Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Energy Sector Incident Report

68192ca0fde951d973eb41a07814f402

TLP:CLEAR
Active

MD5 Hash

Description

On December 29, 2025, coordinated destructive cyberattacks targeted Poland's energy infrastructure during severe winter weather. Approximately 30 wind and solar farms, a manufacturing company, and a combined heat and power plant serving nearly 500,000 customers were affected. Attackers exploited vulnerable FortiGate perimeter devices using stolen credentials and default passwords to access industrial control systems. Multiple types of wiper malware, including DynoWiper and LazyWiper, were deployed to destroy data across IT and OT environments. While renewable facilities lost communication with distribution operators without affecting electricity generation, the incidents demonstrated significant capability to cause physical disruption. Infrastructure analysis revealed connections to threat clusters known as Static Tundra, Ghost Blizzard, and potentially Sandworm, marking a notable escalation in cyber-sabotage operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Energy Sector Incident Report
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 16:06
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 68192ca0fde951d973eb41a07814f402

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.