Policy & Regulation
Basic security failures allowed Russian hackers into Polish power grid
Poland’s CERT reports that suspected Russian government hackers breached energy grid infrastructure using basic security failures, though the attacks failed to disrupt power.
Poland’s Computer Emergency Response Team (CERT), which is part of the country’s Ministry of Digital Affairs, has released a technical report detailing a cyber incident from the end of last year. According to the report, suspected Russian government hackers breached parts of Poland’s energy grid infrastructure by exploiting basic security failures. The targeted facilities included wind and solar farms as well as a heat-and-power plant. The hackers did not face a lot of resistance because the systems they targeted used default usernames and passwords and did not have multi-factor authentication enabled, both of which the report characterized as incredibly basic mistakes.
Once inside the networks, the hackers attempted to infect the systems they broke into with wiper malware designed to erase and effectively destroy them. The report noted that the attackers were perhaps trying to turn off the power, though it remains unclear if that was their actual goal. While the cyberattack was successfully stopped at the heat-and-power plant, the malware made the systems used to monitor and control grid systems at the wind and solar farms inoperable. Despite this disruption, the hackers failed to shut down the power at any of the targeted facilities. The report asserted that even if the hackers had succeeded, the intrusions would not have affected the stability of the Polish power system during the period in question.
The technical report emphasized the hostile intent behind the cyberattack, stating, “All of the attacks were purely destructive in nature — by analogy to the physical world, they can be compared to deliberate acts of arson.”
The intrusions, which occurred on December 29 of last year, have drawn differing attributions from cybersecurity experts. Cybersecurity firms ESET and Dragos previously released reports blaming the intrusions on the notorious Russian government hacking group Sandworm, which has a documented history of targeting energy infrastructure in Ukraine. However, Poland’s CERT has accused a different Russian government hacking group, known as Berserk Bear or Dragonfly, which is typically associated with traditional cyberespionage rather than destructive operations.
Why it matters
This incident highlights how critical infrastructure remains vulnerable to basic security lapses, even when targeted by sophisticated state-backed actors. It underscores the ongoing cyber threat to energy grids in the region.