Poland experienced a significant surge in cyberattacks in 2025, with 270,000 incidents recorded, according to Deputy Minister of Digital Affairs Paweł Olszewski. He described the situation as a 'war in cyberspace' and noted that the number of attacks has more than doubled compared to the previous year.
In December 2025, a destructive cyberattack targeted the Polish energy sector, including a combined heat and power plant supplying nearly 500,000 customers, as well as multiple wind and solar farms. The attack was unprecedented among NATO and EU members, and Polish authorities suspect it originated from Russia.
Marcin Dudek, head of CERT Polska, said the attack was a 'significant escalation' as it was purely destructive rather than financially motivated. Unlike past ransomware incidents, this attack aimed to cause damage. Dudek noted that such a destructive attack on the energy sector has likely not been seen before in NATO or EU countries.
Analysis by cybersecurity firm ESET pointed to the involvement of a Russian threat actor known as 'Sandworm', which has been linked to similar destructive attacks in Ukraine. The U.S. government has previously attributed Sandworm to Russia's GRU intelligence agency. Another possible culprit is 'Dragonfly', associated with Russia's FSB.
While the electricity supply was not disrupted, the attack heightened concerns about the vulnerability of critical infrastructure. Polish authorities have not yet publicly identified the attacker, but the investigation continues, with experts confident that the trail leads back to Russia.



