The attackers struck numerous wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant, but failed to negatively affect energy generation or distribution.
Poland’s national computer emergency response team, CERT Polska, assessed that all of the incidents were carried out by the same threat actor and were purely destructive in nature. Analysts say the activity aligns with a Russia-linked threat group tracked by multiple vendors as Static Tundra, Berserk Bear, Ghost Blizzard, and Dragonfly.
Källa: Poland’s energy control systems were breached through exposed VPN access – Help Net Security
