The 2025 Polish grid attack used no zero days. That’s the point.
In December 2025, coordinated cyber attacks hit over 30 renewable energy facilities and a major CHP plant in Poland. The attackers disabled RTU controllers, wiped IT systems, and disrupted remote control between wind farms and grid operators.
Their toolbox? Default credentials. Exposed VPN interfaces without MFA. Standard management protocols like HTTP, FTP, and SSH – used against devices that still had factory-set passwords.
In OT networks, where communication patterns are stable and tightly coupled to operational roles, this kind of activity is inherently noisy. Unauthorized HTTPS sessions to RTU web interfaces, SSH connections to controllers from unexpected sources, port scans, SOCKS tunnelling – all of these produce clear network-visible signals.
We mapped the CERT.pl-documented attack chain to concrete OT IDS detection points and examined where and how an intrusion detection system like OMICRON StationGuard could have alerted operators, in many cases well before the destructive phase began.
Read the full analysis: omicroncybersecurity.com























