Researchers say Russian government hackers were behind attempted power outage in Poland


  • ESET links December 2025 energy cyberattack in Poland to Sandworm
  • DynoWiper malware attempted disruption but was stopped before causing significant damage
  • The attack echoes the Sandworm blackout in Ukraine in 2015; Poland faces growing threats from Russian cybercrime and sabotage

The devastating December 2025 cyberattack on Poland’s energy system was most likely the work of Sandworm, an infamous Russian state-sponsored threat actor, experts said.

“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to strong overlap with many previous Sandworm wipe activities we analyzed,” ESET researchers said in a new report.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top