Summary

On 29 December 2025, attackers carried out a destructive operation against Poland’s energy sector. According to CERT Polska it hit approximately 30 sites, including combined heat and power plants and dispatch centres for wind and solar facilities. Reconnaissance and unauthorised access had been detected from March to July 2025.

Entry point: Fortinet FortiGate devices exposed to the internet, using default credentials and no multi-factor authentication, which served as both firewalls and VPN gateways.

Affected OT equipment, some of it permanently damaged:

  • Hitachi Energy RTU560 remote terminal units and Relion 650 protection and control relays;
  • Mikronika RTUs and HMIs;
  • Moxa NPort serial device servers.

On Windows systems the attackers deployed a new wiper, DynoWiper. ESET (30 January 2026) describes three phases: recursive file wiping, a second wiping pass, then a forced reboot. Three variants were deployed within hours. ESET’s endpoint protection on the targeted machines interfered with all three, limiting the damage.

No power outage occurred. CERT Polska noted “there was a risk of causing a disruption in electricity generation at the affected facilities.”

Attribution is contested:

  • ESET attributes DynoWiper to Sandworm with medium confidence, citing similarities to the ZOV wiper used in Ukraine. Dragos also points to Sandworm/ELECTRUM.
  • CERT Polska links the activity to the actor tracked as Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly.

Apa maksudnya untuk Malaysia? 🇲🇾

This is the most transferable OT incident of the past year for Malaysia. The initial access was an internet-facing firewall with default credentials and no MFA. The same failure behind the FortiBleed campaign that hit Malaysian organisations in June 2026. Malaysia’s renewable build-out (including the Large Scale Solar programme) adds many small, remotely managed generation sites. That is exactly the profile of the Polish wind and solar dispatch targets.

  • Audit every firewall/VPN that fronts an OT or generation site: no default or shared credentials, MFA enforced, management interface not on the internet.
  • Segment RTUs, relays and serial servers behind the site firewall, and keep known-good configurations and firmware offline for rebuild.
  • Treat endpoint protection on OT Windows hosts as a control that matters. It measurably blunted the wiper in Poland.
  • NC4’s network segmentation alert is the local reference for the containment side.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0883Internet Accessible DeviceInternet-exposed FortiGate firewall/VPN
T0822External Remote ServicesVPN access into sites
T1694.001Default CredentialsDefault credentials, no MFA
T1693.001System FirmwareField devices corrupted and rendered unusable
T0809Data DestructionDynoWiper on Windows HMIs/servers
T0879Damage to PropertySome ICS devices permanently damaged

Detection guidance

  • Alert on administrative logins to edge firewalls from unexpected geographies or with default account names, and on any new local admin accounts.
  • Monitor configuration and firmware changes on RTUs, relays and serial servers against a known-good baseline.
  • Detect mass file overwrite and forced-reboot behaviour on HMIs and engineering hosts.

IoCs

Indicators are published in the CERT Polska report and ESET’s DynoWiper analysis.

References