
The Lesson from the Hack on the Polish Energy Grid
The recent cyberattack in late 2025 on the Polish energy grid, attributed by multiple sources to Russian hackers, painfully demonstrates the vulnerability of modern supply chains… Read more
The recent cyberattack in late 2025 on the Polish energy grid, attributed by multiple sources to Russian hackers, painfully demonstrates how vulnerable modern supply chains have become. This was not a classic attack on a single organization, but a digital disruption impacting an entire chain of parties that collectively maintain critical infrastructure. This is precisely what makes this incident so relevant for supply chain risk management.
Who Was Affected?
The attack was coordinated and had a purely destructive goal, which Polish authorities even compared to ‘digital arson’. The primary targets were systems related to distributed energy generation:
- Approximately 30 wind and solar power plants;
- A large CHP (Combined Heat and Power) plant, which supplies heat to nearly half a million customers;
- A private company in the manufacturing industry.
It is important to note that a total blackout was prevented thanks to timely intervention by Polish authorities. The attackers did manage to disable communication and control systems, causing operators to temporarily lose visibility into the systems. It has even been reported that some industrial equipment suffered permanent damage.
The Cause: Entering Through the Backdoor
What makes this case so shocking for many companies is that the attackers did not use advanced, unknown vulnerabilities (zero-days), nor was it a classic supply chain attack exploiting a weak supplier.
Research by Cert Polska and involved manufacturers shows that the devices at the affected locations were configured with default login credentials and that recommended security features were disabled.
Furthermore, it was found that Multi-Factor Authentication (MFA) was not enabled at critical access points, meaning that guessing or looking up the default password was sufficient to gain full control. Once inside, the attackers could move laterally through the network and reach operational technology (OT), systems that should ideally be isolated from the public network.
The Lesson for Your Business
This incident teaches us that the threat comes not only from complex hacking techniques but often from basic security flaws at crucial partners. The attackers needed detailed knowledge of the specific systems, but access was surprisingly easy to obtain. The true dependency lies in the systems that enable control and monitoring, precisely the systems that energy providers temporarily lost.
This emphasizes the need to focus on the digital hygiene of those partners who exercise control over vital processes, even if those partners are small, such as the wind and solar farms in this example.