CERT-In A.I CyberSecurity Scoring
CERT-In
Company Information
Website:http://www.cert-in.org.in
Employees number:126
Number of followers:14,109
NAICS:541514
Industry Type:Computer and Network Security
Homepage:cert-in.org.in
CERT-In Risk Score (AI oriented)
Between 750 and 799
CERT-InComputer and Network Security
Updated:
09/03/2026
09/03/2026
750/1000
Fair
Baa
CERT-In Global Score (TPRM)
xxxx
CERT-InComputer and Network Security
Score locked

CERT-InFair
Current Score
750Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751
MAY 2026
751
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
751
Vulnerability
29 Dec 2025 • CERT-In
Fortinet, Moxa and CERT Polska: Poland’s energy control systems were breached through exposed VPN access
Coordinated Cyberattacks Target Poland’s Critical Infrastructure in December 2025
750
CRITICAL-1
FORCERMOX1770408103
Coordinated Cyberattacks Target Poland’s Critical Infrastructure in December 2025
On 29 December 2025, a series of destructive cyberattacks struck Poland’s energy and industrial sectors, orchestrated by a Russia-linked threat actor tracked as Static Tundra (also known as Berserk Bear, Ghost Blizzard, and Dragonfly). Poland’s CERT Polska confirmed the attacks targeted renewable energy facilities, a heat and power (CHP) plant, and a private manufacturing company, though no disruptions to energy generation or distribution occurred.
### Initial Access & Tactics
The attackers exploited internet-exposed FortiGate VPN devices used as perimeter firewalls and VPN concentrators without multi-factor authentication (MFA). In all cases, compromised credentials allowed initial access, with attackers leveraging stolen configurations in some instances.
### Renewable Energy Sector Disruptions
At least 30 wind and solar farms were hit, with attackers focusing on substation control systems interfacing with distribution operators. Compromised equipment included:
- RTU controllers, protection relays, and HMI computers
- Hitachi Energy, Mikronika, and Moxa devices in industrial automation environments
Destructive actions corrupted firmware, file deletions, and factory resets led to lost communication between facilities and operators, though power generation continued uninterrupted.
### Heat & Power Plant Sabotage Attempt
A CHP plant supplying heat to nearly half a million customers was targeted in a prolonged intrusion dating back months. Attackers conducted:
- Internal reconnaissance and credential theft (including Active Directory admin access)
- Lateral movement across servers and workstations
- Deployment of DynoWiper malware via Group Policy Objects (GPOs)
An EDR platform blocked the wiper’s execution, limiting damage. Evidence suggests preparations began earlier in 2025, indicating a long-term operation.
### Manufacturing Company Attack
A private manufacturing firm was also targeted opportunistically. Attackers:
- Gained access via a Fortinet device with a publicly leaked configuration
- Modified settings to maintain persistence despite credential changes
- Deployed LazyWiper, a PowerShell-based wiper distributed via GPOs, designed to destroy business-critical data
CERT Polska noted the wiper’s file-overwriting function may have been generated by an LLM.
### Impact & Attribution
While the attacks disrupted monitoring and control systems, they failed to halt energy production. All incidents were linked to the same threat actor, with tactics aligning with known Russian cyberespionage and sabotage operations. The use of wiper malware, stolen credentials, and prolonged reconnaissance underscores the highly targeted and destructive nature of the campaign.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
751
OCTOBER 2025
751
SEPTEMBER 2025
751
AUGUST 2025
751
JULY 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CERT-In ??
What was CERT-In's A.I Rankiteo Cyber Score in May 2026 ??
What was CERT-In's A.I Rankiteo Cyber Score in April 2026 ??
What was CERT-In's A.I Rankiteo Cyber Score in March 2026 ??
What was CERT-In's A.I Rankiteo Cyber Score in February 2026 ??
What was CERT-In's A.I Rankiteo Cyber Score in January 2026 ??
What was CERT-In's A.I Rankiteo Cyber Score in December 2025 ??
What was CERT-In's A.I Rankiteo Cyber Score in November 2025 ??
What was CERT-In's A.I Rankiteo Cyber Score in October 2025 ??
What was CERT-In's A.I Rankiteo Cyber Score in September 2025 ??
What was CERT-In's A.I Rankiteo Cyber Score in August 2025 ??
What was CERT-In's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on CERT-In's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CERT-In ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CERT-In's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?