector cause interruptions to heat or energy supply?

No. Thanks to the rapid response of security teams and endpoint protection tools that detected and partially blocked the destructive software, there were no interruptions to heat supply or energy blackouts. The damage primarily affected IT infrastructure — workstations, servers, and management systems, whose restoration took weeks.

Who is behind the attack?

CERT Polska attributed the attack to the Static Tundra group, linked to the Russian FSB (Center 16). The security firm ESET independently linked the DynoWiper software used in the attack to the Sandworm group (GRU). Both attributions point to Russian intelligence services, though they differ on the specific unit responsible.

Is my company at risk if I’m not a critical infrastructure operator?

Yes. The December attack showed that the compromise of a single technology vendor can simultaneously affect dozens of organizations. If you are part of the supply chain in the energy, manufacturing, or utilities sector — as a component supplier, integrator, logistics company, or subcontractor — the risk applies to you.

How does DynoWiper differ from typical ransomware?

DynoWiper is destructive software (a wiper) whose sole purpose is the permanent destruction of data. Unlike ransomware, it does not encrypt files and does not demand a ransom. It overwrites data with random character strings, rendering it irreversibly unreadable. There is no decryption key, no negotiation, and no possibility of recovery — the only option is restoration from backups.

What are the penalties for non-compliance with NIS2 requirements?

For essential entities (including energy operators): up to EUR 10 million or 2% of global annual turnover. For important entities: up to EUR 7 million or 1.4% of turnover. Additionally, NIS2 introduces the possibility of imposing personal sanctions on board members, including fines and temporary bans from holding management positions.

Where should we start if we’ve never had an OT security audit?

Start by identifying what you have. An inventory of OT devices, mapping connections between IT and OT networks, checking whether default passwords have been changed. It sounds basic, but the December attack proved that fundamental oversights — default passwords, lack of segmentation, shared VPN accounts — are enough to enable a coordinated attack on dozens of locations simultaneously.

Could the attack on Poland’s energy sector happen again?

Yes, and experts consider it likely. The Sandworm group has used over 19 different destructive malware families since 2022. The December attack on Poland is the first confirmed case of these techniques being used against a NATO country. The escalation trend — from Ukraine through neighboring countries to NATO members — indicates that further attacks on critical infrastructure in the region are a matter of when, not if.

Explore Our Products

Solutions mentioned in this article that can help protect your organization:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist