Critical Infrastructure Security, Threat Intelligence

Impact of Sandworm’s averted breach of Poland’s power grid detailed

Binary code on flag of Russia. Program source code or Hacker concept on Russian flag. Russia digital technology security, hacking or programming

Nearly 30 distributed energy generation sites across Poland have been compromised by the thwarted December cyberattack attributed to the Russian state-sponsored hacking operation Sandworm, according to The Record, a news site by cybersecurity firm Recorded Future.

Even though Poland's electricity system was untouched by the intrusion, attackers were able to infiltrate combined heat and power facilities' communication and control systems, as well as systems necessary for renewable energy dispatching from solar and wind facilities, a report from Dragos revealed.

"What remains unclear is whether the hackers attempted to issue operational commands to this equipment or focused solely on disabling communications," said researchers, who noted that undertaking such an intrusion required knowledge of the systems' inner workings.

Such findings, which cement distributed energy systems as valid cyberattack targets, come after Sandworm which has been behind Russia's most damaging cyber intrusions since its emergence in 2013 was reported by ESET to have leveraged the novel DynoWiper malware in its attack on Poland's energy infrastructure.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds