Russian Electrum Poland energy-sector destructive campaign
Campaign
Summary
Hide ▲
Show ▼
The Russian Electrum-linked December 29, 2025 operation expanded into a multi-site destructive campaign against Poland's energy sector, targeting 30 wind and solar installations and a large CHP plant. The activity destroyed key equipment and used OT disruption tactics across multiple facilities. The breadth of the target set and the repeated destructive methods show a coordinated campaign rather than a single-site incident.
Related Happenings
Poland's energy sector hit by network compromise
Incident
H score30
First: 17.02.2026 23:31
Last: 17.02.2026 23:31
Sources 1
How related:
On December 29, 2025, an attacker believed to be linked to the Russian Electrum threat group targeted 30 wind and solar power installations and a large CHP plant in Poland, destroying key equipment beyond repair.
About this happening:
A destructive cyberattack on Poland's energy sector extended into a second CHP plant after the December 29, 2025 campaign that also hit more than 30 wind and sol...
Poland's energy sector hit by network compromise
IncidentHow related: On December 29, 2025, an attacker believed to be linked to the Russian Electrum threat group targeted 30 wind and solar power installations and a large CHP plant in Poland, destroying key equipment beyond repair.
About this happening: A destructive cyberattack on Poland's energy sector extended into a second CHP plant after the December 29, 2025 campaign that also hit more than 30 wind and sol...
Static Tundra destructive campaign against Polish energy and manufacturing targets
Campaign
H score32
First: 31.01.2026 09:05
Last: 31.01.2026 09:05
Sources 1
About this happening:
The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company*...
Static Tundra destructive campaign against Polish energy and manufacturing targets
CampaignAbout this happening: The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company*...
Sandworm destructive campaign against Poland’s power grid
Campaign
H score46
First: 26.01.2026 12:55
Last: 26.01.2026 12:55
Sources 1
About this happening:
Sandworm ran a coordinated campaign against Poland’s power grid in late December 2025, using a destructive wiper named DynoWiper. The activity targeted two CHP p...
Sandworm destructive campaign against Poland’s power grid
CampaignAbout this happening: Sandworm ran a coordinated campaign against Poland’s power grid in late December 2025, using a destructive wiper named DynoWiper. The activity targeted two CHP p...
Sandworm DynoWiper wiper attack on Polish energy infrastructure
Malware Activity
H score39
First: 24.01.2026 10:21
Last: 24.01.2026 10:21
Sources 1
About this happening:
Sandworm used DynoWiper, a previously undocumented wiper malware, in a failed attack against Poland's energy sector. The activity targeted two combined heat and...
Sandworm DynoWiper wiper attack on Polish energy infrastructure
Malware ActivityAbout this happening: Sandworm used DynoWiper, a previously undocumented wiper malware, in a failed attack against Poland's energy sector. The activity targeted two combined heat and...
Latest development: 29.01.2026 00:14
Dragos says the late-December attack on Poland's power grid was carried out by the Russian activity cluster Electrum with moderate confidence, noting overlap with Sandworm (APT44) but treating Electrum as a distinct cluster. The group targeted exposed and vulnerable RTUs, network edge devices, monitoring and control systems, and Windows-based machines at DER sites, disabled communications equipment at multiple sites, and wiped some Windows systems.
Timeline
-
11.08.2026 02:07 2 articles · 3h ago
Attacker gains WAGO PFC200 PLC foothold at Polish CHP plant
Exploitation ObservedBeginning on December 18, the attacker found a WAGO PFC200 PLC at the CHP plant in Poland whose web interface was exposed on the private APN and protected with default administrator credentials, then compromised the controller and used it as a bridge into the plant’s OT network.
Show sources
- Hackers breached a small Polish energy plant via private APN last year — www.bleepingcomputer.com — 11.08.2026 02:07
- Hackers breached a small Polish energy plant via private APN last year — www.bleepingcomputer.com — 11.08.2026 02:07
-
11.08.2026 02:07 1 articles · 3h ago
Attacker connects to three Siemens PLCs at Polish CHP plant
Campaign Scope UpdateOver the following week, the attacker scanned the CHP plant network for SCADA systems and industrial devices in Poland, and on December 25 connected to three Siemens PLCs, likely preparing for the later destructive action.
Show sources
- Hackers breached a small Polish energy plant via private APN last year — www.bleepingcomputer.com — 11.08.2026 02:07
-
11.08.2026 02:07 1 articles · 3h ago
Attacker shuts down steam turbine and water treatment system at Polish CHP plant
Victim Impact UpdateAt approximately 5:30 a.m. on December 29, the attacker accessed the SCADA interface and Siemens PLCs, switched them into STOP mode, activated password protection, and shut down the steam turbine and process-water treatment system, interrupting cogeneration operations at the small CHP plant before staff restored the impacted systems quickly.
Show sources
- Hackers breached a small Polish energy plant via private APN last year — www.bleepingcomputer.com — 11.08.2026 02:07