Cyber Attack on Polish Solar Plants Highlights Vulnerabilities in Energy Infrastructure

Cyber Attack on Polish Solar Plants Highlights Vulnerabilities in Energy Infrastructure

First seen 24 Mar 2026, 17:47 UTC Pv-Magazine-UsaPv-Magazine 51.9

Article Content

Browse articles
ThreatCluster

In late December 2025, a cyber attack targeted several solar plants in Poland, affecting 30 renewable energy sites. The attackers deployed wiper malware against substation equipment, leaving solar inverters untouched. This incident revealed that attackers are increasingly targeting the broader ecosystem of distributed energy resources rather than just individual devices. Although the attack did not lead to widespread blackouts, it highlighted vulnerabilities in solar monitors, APIs, and mobile applications that communicate with solar equipment. Backhaul communication channels, such as SSH and HTTPS, are potential entry points for attackers, raising significant cybersecurity concerns. The incident underscores the need for improved security measures across the solar energy sector, as many systems still utilize unencrypted interfaces. Industry experts are calling for enhanced cybersecurity protocols to protect against similar threats in the future.

Key Points: • 30 solar energy sites in Poland were attacked with wiper malware targeting substation equipment. • Solar inverters remained untouched, indicating a shift in attack focus to broader energy systems. • Vulnerabilities exist in solar monitors and APIs, posing significant cybersecurity risks.

Timeline

2025-12-01
Cyber attack on solar plants in Poland occurred
2026-03-24
Articles published detailing the attack and its implications