Skip to content
Knowledge base

DynoWiper and the attack on Polish energy: wiper versus ransomware

A coordinated attack on at least 30 renewable energy farms and a CHP plant serving ~500,000 customers showed that a wiper — data-destroying software — is more dangerous than ransomware. The vector was a lack of MFA on VPN gateways. We explain the mechanism and the defense.

The most serious cybersecurity incident of 2025 in Poland was the coordinated attack on the energy sector on 29–30 December 2025. It struck at least 30 wind and photovoltaic farms, a combined heat and power plant serving about 500,000 customers, and a manufacturing company. The attackers did not want money — they wanted to destroy. They used a wiper, software whose only goal is the destruction of data.

This article explains how a wiper differs from ransomware, what is known about the attack on Polish energy and — most importantly — how to protect OT/ICS infrastructure against this class of threat. For the broader context, see the 2026 cyber threat landscape report.

Wiper versus ransomware — the key difference

This distinction determines the entire defense strategy.

  • Ransomware encrypts data and extorts a ransom in exchange for a decryption key. The goal is profit, and recovering the data is — at least in theory — possible. There is another party with whom (unfortunately) one can negotiate.
  • A wiper destroys data, often pretending to be ransomware, but with no intention whatsoever of restoring it. The goal is destruction, operational paralysis or covering tracks, not money. There is no key, no negotiation.

The consequence is fundamental: against a wiper, the classic “pay or don’t pay” calculations lose all meaning. The only real defense is the ability to quickly restore the environment from backups the attacker could not destroy. That is why immutable, offline backups are not a luxury in OT but a condition of survival.

What is known about the attack on Polish energy

The attack used a wiper named DynoWiper by ESET (signature Win32/KillFiles.NMO). Prime Minister Donald Tusk noted that, had the attack succeeded, more than 500,000 people could have lost heat. The timing is also symbolic: the attack came on the 10th anniversary of the Sandworm group’s attack on the Ukrainian power grid (BlackEnergy, December 2015), which cut power to about 225,000 people.

Attribution — handle with care

Attributing the attack is not definitive and differs between sources:

  • ESET attributed the attack to the Sandworm group (GRU Unit 74455) with moderate confidence.
  • CERT Poland pointed to an overlap of infrastructure with the Static Tundra/Berserk Bear cluster (Dragonfly, linked to the FSB), without a definitive attribution.

Such divergence is typical of attribution in cyberspace and should not obscure the practical conclusion: regardless of which actor was behind the attack, the entry vector was the same and mundane — a lack of MFA on VPN gateways.

The entry vector: no MFA on VPN

The most important technical lesson from this incident is also the simplest: the attackers got in through VPN gateways without multi-factor authentication. Stolen or guessed credentials were enough to gain a foothold from which the OT environment could be reached.

This is not a sophisticated 0-day — it is hygiene that was missing. In the 2026 landscape, stolen credentials are the main entry vector (22% of breaches per Verizon DBIR 2025), and infostealers flood the market with billions of logins. A gateway without MFA is, in these conditions, an open door.

The broader picture: not just energy

The attack on energy was not isolated. In 2025, incidents were recorded at five Polish water and sewage facilities (including Tolkmicko, Małdyty, Sierakowo, Wydminy and Kuźnica). The attackers (groups linked to Russian military intelligence) gained access to SCADA systems via internet-exposed interfaces and weak passwords. ENISA identifies hacktivist groups as leading the attacks on OT in the EU, focusing on energy and the water economy. According to ENISA, OT threats account for 18.2% of all categories.

The pattern repeats: exposure of management interfaces to the internet + weak access control = a foothold in critical infrastructure. See also: APT attacks on energy infrastructure and the anatomy of an OT security audit at a water utility.

How to protect OT/ICS against wipers

Defending against a wiper is a combination of attack-surface reduction, access control and the ability to recover.

1. Close down remote access

  • Deploy phishing-resistant MFA on all VPN gateways, edge devices and privileged accounts — this is the direct answer to the attack vector.
  • Limit and monitor service access and vendor accounts.

2. Cut off and segment OT

  • Cut SCADA/HMI management interfaces off from the internet; if remote access is necessary, run it through controlled, authenticated channels.
  • Introduce IT/OT segmentation so that a foothold in the office network does not automatically grant access to process control.
  • Check the visibility of your devices in search engines such as Shodan — what you see, the attacker sees too. An OT security audit in manufacturing will help.

3. Assume the attack will succeed — and prepare to recover

  • Maintain immutable, offline backups of configurations and critical data — against a wiper this is the only real insurance.
  • Regularly test recovery, not just backup creation — a backup that cannot be restored does not exist.
  • Rehearse a destruction scenario (tabletop) and build it into business continuity plans; see a tabletop scenario: an attack on industrial ICS/OT systems.

4. Use NIS2 as leverage

For energy infrastructure operators these actions are not optional — they are directly the requirements of the NIS2/KSC regime for essential entities. See NIS2 for the energy sector — requirements and implementation.

Summary

The DynoWiper attack on Polish energy is a reminder of two truths. First, the most dangerous attacks on critical infrastructure are not always technically sophisticated — here a VPN gateway without MFA was enough. Second, against a wiper neither a ransom nor negotiation protects you, but the ability to recover from backups the attacker did not reach. Closing down remote access, IT/OT segmentation and tested, immutable backups are today the minimum for every operator.

The content above is educational, and the attribution of the attack described remains disputed between sources. If you want to assess your OT/ICS infrastructure’s exposure and test your recovery capability, the nFlo team will conduct an audit and help close the gaps.

Sources and reference materials

  • ESET — analysis and naming of the wiper (DynoWiper / Win32/KillFiles.NMO)
  • CERT Poland (NASK) — statements on the attack on the energy sector and attribution
  • ENISA Threat Landscape 2025 — OT threats and hacktivist groups
  • Verizon Data Breach Investigations Report (DBIR) 2025 — entry vectors

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist