OT CT (Ep. 16): The Great Polish Electrical Cyber Attack

OT CT (Ep. 16): The Great Polish Electrical Cyber Attack

🎙 Mike Holcomb 👥 27K 📅 February 4, 2026 ⏱ 64 min 👁 1K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICScyber attackPolandrenewable energy

Summary

In this episode of OT Cyber Tuesday, Mike Holcomb provides a high-level overview of a coordinated cyber attack against distributed energy resources (DER) in Poland in December 2025. The attack targeted wind farms, solar farms, and a combined heating and power plant, affecting about 30 sites. The attackers, likely Russian state-sponsored (possibly Sandworm), gained access months prior and on December 29th launched a destructive attack. They compromised Fortinet firewalls using default credentials, wiped RTUs and IEDs at substations, and disrupted monitoring and control. Despite the scale, there was no power outage because the renewable sources contributed only a small fraction of the grid’s power. The speaker emphasizes the importance of sharing incident details for learning and highlights common security weaknesses such as default credentials and lack of multi-factor authentication. He also discusses the potential future risk if renewable energy becomes a larger share of the grid. The video includes analysis of the attack timeline, techniques, and lessons learned for OT/ICS defenders.

161 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world OT/ICS attack, based on official reports. The speaker’s argumentation is solid, drawing on his experience and the cited reports. He effectively explains the technical aspects and implications for the industry. However, some points are speculative, such as the attribution to Sandworm, which he acknowledges. The discussion on the future risk of renewable energy is well-reasoned.

Scientific Rigor, Source Quality, Title Accuracy

The speaker relies on official reports from Poland CERT and Dragos, which adds credibility. He also mentions Kim Zetter’s article. The title accurately reflects the content. The video is a commentary rather than a primary source, but the speaker clearly distinguishes between facts from reports and his own analysis. The adéquation between title and content is good.

135 words

Title / Content Match

The title accurately reflects the content, which focuses on the Polish electrical cyber attack.

Quality & Reliability

7/10

The video is based on official reports from Poland CERT and Dragos, and the speaker is an experienced OT/ICS cybersecurity professional. However, it is a commentary/analysis rather than a peer-reviewed study, and some details are speculative.

Key Moments

Cited Sources

  • Poland CERT report — Official report on the cyber attack
  • Dragos report — Analysis of the attack by Dragos
  • Kim Zetter article — Article by Kim Zetter on the attack

Concurring Sources

  • Dragos report — Corroborates the details of the attack.

Contribution & Novelties

This video provides a timely analysis of a recent OT/ICS cyber attack, highlighting the importance of securing distributed energy resources. It offers practical lessons for defenders, such as the need to change default credentials and implement MFA. The discussion on the potential future impact on grid stability is particularly relevant as renewable energy adoption increases.

Pour aller plus loin :

88 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, reflecting the detailed technical analysis. The quality and reliability scores are slightly lower due to the reliance on third-party reports and some speculative elements. Overall, the video is a valuable resource for OT/ICS professionals.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.