ThreatCluster

Data Destruction and Disk Wiping Techniques Targeting Organizations

First seen 22 Jul 2026, 18:55 UTC attack.mitre.org 80% similarity 76

Article Content

Browse articles
ThreatCluster

Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities. The attacks can affect both on-premises and cloud environments, targeting critical infrastructure and data storage systems. Notable malware such as CaddyWiper and AcidPour have been identified in recent attacks, including the 2022 Ukraine Electric Power Attack and the 2025 Poland Wiper Attacks. Organizations are urged to implement disaster recovery plans and maintain off-system backups to mitigate potential data loss. The threat landscape remains active, with the potential for significant operational disruption.

Key Points: • Adversaries are using malware to overwrite files and disk data, disrupting operations. • Techniques include data destruction and disk wiping, affecting both cloud and on-prem systems. • Organizations must implement disaster recovery plans and secure backups to prevent data loss.

ThreatCluster AI

Timeline

2022-01-01
Ukraine Electric Power Attack
Sandworm Team deployed CaddyWiper to wipe files related to OT capabilities, impacting power infrastructure.
attack.mitre.org
2025-01-01
Poland Wiper Attacks
Adversaries utilized wiper malware to overwrite files, affecting multiple organizations across Poland.
attack.mitre.org
2026-07-22
Current Threat Landscape
Adversaries continue to leverage data destruction and disk wiping techniques, posing a significant threat to organizations.
attack.mitre.org

Community

Browse all →