Sun, Aug 16

DETAILED REPORT OF POLANDS GRID CYBER ATTACK ON DECEMBER 29, 2025

"In each affected facility, a FortiGate device was present, serving as both a VPN concentrator and a firewall. In every case, the VPN interface was exposed to the Internet and allowed authentication to accounts defined in the configuration without multi‑factor authentication. Due to the destructive actions carried out by the attacker, it was not possible to recover complete logs from any of the compromised devices. During the analysis, it was determined that some of these devices had been vulnerable in the past, in certain periods for extended durations, including to remote code execution vulnerabilities. "Available intelligence indicates it is a common practice in the industry to reuse the same accounts and passwords across multiple facilities. In such a scenario, the compromise of even a single account could have enabled the threat actor to identify and access other devices where the same credentials were used."

1786894423978.pdf
5.5MB

1