Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meta’s Muse Is Better at Surveilling Than Helping Me

    September 20, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meta’s Muse Is Better at Surveilling Than Helping Me
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4
    • This Week’s Awesome Tech Stories From Around the Web (Through September 19)
    • Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
    • Mathematicians Hate AI. They Can’t Quit It
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Poland’s energy control systems were breached through exposed VPN access
    Cybersecurity

    Poland’s energy control systems were breached through exposed VPN access

    kirklandc008@gmail.comBy kirklandc008@gmail.comFebruary 7, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Poland's energy control systems were breached through exposed VPN access
    Share
    Facebook Twitter LinkedIn Pinterest Email

    On 29 December 2025, coordinated cyberattacks unfolded across Poland’s critical infrastructure, targeting energy and industrial organizations.

    The attackers struck numerous wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant, but failed to negatively affect energy generation or distribution.

    Poland’s national computer emergency response team, CERT Polska, assessed that all of the incidents were carried out by the same threat actor and were purely destructive in nature. Analysts say the activity aligns with a Russia-linked threat group tracked by multiple vendors as Static Tundra, Berserk Bear, Ghost Blizzard, and Dragonfly.

    “In all three incidents, the attackers gained their initial foothold through internet-exposed FortiGate perimeter devices configured as VPN concentrators and firewalls,” CERT said in its report. “In every case, the VPN interface was exposed to the Internet and allowed authentication to accounts defined in the configuration without multi‑factor authentication.”

    Renewable energy facilities lost visibility at substations

    In the renewable energy sector, attackers targeted at least 30 wind and photovoltaic facilities. The activity focused on grid connection point substations, where renewable plants interface with distribution system operators.

    After gaining access, the attackers compromised industrial control systems including RTU controllers, protection relays, HMI computers, and serial device servers.

    The affected equipment included systems from Hitachi Energy, Mikronika, and Moxa deployed within substation and industrial automation environments supporting renewable energy production and distribution. Destructive actions included uploading corrupted firmware, deleting operating files, and resetting devices to factory settings.

    The activity caused a loss of communication between facilities and distribution system operators, reducing monitoring and remote control capabilities, but electricity generation continued.

    Prolonged intrusion preceded heat and power plant sabotage

    On the same day, attackers executed an operation against a heat and power (CHP) plant supplying heat to nearly half a million customers. The goal was irreversible data loss across the organization’s internal network through the deployment of wiper malware.

    Evidence indicates that the incident was preceded by months of unauthorized access, internal reconnaissance, and theft of sensitive operational information. During this period, privileged Active Directory credentials were obtained, enabling lateral movement across servers and workstations.

    A custom wiper known as DynoWiper was later deployed using Group Policy Objects distributed from a domain controller. An EDR platform detected the activity and blocked execution, limiting the scope of damage.

    Indicators associated with the intrusion had been present earlier in 2025, pointing to sustained access and preparation ahead of the attack.

    Manufacturing company targeted in parallel operation

    Attackers also attempted to disrupt operations at a private manufacturing company. The activity unfolded alongside the energy sector attacks, and the target was opportunistic in nature.

    Initial access was gained through a Fortinet perimeter device whose configuration had previously been stolen and publicly disclosed on an online forum used by criminal communities. After access was established, the attackers modified device settings to preserve persistence even if credentials were changed. Movement within the internal network led to administrative access within the Windows domain.

    The destructive phase relied on a PowerShell-based wiper referred to as LazyWiper, which was distributed through Group Policy Objects with the goal of destroying business-critical data. The Polish CERT believes that the file overwriting function employed by the wiper script was generated by an LLM.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Access breached control Energy exposed Polands systems VPN
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Meta Sued Over Training Data for Its AI and Face-Recognition Systems

    September 11, 2026

    This founder is teaching chips how to recycle (their energy)

    September 8, 2026

    An ‘AI Legal Team’ Has Won Its First Case. It’s a Rare Victory for Access to Justice.

    August 27, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Meta’s Muse Is Better at Surveilling Than Helping Me
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4

    Meta’s Muse Is Better at Surveilling Than Helping Me

    September 20, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026

    Napster Is Back, and It Wants to Digitally Clone Teachers

    September 19, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.