Quick Summary
The Securityish Brief
On December 29, 2025, Poland experienced a series of cyberattacks that targeted critical infrastructure within its energy sector. The attacks affected various facilities, including at least 30 wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant. CERT Polska reported that all incidents were executed by the same threat actor, identified as a Russia-linked group known by names such as Static Tundra and Berserk Bear.
The attackers gained initial access through internet-exposed FortiGate perimeter devices, which were configured as VPN concentrators and firewalls. These devices allowed authentication without multi-factor authentication, making them vulnerable. Although the attacks caused significant disruptions, such as loss of communication and operational capabilities, they did not impact electricity generation.
In the renewable energy sector, the attackers compromised industrial control systems, including RTU controllers and HMI computers, leading to corrupted firmware uploads and deletion of operating files. This resulted in reduced monitoring and control capabilities for the affected facilities.
In a parallel operation, the attackers targeted a CHP plant supplying heat to nearly half a million customers. They aimed for irreversible data loss through the deployment of a custom wiper malware known as DynoWiper. Evidence suggests that this attack was preceded by months of unauthorized access and reconnaissance.
Additionally, a private manufacturing company was targeted during the same timeframe. Attackers gained access through a compromised Fortinet device configuration that had been disclosed online. They used a PowerShell-based wiper called LazyWiper to destroy critical data within the organization.
Implications for Cybersecurity
This incident highlights the critical vulnerabilities associated with exposed VPN configurations and the importance of implementing multi-factor authentication. Organizations should prioritize securing perimeter devices and regularly review their configurations to prevent unauthorized access.
Moreover, the use of advanced wiper malware like DynoWiper and LazyWiper indicates a shift towards more destructive cyber tactics. Companies in critical sectors must enhance their monitoring capabilities and incident response plans to mitigate the risks posed by such sophisticated attacks.
Key Takeaways
- Review and secure all internet-exposed VPN configurations to prevent unauthorized access.
- Implement multi-factor authentication on critical systems to enhance security.
- Regularly monitor for unusual activity and unauthorized access attempts on network devices.
- Develop and test incident response plans to address potential cyber threats effectively.
- Educate employees about the risks of phishing and other social engineering tactics that could lead to breaches.
Key Terms & Concepts
- FortiGate: In this article, FortiGate refers to a type of security device used for VPN and firewall functions.
- DynoWiper: DynoWiper is a custom wiper malware designed to erase data and disrupt operations.
- LazyWiper: LazyWiper is a PowerShell-based wiper malware used to destroy business-critical data.
- CERT Polska: CERT Polska is Poland’s national computer emergency response team that assesses and responds to cybersecurity incidents.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.