Poland, December 2025: lessons for every wind and solar site

Attackers hit more than 30 wind and solar farms in Poland through grid-connection devices, some with default credentials. What every site can learn.

Abstract illustration of wind turbines and solar panels linked to a grid connection point, with one communication line broken

Key points

  • On 29 December 2025, coordinated cyberattacks hit more than 30 wind and solar farms in Poland, plus a combined heat and power plant.
  • The attackers targeted equipment at grid connection points. Some devices were reached with default credentials, and RTU firmware was corrupted.
  • Electricity production continued, but communication with the distribution system operator was disrupted.
  • CERT Polska’s August 2026 follow-up found a further attack path through a misconfigured private mobile network.
  • Most of the fixes are basic: know your assets, remove default credentials, control remote access, watch grid-connection devices and plan to run isolated.

On 29 December 2025, coordinated cyberattacks hit more than 30 wind and solar farms in Poland, as well as a combined heat and power plant. The attackers went after the equipment at each site’s grid connection point: remote terminal units (RTUs), human-machine interfaces (HMIs), protection relays and communications devices.

Electricity production continued, but communication with the distribution system operator was disrupted. Plant that keeps generating while the network operator can no longer see or direct it is a pattern seen before.

The equipment involved is found at wind and solar sites in many countries, including Australia. This article sets out what CERT Polska found, how the incident fits a wider pattern, and a checklist any site can work through.

What CERT Polska found

CERT Polska published its incident report on 30 January 2026. It set out that the targets were devices at grid connection points, that some were reached with default credentials, and that RTU firmware was corrupted. A device with corrupted firmware may need to be reloaded or replaced before it works again.

A follow-up report on 8 August 2026 described a new attack path through a misconfigured private mobile network (APN). CERT Polska called the incident the first purely destructive cyberattack on Poland’s energy sector. In other words, its aim was damage, not theft or ransom.

The lessons are plain:

  • The grid connection point is a target. It is where a site’s control, protection and communications meet, and where an attacker can cut the link to the network operator.
  • Default credentials still work. Some devices were reached with credentials that should have been changed at commissioning.
  • Mobile links can open a path around other defences. A misconfigured private mobile network gave the attackers another way in.

Part of a wider pattern

Plant keeps running, but remote control is lost

In February 2022, an attack on the Viasat KA-SAT satellite network cut remote monitoring and control of about 5,800 Enercon wind turbines (11 GW) in Germany. The turbines kept running on automatic control. In both cases generation continued. What was disrupted was the link that lets the network operator see and direct the plant. On a network with a high share of wind and solar, losing that across many sites at once is a system risk, not only a site problem.

Inverters and batteries have known weaknesses

In March 2025, Forescout’s SUN:DOWN research reported 46 new vulnerabilities across products from three leading inverter vendors. It also found that 80% of solar-system vulnerabilities disclosed in the previous three years were high or critical.

In February 2026, Dragos reported authentication-bypass and command-injection flaws in battery energy storage system (BESS) equipment, with more than 100 devices exposed online. Authentication bypass lets an attacker in without a valid login. Command injection lets them run their own commands on the device.

Hidden communication paths

In May 2025, Reuters reported that US officials had found undocumented communication devices, including cellular radios, in some Chinese-made solar inverters and batteries, and that these could let attackers bypass firewalls. The report relied on anonymous sources, so it should be treated with care.

The general lesson holds either way. A firewall only protects traffic that passes through it. A cellular radio inside a device, like a misconfigured private mobile network, can create a path around it.

A checklist for wind and solar sites

ASD’s CI Fortify guidance asks critical infrastructure operators to be able to isolate vital OT and enabling systems for 3 months and to fully rebuild them, starting from a current OT asset inventory. That is a demanding goal. The steps below are where most sites can start.

  1. Keep a current OT asset inventory. List every device at the grid connection point and across the site, including RTUs, HMIs, protection relays, communications devices, inverters and battery controllers. Record firmware versions and every communication path, including cellular, satellite and vendor links.
  2. Remove default credentials. Change them on every device at commissioning, after any replacement and after any firmware reload. Then test that no device still accepts them.
  3. Control remote access. Close links you do not need. Make sure no controller, HMI or battery interface can be reached from the internet. Give vendors access only when needed, with multi-factor authentication and logging. Check the settings of any private mobile network.
  4. Monitor grid-connection-point devices. Watch RTUs, relays and communications devices for new logins, configuration changes and firmware changes, and for traffic that does not match normal patterns. Dragos found that organisations with full OT visibility detected and contained OT ransomware in 5 days on average, compared with 42 days across industry.
  5. Plan to operate isolated. Agree with your network operator how the site will run, and how it will be curtailed if needed, when remote links are down. Keep offline copies of firmware and configurations, and hold spares for critical devices, so a corrupted RTU can be rebuilt. Test the plan.
  6. Know your reporting duties. If your site is a critical infrastructure asset under the SOCI Act, a cyber incident with a significant impact must be reported to ASD within 12 hours of becoming aware of it, and one with a relevant impact within 72 hours. Since 30 May 2025, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must also report any ransomware payment to ASD within 72 hours of making it. Decide in advance who assesses the impact and who reports.

How we approach this

Ozari’s control-room software for DER-heavy distribution networks is designed with these risks in mind.

  • It runs on-premise or fully air-gapped, with an offline licence and no call-home.
  • Operator commands need approval from two different people, and every command is written to a tamper-evident audit log.
  • The control plane never speaks raw field protocols. A separate gateway handles them.

Ozari Defend, our on-premise, AI-native cyber defence for OT, is in early access. A read-only shadow pilot is the simplest way to start.

Start safely

Begin with a read-only shadow pilot

Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.

Secret Link