Find notable cyber news and cases, enriched with sources, timelines, and signals.

Static Tundra destructive campaign against Polish energy and manufacturing targets

Campaign
First reported
Last updated
Happening score
H score 32
2 unique sources, 2 articles

Summary

Hide ▲

The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company, and a CHP plant in Poland. The operation used vulnerable Fortinet/FortiGate devices, wiper malware such as DynoWiper and LazyWiper, and access paths including SSL‑VPN portal service exposure and Active Directory. Public reporting now also links the broader threat actor to router scanning worldwide for weak SNMP passwords and community strings and to exploitation of CVE-2018-0171 on Cisco devices. The same source says the late-2025 Poland energy-infrastructure attacks were officially attributed to FSB Centre 16 by the UK and EU.

Related Happenings

Cybersecurity agencies from 12 countries fresh warning / joint advisory for published on 2026-07-13

Public Sector Action
H score53 First: 13.07.2026 13:40 Last: 13.07.2026 13:40 Sources 1

How related: Cybersecurity agencies from 12 countries have issued a fresh warning that a Russian state-sponsored cyber unit is actively targeting vulnerable routers worldwide.

About this happening: Cybersecurity agencies from 12 countries issued a fresh advisory urging defenders to harden vulnerable routers amid active targeting by a Russian state-sponsored cyber u...

FSB 16th Centre yearslong cyber espionage campaign against European governments and critical infrastructure

Campaign
H score42 First: 13.07.2026 13:00 Last: 13.07.2026 13:00 Sources 1

About this happening: FSB 16th Centre is tied to a yearslong cyberespionage campaign against European governments and critical infrastructure across at least nine countries. The C...

Russian FSB Center 16 router intrusion campaign

Campaign
H score40 First: 13.07.2026 12:32 Last: 13.07.2026 12:32 Sources 1

About this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...

Initial access broker (IAB) campaign expands across multiple victims

Campaign
H score89 First: 22.06.2026 23:01 Last: 22.06.2026 23:01 Sources 1

About this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...

Latest development: 23.06.2026 13:30

On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.

FortigateSniffer FortiOS packet-sniffer credential-harvesting tool

Malware Activity
H score72 First: 22.06.2026 23:01 Last: 22.06.2026 23:01 Sources 1

About this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...

Timeline

  1. 31.01.2026 09:05 1 articles · 5mo ago

    Destructive intrusion on Polish energy and industrial targets

    Exploitation Observed

    On December 29, 2025, coordinated destructive activity targeted more than 30 wind and photovoltaic farms, a private manufacturing company, and a large combined heat and power plant in Poland. The attackers gained access through vulnerable Fortinet and FortiGate devices, moved through power-substation and Active Directory environments, and deployed wiper malware including DynoWiper and LazyWiper, while attempts to detonate the wipers were unsuccessful.

    Show sources
  2. 31.01.2026 09:05 1 articles · 5mo ago

    Communications disruption without power or heat outage

    Victim Impact Update

    On December 29, 2025, destructive activity against Polish renewable-energy infrastructure disrupted communication between affected facilities and the distribution system operator, but electricity production continued. The combined heat and power plant did not lose heat supply to end users, so the operational impact remained limited to communications and attempted sabotage rather than achieved service outages.

    Show sources
  3. 31.01.2026 09:05 3 articles · 5mo ago

    CERT Polska disclosure and attribution update

    Initial Disclosure

    On January 31, 2026, CERT Polska publicly disclosed the coordinated campaign against Polish energy and industrial targets, attributed it to Static Tundra linked to Russia's FSB Center 16 unit, and noted that ESET and Dragos had associated the activity with Sandworm at moderate confidence. The disclosure also described long-term data theft in the combined heat and power plant case dating back to March 2025, use of credentials from on-premises systems to access M365 services such as Exchange, Teams, and SharePoint, and the deployment of DynoWiper and LazyWiper through FortiGate, SSL-VPN, and Active Directory paths.

    Show sources