Key points
- On 29 December 2025, coordinated cyberattacks hit more than 30 wind and solar farms in Poland, plus a combined heat and power plant.
- The attackers targeted equipment at grid connection points. Some devices were reached with default credentials, and RTU firmware was corrupted.
- Electricity production continued, but communication with the distribution system operator was disrupted.
- CERT Polska’s August 2026 follow-up found a further attack path through a misconfigured private mobile network.
- Most of the fixes are basic: know your assets, remove default credentials, control remote access, watch grid-connection devices and plan to run isolated.
On 29 December 2025, coordinated cyberattacks hit more than 30 wind and solar farms in Poland, as well as a combined heat and power plant. The attackers went after the equipment at each site’s grid connection point: remote terminal units (RTUs), human-machine interfaces (HMIs), protection relays and communications devices.
Electricity production continued, but communication with the distribution system operator was disrupted. Plant that keeps generating while the network operator can no longer see or direct it is a pattern seen before.
The equipment involved is found at wind and solar sites in many countries, including Australia. This article sets out what CERT Polska found, how the incident fits a wider pattern, and a checklist any site can work through.
What CERT Polska found
CERT Polska published its incident report on 30 January 2026. It set out that the targets were devices at grid connection points, that some were reached with default credentials, and that RTU firmware was corrupted. A device with corrupted firmware may need to be reloaded or replaced before it works again.
A follow-up report on 8 August 2026 described a new attack path through a misconfigured private mobile network (APN). CERT Polska called the incident the first purely destructive cyberattack on Poland’s energy sector. In other words, its aim was damage, not theft or ransom.
The lessons are plain:
- The grid connection point is a target. It is where a site’s control, protection and communications meet, and where an attacker can cut the link to the network operator.
- Default credentials still work. Some devices were reached with credentials that should have been changed at commissioning.
- Mobile links can open a path around other defences. A misconfigured private mobile network gave the attackers another way in.
Part of a wider pattern
Plant keeps running, but remote control is lost
In February 2022, an attack on the Viasat KA-SAT satellite network cut remote monitoring and control of about 5,800 Enercon wind turbines (11 GW) in Germany. The turbines kept running on automatic control. In both cases generation continued. What was disrupted was the link that lets the network operator see and direct the plant. On a network with a high share of wind and solar, losing that across many sites at once is a system risk, not only a site problem.
Inverters and batteries have known weaknesses
In March 2025, Forescout’s SUN:DOWN research reported 46 new vulnerabilities across products from three leading inverter vendors. It also found that 80% of solar-system vulnerabilities disclosed in the previous three years were high or critical.
In February 2026, Dragos reported authentication-bypass and command-injection flaws in battery energy storage system (BESS) equipment, with more than 100 devices exposed online. Authentication bypass lets an attacker in without a valid login. Command injection lets them run their own commands on the device.
Hidden communication paths
In May 2025, Reuters reported that US officials had found undocumented communication devices, including cellular radios, in some Chinese-made solar inverters and batteries, and that these could let attackers bypass firewalls. The report relied on anonymous sources, so it should be treated with care.
The general lesson holds either way. A firewall only protects traffic that passes through it. A cellular radio inside a device, like a misconfigured private mobile network, can create a path around it.
A checklist for wind and solar sites
ASD’s CI Fortify guidance asks critical infrastructure operators to be able to isolate vital OT and enabling systems for 3 months and to fully rebuild them, starting from a current OT asset inventory. That is a demanding goal. The steps below are where most sites can start.
- Keep a current OT asset inventory. List every device at the grid connection point and across the site, including RTUs, HMIs, protection relays, communications devices, inverters and battery controllers. Record firmware versions and every communication path, including cellular, satellite and vendor links.
- Remove default credentials. Change them on every device at commissioning, after any replacement and after any firmware reload. Then test that no device still accepts them.
- Control remote access. Close links you do not need. Make sure no controller, HMI or battery interface can be reached from the internet. Give vendors access only when needed, with multi-factor authentication and logging. Check the settings of any private mobile network.
- Monitor grid-connection-point devices. Watch RTUs, relays and communications devices for new logins, configuration changes and firmware changes, and for traffic that does not match normal patterns. Dragos found that organisations with full OT visibility detected and contained OT ransomware in 5 days on average, compared with 42 days across industry.
- Plan to operate isolated. Agree with your network operator how the site will run, and how it will be curtailed if needed, when remote links are down. Keep offline copies of firmware and configurations, and hold spares for critical devices, so a corrupted RTU can be rebuilt. Test the plan.
- Know your reporting duties. If your site is a critical infrastructure asset under the SOCI Act, a cyber incident with a significant impact must be reported to ASD within 12 hours of becoming aware of it, and one with a relevant impact within 72 hours. Since 30 May 2025, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must also report any ransomware payment to ASD within 72 hours of making it. Decide in advance who assesses the impact and who reports.
How we approach this
Ozari’s control-room software for DER-heavy distribution networks is designed with these risks in mind.
- It runs on-premise or fully air-gapped, with an offline licence and no call-home.
- Operator commands need approval from two different people, and every command is written to a tamper-evident audit log.
- The control plane never speaks raw field protocols. A separate gateway handles them.
Ozari Defend, our on-premise, AI-native cyber defence for OT, is in early access. A read-only shadow pilot is the simplest way to start.
Sources
- CERT Polska, Energy Sector Incident Report – 29 December 2025, 30 January 2026.
- CERT Polska, Follow-Up Report of the December 2025 Energy Sector Incident, 8 August 2026.
- pv magazine, Satellite cyber attack paralyzes 11GW of German wind turbines, 1 March 2022.
- Forescout, Forescout Vedere Labs Uncovers Severe Systemic Security Risks in Global Solar Power Infrastructure, 27 March 2025.
- Dragos, Dragos 2026 OT Report Shows Surge in Threat Groups and Ransomware, 17 February 2026.
- Utility Dive (reporting Reuters), ‘Rogue’ communication devices found on Chinese-made solar power inverters, 15 May 2025.
- Australian Signals Directorate, CI Fortify, October 2025.
- Australian Signals Directorate, Annual Cyber Threat Report 2024–25 fact sheet: for critical infrastructure (PDF), October 2025.
- Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act 2018: general guidance for critical infrastructure assets (PDF), April 2025.
- MinterEllison, Pay and tell: mandatory ransomware payment reporting obligations in force, 16 June 2025.



