www.securityweek.com 8/10/2026, 10:17:17 AM · external

Poland’s grid hit again by Sandworm via Fortinet VPN

Poland’s grid hit again by Sandworm via Fortinet VPN
CyberSIXT Evidence Panel
Primary Source cert.pl
Threat Actor

POLAND'S CERT reported a second cyberattack on the country’s power grid by Russian-linked threat actors (Sandworm), specifically targeting industrial control systems in December 2025. The attackers aimed for destructive consequences, affecting safety and stability monitoring systems of around 30 sites, including CHP plants and renewable energy centers without causing electrical outages. The attack leveraged a private APN used in energy facilities, which had not previously been reported.

A smaller CHP plant faced particular disruption, with the shutdown of steam turbines and water treatment systems caused by the hacking. Attackers exploited a Fortinet VPN and cellular router, gaining access to PLCs that controlled critical operational technology. Although systems were restored quickly, physical damage occurred to some ICS devices, and the report warned of vulnerabilities in similar configurations worldwide.

View Primary Source Via www.securityweek.com

Article by CyberSIXT