CERT Polska details coordinated attack on Polish energy infrastructure

CERT Polska has published an incident report on a coordinated attack against Polish energy infrastructure and a private manufacturing company on 29 December. More than 30 wind and solar farms were targeted, along with several components in the surrounding grid. Both IT and OT environments were involved, and the investigation uncovered several previously unknown destructive malware variants, among them Lazywiper and Dynowiper. The report concludes the attack was destructive, but that the effect was limited to disrupted communications and did not directly affect heat and power production. The analysis points to the Russia-affiliated group Berserk Bear/Ghost Blizzard as the likely actor.

What this means for your organisation

The Norwegian power sector shares suppliers, remote-management models and the same IT/OT coupling as the Polish one. What matters in this report is not the malware itself but that the attack struck many small generation units at once. Renewable sites are often unmanned, remotely monitored and operated by third parties, and that is where preparedness is typically weakest. Organisations in scope for NIS2 should read this as a description of their own threat picture.

Berigo recommends

  • Map every remotely operated generation unit and who genuinely has access, including supplier service accounts.
  • Test that you can keep sites running without central communications, and exercise that scenario specifically.
  • Separate IT and OT networks with controlled crossings, and log the traffic between them.
  • Add destructive malware, not just ransomware, as its own scenario in your incident plan.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch