logo

Sandworm Blamed for Wiper Attack on Poland Power Grid

ID: cd455897-b12f-59f8-9273-618217e35b55

STIX ID: report--cd455897-b12f-59f8-9273-618217e35b55

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-01-26

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

A destructive wiper attack on Dec. 29–30 targeted two combined heat and power plants and a renewable energy management system in Poland; ESET attributes the activity with medium confidence to the Russian Sandworm APT and identifies the malware as DynoWiper, while Polish authorities reported no blackout or successful disruption. The report places the incident in the context of Sandworm's prior disruptive campaigns (BlackEnergy, NotPetya, Industroyer) but contains limited technical details or IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.