On 24 September 2026 the Danish Defence Intelligence Service (DDIS) stated that Russia has intensified its use of sabotage and destructive cyberattacks. It assessed that Russia will escalate its hybrid war further in the coming months, with more frequent attacks against the West and NATO and greater consequences for the countries affected than before. DDIS gives two examples of what this could include: destructive cyberattacks with serious consequences for critical societal functions, and sabotage attacks with a high risk of injuries [1]. The assessment covers the West and NATO as a whole, and Russian destructive attacks have affected organisations in Poland [2], Denmark [3], elsewhere in Europe [4] and the United States [5][6].
The same day, the Danish Resilience Agency (SAMSIK), which has included Denmark's Centre for Cyber Security since January 2025 [7], raised its threat level for destructive cyberattacks against Denmark from medium to high. SAMSIK assesses it as likely, meaning 60 to 90 per cent on its scale, that Russia will attempt such attacks. It says the threat mainly concerns wipers, which delete or overwrite data so that it cannot be recovered from the affected systems, and cyberattacks that manipulate operational technology (OT) [8][9].
We recommend planning for an attack that destroys data as well as one that encrypts it for ransom. There is no decryption key to pay for when a wiper destroys data, so recovery depends on backups and on how quickly the organisation stops the destruction.
Russian military intelligence (GRU) has used destructive malware since at least 2015 [5], and it has disguised some of these attacks as ransomware or other criminal activity [4][10]. The UK government attributes NotPetya (June 2017) to the Russian military and says it "masqueraded as a criminal enterprise but its purpose was principally to disrupt". NotPetya was aimed at Ukraine and spread to organisations across Europe, costing them hundreds of millions of pounds [4]. In 2020 the US Department of Justice charged six officers of GRU Unit 74455 over NotPetya and other attacks. It put the losses of the three victims identified in the indictment, among them a Pennsylvania hospital system, at nearly $1 billion [5]. WhisperGate, which GRU Unit 29155 deployed against Ukrainian government systems in January 2022, looked like ransomware and was designed to destroy the target computer and its data. The Unit 29155 officers charged over it later targeted systems in the United States and 25 other NATO countries that were supporting Ukraine [10]. The UK also attributes the attack on the Viasat satellite network to Russia. The attack took place an hour before the invasion on 24 February 2022 and affected wind farms in central Europe [11].
Attackers hit Poland's energy sector on 29 December 2025. At more than 30 wind and solar farms, a large combined heat and power plant and a manufacturing company, they damaged controller firmware, deleted system files or launched custom wiper malware. EDR software blocked the wiper at the heat and power plant, electricity production continued and the heat supply was not disrupted [2]. The UK, together with EU member states, attributed the attack on Poland's energy grid to Russia's FSB Centre 16 on 13 July 2026. The UK government said it could have left 500,000 people without electricity [12][13]. CERT Polska's follow-up report of 8 August 2026 describes a parallel attack on a smaller combined heat and power plant that supplies heat to about 50,000 residents. The attackers entered through a wind farm VPN that accepted logins without multi-factor authentication, then moved through a private mobile network and a controller that still had its default password. They scanned the private mobile network from 18 December, and on the morning of 29 December they switched the plant's controllers to stop mode and locked them with a password, which shut down a steam turbine and the process water treatment system. The operators kept it to a short outage, and heat and electricity supplies to customers continued [14].
The UK National Crime Agency reported in 2024 that Evil Corp, the group behind the BitPaymer and WastedLocker ransomware, was tasked before 2019 "by Russian Intelligence Services to conduct cyber-attacks and espionage operations against NATO allies" [15]. The Canadian Centre for Cyber Security assesses that ransomware is the top cybercrime threat to Canada's critical infrastructure, and that the top ransomware groups affecting Canada very likely have their core membership in countries of the former Soviet Union. It also assesses that Russia's cyber activity is supported by a network that includes Russia-nexus cybercriminals and hacktivists [16]. The UK said on 13 July 2026 that the cyber division of GRU Unit 29155 had worked with cybercriminals to recruit hackers from Russian universities [12]. The same day the EU adopted its largest cyber sanctions package to date, which targets "the network of cybercriminals, hacktivists and private companies operating under Russia's instruction, direction or control" [17].
DDIS assesses that Russia was behind a destructive attack on a Danish water utility in 2024, carried out by the pro-Russian group Z-Pentest. It also assesses that the Russian state uses Z-Pentest and the DDoS group NoName057(16) "as instruments of its hybrid war against the West" [3]. SAMSIK reports that the attackers compromised the utility's OT system and manipulated the water pressure, leaving 450 households without water for a period [9]. The US Department of Justice says the same group, which it calls CARR or Z-Pentest, was founded, funded and directed by the GRU, and that its victims included public drinking water systems in several US states [6].
The UK National Cyber Security Centre (NCSC) announced a joint advisory on FSB Centre 16 on 13 July 2026, co-sealed by agencies from the United States, Canada, Denmark and nine other countries. The NCSC listed communications, defence, energy, financial services, government and healthcare among the sectors most at risk from this targeting [13]. According to DDIS, Russia has begun to target support for Ukraine more directly, for example by sabotaging defence companies or the railways that carry military equipment to Ukraine [1]. SAMSIK's higher threat level applies across Danish society. SAMSIK assesses that the threat is likely to apply in particular to organisations that run critical functions in critical infrastructure and depend in part on OT systems, for example in the energy, water and transport sectors. It notes that Russian state groups conduct cyber espionage against Danish critical infrastructure on an ongoing basis, and that such espionage is often a precondition for targeted destructive attacks. Pro-Russian groups go after systems protected so poorly that they are easy to find and enter [8]. Organisations outside these sectors can suffer collateral damage, as NotPetya's victims outside Ukraine did [4][5].
Ransomware encrypts and renames an organisation's files, and a wiper deletes, empties, overwrites or corrupts them. BullWall monitors file activity on local and cloud-based file shares, including backup files stored on shares. It detects both kinds of attack as they happen, from signals such as mass deletion, bulk overwriting, corrupted files, ransom notes, mass renaming and changes to decoy files. Because the detection runs on the storage itself, it does not depend on an agent on the attacking device, and it keeps working when an attacker has disabled endpoint protection or writes from an unmanaged device. When BullWall detects an attack of either kind, it automatically contains the responsible user account and device within seconds. The loss is limited to the files changed before containment, and BullWall lists those files so they can be restored from backup. On servers, BullWall's Server Intrusion Protection adds multi-factor authentication to RDP logons.
If you have questions about this advisory or would like help reviewing your preparations, contact us at info@bullwall.com.