The end of December 2025 will go down in the history of Polish cybersecurity as the moment virtual threats collided hard with physical reality. In the middle of a frost and a snowstorm, critical infrastructure in our country came under an unprecedented, coordinated attack. The goal? Not data theft or a ransom. The goal was pure destruction – the digital equivalent of arson.
The report published by CERT Polska, NASK and the Ministry of Digital Affairs paints a chilling picture. The victims were at least 30 renewable energy farms (wind and solar), a large combined heat and power plant heating almost half a million customers, and a private manufacturing company.
What does this incident teach us, where were the cardinal mistakes made, and how do we keep our own organisations from facing the same scenario?
Anatomy of digital sabotage – how did the attackers get into the network?
The attackers, whose profile resembles the advanced APT group “Static Tundra” (linked in the past to, among other things, attacks on Ukrainian energy), had clearly done excellent reconnaissance of both industrial (OT) and corporate (IT) infrastructure. They used wiper malware (the DynoWiper and LazyWiper variants), whose only job was to erase files irreversibly, destroy disks and physically damage hardware.
What is most alarming, though, is that they did not need any magic zero-day vulnerabilities. They used what has been the Achilles' heel of many companies for years:
- Leaky network edges and no MFA: The way in, at every compromised site, was Fortigate edge devices acting as VPN concentrators. The interfaces were exposed to the internet, and logins required no multi-factor authentication (MFA).
- Default passwords in industrial automation (OT): Once the attackers were inside the renewable energy farm networks, the rest was easy. They logged into industrial controllers (for example Hitachi RTUs, Mikronika HMI computers, Moxa port servers) using the built-in factory credentials (for example the “Default” or “root” accounts).
- Deadly password recycling: The report exposed a pathology that is common in the industry: the same passwords were used across many different sites. Taking over one wind farm handed the attackers the keys to dozens more.
- Active Directory takeover and “bricking” hardware: At the combined heat and power plant, the attackers spent months quietly doing reconnaissance. They stole the Active Directory database (the ntds.dit file), which gave them full control of the domain, and then pushed the wiper out through ordinary GPO policies. At the renewable energy farms, they uploaded modified firmware to the controllers and put them into an endless restart loop, which cut communication with the distribution grid operators.
3 bitter lessons we have to learn
This unprecedented attack was a brutal test of security procedures that exist mostly on paper. Here is what I take from it:
1. MFA is not optional. It is the absolute foundation. Leaving remote access (VPN) without a second authentication factor is an open invitation to an intruder.
2. OT network hygiene is a priority. Industrial environments are on the front line. Deploying automation devices and SCADA/PLC controllers with a default password is unacceptable. Strict segmentation between the IT and OT networks matters just as much.
3. Detection saves the business. At the attacked combined heat and power plant, technology stopped a complete disaster. The malicious code was distributed, but the EDR (Endpoint Detection and Response) software recognised the destructive behaviour and blocked the data-wiping process on more than 100 machines.
Theory is not enough. Why train on cyber ranges such as CDeX?
The conclusions from the reports are obvious, so why do such attacks keep happening? Because procedures on paper do not defend infrastructure in a crisis. When files disappear from the monitors and the SCADA controllers stop responding, what decides the outcome is the “muscle memory” of the security team (SOC) and the engineers. Teams have to train in battle conditions, but testing destructive malware on live production systems is out of the question.
The answer is a modern cyber range, such as the Polish platform CDeX (Cyber Defence eXercise Platform). Why is adopting this kind of solution now a market “must-have” for critical sectors?
- Digital twins: CDeX lets you recreate your real IT/OT infrastructure 1:1 in a fully isolated, virtual environment. You can test your defences, see how the network reacts to attacks and learn from mistakes, with no risk of stopping real production or power supply.
- Dedicated scenarios for energy and industry: The platform offers more than 500 hours of hyper-realistic training, covering MITRE ATT&CK techniques 100%. In the context of the 29 December attack, the built-in scenarios are particularly valuable: “SCADA: Reusable Energy Scenario” (focused on wind farms), “Secure OT architecture: Defense of SCADA/ICS” (protection against attacks on industrial devices) and advanced modules that teach defence against domain takeover (Windows AD Advanced Attacks).
- Blue vs Red Team exercises: Lecture-hall theory is a thing of the past. CDeX lets you run “live-fire” exercises in which your team (Blue Team) actively defends the replicated infrastructure, while the other half of the crew (Red Team) or built-in automated bots carry out sophisticated attacks.
- Safe testing and measurability: Exercises can take the engaging form of Capture The Flag (CTF). Trainers monitor progress in real time, see where the team has gaps and can change the attack conditions on the fly.
Summary
The attack on Polish energy shows that the threat of sabotage is very real, and that cybercriminals ruthlessly exploit basic neglect. The cost of downtime in critical infrastructure is enormous today.
We cannot build security on hope alone. Investing in advanced training platforms such as CDeX lets you move from theory to hard practice. A team that has “survived” and repelled a simulated destructive wiper attack on a virtual range will react faster, with more confidence and more effectively in real life. In cybersecurity, “train the way you will fight” matters more today than ever.
Want to keep up with the most important analyses from the world of cybersecurity and learn more about practical protection of IT and OT infrastructure? Read my blog at istrus.pl regularly!


