Cyber ​​Siege: How Hackers Target the World’s Infrastructure

 



Introduction

The years 2025 and 2026 have witnessed an unprecedented escalation in cyberattacks targeting critical infrastructure worldwide. What was once the domain of theoretical risk assessments and cybersecurity exercises has become a tangible reality: nation-state hackers, operating with increasing sophistication and audacity, are systematically probing, penetrating, and in some cases destroying the systems that keep modern societies functioning. From the electricity grids of Poland and Sweden to the public transportation network of Los Angeles, from enterprise firewall appliances to medical device manufacturers, the pattern is unmistakable. Cyberwarfare has moved from the margins to the mainstream of geopolitical conflict.

This essay examines ten major cyberattacks that have occurred between 2025 and 2026, analyzing their methods, attribution, impact, and broader implications for global security. These incidents—ranging from data-destroying wiper malware to credential theft campaigns affecting tens of thousands of devices—reveal a dangerous new reality: critical infrastructure is under siege, and the attackers are growing bolder.

1. The Polish Electricity Grid Attack: Data-Destroying Malware and the Specter of Mass Blackouts

In December 2025, Poland's electricity grid became the target of a sophisticated cyberattack that, had it succeeded, could have plunged half a million citizens into darkness during the depths of winter. The attack, first publicly disclosed in January 2026 by cybersecurity firms ESET and Dragos, involved the deployment of a data-destroying malware known as a wiper, specifically, a variant called DynoWiper.

The attackers successfully compromised approximately 30 distributed energy sites across Poland, including combined heat and power plants, wind farms, and solar energy dispatch centers. Their primary target was not the active power generation systems themselves but the communication and control infrastructure—specifically, remote terminal units (RTUs) that interface between physical equipment and control systems. By disabling these devices, the hackers effectively blinded operators to the status of critical equipment. In some cases, the damage was permanent: industrial control system devices were bricked, rendered irreparably damaged and impossible to restore in the field.

The attack bore the hallmarks of Russia's notorious Sandworm group, also tracked by Dragos as Electrum, a threat actor with a long history of targeting energy infrastructure. Sandworm had previously been implicated in the 2015 and 2016 cyberattacks on Ukraine's power grid, which caused widespread blackouts. However, the Polish attack differed in one critical respect: it appeared rushed and opportunistic rather than meticulously planned. As Dragos noted, this operation looked very rushed, but it is impossible to assess the reason.

The implications were nonetheless grave. The attackers demonstrated the ability to systematically compromise RTUs across multiple sites, suggesting they had mapped common configurations and operational patterns to exploit systematically. While no power outages occurred, due to the inherent design of electrical systems, which continue operating in their last known state even when communication is lost, the attack served as a stark warning. Polish authorities confirmed that if the attackers had issued malicious operational commands, the consequences could have been catastrophic.

The UK Foreign Office later formally attributed the attack to Russia's Federal Security Service (FSB), specifically its Centre 16. In July 2026, the United Kingdom and the European Union imposed their first coordinated package of cyber sanctions against Russian hackers in response.

For more details about this attack, click here

2. The Swedish Thermal Power Plant: A Failed Assault by Pro-Russian Hackers

In the spring of 2025, a pro-Russian hacker group attempted to breach a thermal power plant in western Sweden. The attack, disclosed publicly by Sweden's Minister for Civil Defense Carl-Oskar Bohlin in June 2026, targeted the plant's operational technology (OT) systems, the industrial software that controls physical infrastructure such as power generation equipment.

The attempted intrusion was unsuccessful, thanks to the facility's built-in security protections. Sweden's security service investigated the incident and identified the perpetrators, who are believed to have links to Russian intelligence services. Bohlin noted that similar attempts had been recorded in neighboring Norway and Denmark, while Poland had experienced a comparable attack on a much larger scale.

Perhaps most significantly, the Swedish minister observed a troubling shift in tactics: these groups that once carried out denial-of-service attacks are now attempting destructive cyberattacks against organizations in Europe. This evolution, from nuisance-level website takedowns to potentially life-threatening infrastructure attacks, represents a fundamental escalation in the threat landscape.

For more details about this attack, click here

3. The Los Angeles Metro Attack: Iranian Intelligence Behind a Transit System Breach

In March 2026, the Los Angeles County Metropolitan Transportation Authority (LACMTA), widely known as LA Metro, discovered a breach that would force the shutdown of parts of its network. The attack, which disrupted internal operations but did not impact rail and bus services, was initially claimed by a group calling itself Ababil of Minab, which purported to be a pro-Iranian hacktivist collective.

However, forensic investigation by Israeli cybersecurity firm Gambit Security revealed a different reality. The group was not a standalone hacktivist crew but rather an operation with ties to Iran's Ministry of Intelligence and Security (MOIS). Gambit's researchers found that Ababil of Minab used infrastructure previously associated with Black Shadow, an Iranian group operating on behalf of MOIS.

The attackers' methods were devastatingly effective. They erased databases, virtual machines, and storage volumes using both automated scripts and manual hands-on-keyboard activity. Their playbook combined multiple techniques across virtualization, storage, and backup infrastructure specifically designed to deny recovery. The hackers published screenshots and videos demonstrating their access to LA Metro's internal systems, including a core virtualization management platform, web servers, and even an operational technology system used to monitor trains.

The attack was part of a broader wave of Iranian cyber operations following US and Israeli strikes on Iran in late February 2026. The timing was particularly sensitive: Los Angeles was one of the host cities for the FIFA 2026 World Cup, which began on June 11. The breach took weeks to fully remediate, with hundreds of servers requiring inspection before they could be brought back online.

For more details about this attack, click here

4. FortiBleed: The Massive Credential Theft Campaign Against Fortinet Firewalls

In June 2026, security researchers disclosed an ongoing, large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate firewalls and VPN gateways. Dubbed FortiBleed, the operation had been running since at least February 2026 and resulted in the compromise of over 86,000 devices across 194 countries, representing approximately half of all internet-facing Fortinet firewalls worldwide.

The attackers amassed a verified database of valid administrator and VPN credentials through a combination of methods: brute-force attacks, interception of SSL VPN authentication data, exploitation of known vulnerabilities, and extraction of configuration information from compromised devices. They executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at MSSQL servers. The campaign was attributed to a Russian-speaking threat actor operating as an Initial Access Broker.

The potential impact was staggering. Valid administrative credentials would allow attackers to modify firewall policies, create backdoor accounts, disable security controls, and establish persistent access. VPN credentials could provide direct entry into corporate networks, bypassing perimeter security. Compromised firewall access could facilitate Active Directory compromise, credential theft, privilege escalation, and internal reconnaissance, often serving as a precursor to data exfiltration, ransomware deployment, or supply-chain attacks.

At least four organizations were fully compromised as a result of the campaign, including major government entities and critical infrastructure providers. The US Cybersecurity and Infrastructure Security Agency (CISA) issued urgent mitigation guidance, including terminating active sessions, resetting all credentials, enforcing phishing-resistant multi-factor authentication, and restricting management access.

For more details about this attack, click here

5. The Stryker Wiper Attack: Weaponizing Microsoft Intune Against a Fortune 500 Company

On March 11, 2026, the global medical technology giant Stryker Corporation was paralyzed by one of the most consequential cyberattacks in history. The Iran-linked hacktivist group Handala, operating with the backing of Iran's Ministry of Intelligence and Security, used compromised Microsoft Entra ID Global Administrator credentials to issue a legitimate Remote Wipe command through Microsoft Intune.

In approximately three hours, an estimated 80,000 devices across 79 countries were destroyed. No malware was deployed. The attackers simply weaponized the enterprise's own management tools against it, an emerging class of attack termed living off trusted services (LoTS). Because the destructive action was performed through valid platform features using valid credentials, traditional malware detection and endpoint detection and response tools had no signatures to detect.

The attackers claimed to have stolen 50 terabytes of data before executing the wipe. They framed the attack explicitly as reprisal for a February 28 strike on a girls' elementary school in Minab, Iran, which a Pentagon investigation attributed to the United States. Unlike ransomware operators, Handala did not demand payment; their goal was pure destruction.

The Stryker attack exposed a critical vulnerability in how enterprises manage their device fleets. Unified Endpoint Management platforms like Microsoft Intune provide a single point of failure: one compromised privileged credential can provide simultaneous, authenticated, trusted command over every enrolled device globally. CISA, the FBI, and Microsoft all issued formal guidance in response, with the most critical recommendation being Multi-Admin Approval for high-impact actions such as remote wipe.

For more details about this attack, click here

6. The Norwegian Dam Attack: Opening Floodgates Through Digital Sabotage

In April 2025, pro-Russian hackers achieved a chilling feat: they seized control of a dam in Bremanger, western Norway, and opened its floodgates. The attackers compromised a digital system that remotely controlled one of the dam's valves and set the outflow valves to open position. For four hours, approximately 500 liters of water per second were released before the breach was detected and contained.

Norway's domestic intelligence service, PST, concluded that pro-Russian hackers were responsible. The attack marked the first time Oslo officially attributed a cyber incident to Russia. PST Director Beate Gangås warned that cyber attacks are increasingly being carried out against European countries to stoke fear and unrest.

While no physical damage occurred, the incident demonstrated that hackers could manipulate physical infrastructure in ways that could cause real-world harm, including flooding, property damage, and potentially loss of life.

For more details about this attack, click here

7. The Attack on European Electricity and Water Networks: A Series of Russian-Linked Incursions

Beyond the individual incidents in Poland, Sweden, and Norway, a broader pattern of Russian-linked cyberattacks has emerged across Europe's electricity and water infrastructure. Polish intelligence reported that hackers breached water treatment facilities in five Polish towns during 2025, gaining access to industrial control systems. A Russian group also hacked a water treatment plant in Quebec, Canada, gaining access to control pumps and chlorine dosing systems.

European officials have expressed growing concern over the vulnerability of power plants and water treatment facilities. In December 2024, the Russian hacktivist group Z-Pentest conducted a cyberattack against a Danish water utility. Pro-Russian hacktivists have attacked municipal water and sewage systems in Poland, with a half-dozen previous attacks generally blamed on such groups, providing Moscow a thin veneer of deniability.

The European Union responded in July 2026 by sanctioning nine individuals and four entities linked to Russian cyberattacks against critical infrastructure. Among those sanctioned were members of the Cyber Army of Russia Reborn (CARR), a hacktivist group that has conducted numerous operations against Western infrastructure.

For more details about this attack, click here

8. The Attack on Ukraine's Power Grid: The Ongoing Digital War

Russia's cyberwar against Ukraine's energy infrastructure has continued unabated throughout 2025. According to official figures, Russian attacks on Ukraine's energy infrastructure reached 1,225 in 2025, eclipsing the cumulative total of the war's first three years, while damage to the grid surpassed $20 billion.

In the digital domain, Russian-linked groups such as Sandworm launched coordinated cyberattacks targeting Danish energy companies. Ukrainian officials warned that Russia was combining missile strikes with coordinated cyberattacks against the energy grid as winter approached. The Security Service of Ukraine also uncovered an FSB mole within a Ukrainian energy company who had been guiding Russian drone strikes against critical infrastructure.

For more details about this attack, click here

9. The Threat to the UK Electricity Grid

While the United Kingdom has not yet experienced a major destructive cyberattack on its electricity grid, warnings have intensified throughout 2026. In May 2026, GCHQ's director warned that Russia is actively targeting Britain's subsea energy cables and pipelines as part of a widening hybrid campaign. Cybersecurity experts have warned that Iran could turn the lights out in Britain by targeting critical national infrastructure.

The UK government published its first cross-sector energy cyber security strategy, acknowledging that cyber risk remains the leading concern for utilities, driven by higher attack volumes and geopolitical tensions. The 2026 UK Cyber Leaders Challenge centered around a fictional scenario of malicious activity within the UK's electricity grid, a scenario that now seems less like fiction and more like a question of when, not if.

For more details about this threat, click here

10. The ZionSiphon Malware: Targeting Israeli Water Infrastructure

In the aftermath of the Twelve-Day War between Iran and Israel in June 2025, cybersecurity researchers detected a new operational technology malware called ZionSiphon, specifically designed to target Israeli water treatment and desalination systems. First detected on VirusTotal on June 29, 2025, the malware appeared purpose-built for ICS sabotage.

Iranian threat groups, including APT35 (Charming Kitten), MuddyWater, and CyberAv3ngers, have launched campaigns against Israeli critical infrastructure, including water utilities, healthcare facilities, and industrial control systems. As one analysis noted, Iran is currently more likely than ever to retaliate through cyberattacks due to its significantly reduced ability to respond through conventional military means. The ZionSiphon malware represents a dangerous evolution: adversaries are now developing specialized tools to target specific types of industrial infrastructure.

For more details about this malware, click here

Analysis and Implications

The ten attacks examined in this essay share several common characteristics that together paint a troubling picture of the current threat landscape.

First, the attackers are nation-states or their proxies. Russia and Iran dominate the attribution landscape, with both countries employing cyber operations as instruments of state policy. Russia's attacks on European energy infrastructure appear designed to punish countries supporting Ukraine, while Iran's operations seem motivated by retaliation and deterrence. In both cases, the attackers operate with the resources, patience, and strategic direction of state intelligence services.

Second, the targets are increasingly diverse. From electricity grids and dams to transit systems, firewalls, and medical device manufacturers, no sector is immune. The attacks demonstrate a comprehensive understanding of how modern infrastructure operates and how it can be disrupted.

Third, the methods are evolving rapidly. The Stryker attack represents a watershed moment: the weaponization of legitimate management tools against their owners. No malware, no zero-day exploits, no complex reverse engineering, just compromised credentials and a few clicks in an administrative console. This living off trusted services approach makes detection extraordinarily difficult and defense exceptionally challenging.

Fourth, the consequences are escalating. While many attacks have been contained or failed to achieve their full destructive potential, the trajectory is clear. Attackers are learning, adapting, and growing bolder. The Polish attack appeared rushed and opportunistic, but it demonstrated the ability to systematically compromise OT systems across multiple sites. The Norwegian dam attack proved that hackers can manipulate physical infrastructure. The Stryker attack showed that a single compromised credential can destroy tens of thousands of devices in hours.

Fifth, defense remains woefully inadequate. The FortiBleed campaign compromised half of all internet-facing Fortinet firewalls globally. The Stryker attack succeeded because Multi-Admin Approval was not enabled. Too many critical infrastructure operators continue to expose management interfaces to the internet, fail to enforce multi-factor authentication, and neglect basic security hygiene.

Conclusion

The attacks examined in this essay are not isolated incidents; they are part of a broader, sustained campaign of cyber aggression against the infrastructure that underpins modern life. The Polish grid attack, the Swedish power plant intrusion, the LA Metro breach, the FortiBleed campaign, the Stryker wiper attack, the Norwegian dam sabotage, and the series of attacks on European water and electricity networks collectively demonstrate that critical infrastructure is under siege.

The response must be equally comprehensive. Governments must strengthen cybersecurity regulations, impose meaningful consequences on attackers, and invest in resilience. Private sector organizations must treat cybersecurity as an existential priority, not a compliance exercise. The lessons of the Stryker attack, that legitimate management tools can be weaponized, that a single compromised credential can cause catastrophic damage, must be heeded across every sector.

As Swedish Minister Bohlin warned, groups that once carried out denial-of-service attacks are now attempting destructive cyberattacks against organizations in Europe. The warning applies globally. The lights may not have gone out, yet. But the attackers are learning, adapting, and preparing for the next assault. The question is not whether another major attack will occur, but when, and whether we will be ready.

Post a Comment

0Comments

Post a Comment (0)