1 min read  ·  248 words

A cyber attack on Poland’s power grid on December 29, 2025, exploited internet-exposed FortiGate VPN concentrators lacking multi-factor authentication and reused credentials across multiple substations, enabling attackers to move laterally through critical infrastructure. The breach underscores how basic security hygiene failures — not sophisticated zero-days — can compromise national energy systems.

The investigation revealed that each compromised facility relied on FortiGate devices serving as both firewall and VPN gateway, with the VPN interface directly accessible from the internet. Authentication depended solely on locally defined accounts, and forensic analysis confirmed that some devices had remained unpatched against known remote code execution vulnerabilities for extended periods. Destructive attacker activity wiped logs, preventing full reconstruction of the intrusion timeline.

Credential reuse across geographically dispersed sites turned a single point of compromise into a systemic breach. Intelligence indicates that shared accounts and passwords are common practice in operational technology environments, where convenience often overrides segmentation. Once valid credentials were obtained — whether through vulnerability exploitation or credential stuffing — the threat actor could enumerate and access other facilities using the same login pairs, bypassing network-level defenses entirely.

This incident reflects a broader pattern in critical infrastructure: legacy remote access architectures designed for availability, not resilience. The convergence of IT and OT networks has expanded the attack surface, yet many operators still treat VPN concentrators as set-and-forget appliances. Mandating multi-factor authentication, enforcing unique credentials per site, and implementing continuous vulnerability management are no longer optional — they are baseline requirements for grid reliability.

Read the full report at Energy Central.

Written by