Researchers say Russian government hackers were behind the attempted blackout in Poland


  • ESET links December 2025 Poland energy cyber attack to Sandworm
  • The DynoWiper malware attempted to interrupt, but was stopped before it could cause significant damage
  • Attack echoes Sandworms 2015 Ukraine blackout; Poland faces increasing Russian cyber and sabotage threats

The devastating December 2025 cyber attack on Poland’s energy system was most likely the work of Sandworm, a notorious Russian state-sponsored threat actor, experts have said

“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with several previous Sandworm wiper activities we analyzed,” ESET researchers said in a new report.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top