logo

Default Credentials, Vulnerable Devices Exploited in Polish Energy Grid Attack

ID: 3c624a5d-01bc-5ea4-a6e8-a075f33c0993

STIX ID: report--3c624a5d-01bc-5ea4-a6e8-a075f33c0993

Feed Name: The Cyber Express

Threat Score
88/100

Date Published: 2026-01-30

Date Updated: 2026-04-23

Author: Paul Shread

...
...

CERT Polska reported a December 2025 nation-state cyber campaign that compromised at least 30 distributed energy resources (wind and solar farms) in Poland by exploiting default/static credentials, exposed FortiGate SSL‑VPNs lacking MFA, and outdated/misconfigured OT devices; the attackers deployed DynoWiper-like code and used configuration-based credential harvesting and pivoting to cloud services, resulting in loss of communications with distribution system operators but no immediate impact on generation or grid stability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.