← All posts
16 Feb 2026Cybersecurity · Critical Infrastructure · OT Security

What the destructive attack on Polish energy infrastructure teaches us

December 2025: wiper malware, thirty renewable energy farms and a district heating plant. The entry vector was edge devices exposed to the internet without multi-factor authentication.

Grzegorz Struś5 min read
What the destructive attack on Polish energy infrastructure teaches us

The end of December 2025 will go down in the history of Polish cybersecurity as the moment virtual threats collided hard with physical reality. In the middle of a frost and a snowstorm, critical infrastructure in our country came under an unprecedented, coordinated attack. The goal? Not data theft or a ransom. The goal was pure destruction – the digital equivalent of arson.

The report published by CERT Polska, NASK and the Ministry of Digital Affairs paints a chilling picture. The victims were at least 30 renewable energy farms (wind and solar), a large combined heat and power plant heating almost half a million customers, and a private manufacturing company.

What does this incident teach us, where were the cardinal mistakes made, and how do we keep our own organisations from facing the same scenario?

Anatomy of digital sabotage – how did the attackers get into the network?

The attackers, whose profile resembles the advanced APT group “Static Tundra” (linked in the past to, among other things, attacks on Ukrainian energy), had clearly done excellent reconnaissance of both industrial (OT) and corporate (IT) infrastructure. They used wiper malware (the DynoWiper and LazyWiper variants), whose only job was to erase files irreversibly, destroy disks and physically damage hardware.

What is most alarming, though, is that they did not need any magic zero-day vulnerabilities. They used what has been the Achilles' heel of many companies for years:

3 bitter lessons we have to learn

This unprecedented attack was a brutal test of security procedures that exist mostly on paper. Here is what I take from it:

1. MFA is not optional. It is the absolute foundation. Leaving remote access (VPN) without a second authentication factor is an open invitation to an intruder.

2. OT network hygiene is a priority. Industrial environments are on the front line. Deploying automation devices and SCADA/PLC controllers with a default password is unacceptable. Strict segmentation between the IT and OT networks matters just as much.

3. Detection saves the business. At the attacked combined heat and power plant, technology stopped a complete disaster. The malicious code was distributed, but the EDR (Endpoint Detection and Response) software recognised the destructive behaviour and blocked the data-wiping process on more than 100 machines.

Theory is not enough. Why train on cyber ranges such as CDeX?

The conclusions from the reports are obvious, so why do such attacks keep happening? Because procedures on paper do not defend infrastructure in a crisis. When files disappear from the monitors and the SCADA controllers stop responding, what decides the outcome is the “muscle memory” of the security team (SOC) and the engineers. Teams have to train in battle conditions, but testing destructive malware on live production systems is out of the question.

The answer is a modern cyber range, such as the Polish platform CDeX (Cyber Defence eXercise Platform). Why is adopting this kind of solution now a market “must-have” for critical sectors?

Summary

The attack on Polish energy shows that the threat of sabotage is very real, and that cybercriminals ruthlessly exploit basic neglect. The cost of downtime in critical infrastructure is enormous today.

We cannot build security on hope alone. Investing in advanced training platforms such as CDeX lets you move from theory to hard practice. A team that has “survived” and repelled a simulated destructive wiper attack on a virtual range will react faster, with more confidence and more effectively in real life. In cybersecurity, “train the way you will fight” matters more today than ever.

Want to keep up with the most important analyses from the world of cybersecurity and learn more about practical protection of IT and OT infrastructure? Read my blog at istrus.pl regularly!

Grzegorz Struś

Grzegorz Struś

I spent fifteen years running operations, sales and transformation programmes in technology companies. Now I do the same for companies moving into their next stage, as an operations director, on an interim mandate or through a defined project.

Book a time in my calendar
Next post
The end of the era of safe choices
4 Feb 2026

The end of the era of safe choices

Why boards increasingly prefer the risk of a small supplier to overpaying a giant — and what that changes about how you have to sell.