Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack
Critical Infrastructure Security Attacks DDoS Latest News News & Analysis Security

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

Kirsten DoyleBy Kirsten DoyleApril 20, 20266 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Swedish heat and power plant in failed cyberattack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In 2025, pro-Russian threat actors attempted to disrupt a Combined Heat and Power (CHP) facility in western Sweden. A failed attack on dual-purpose critical infrastructure serving both electricity generation and district heating networks. 

The Minister for Civil Defence of Sweden, Carl-Oskar Bohlin, revealed in a news conference that the cyber-attack had been conducted in the spring of 2025 and the perpetrators were acting on behalf of Russian intelligence services. 

An activist group loyal to Russia attempted an attack against a company in Sweden, but the attack failed, Bohlin added, pointing out that the security functions embedded within the system thwarted the threat. 

Swedish security agencies investigated the matter, and there were no disruptions in its operations. 

Despite this, officials noted that a larger issue underlies the trend in which these tactics are being used. Russian activists have started moving away from the traditional DDoS attack tactics towards OT systems, he explained. 

Typically, the attacks target operational systems. If these systems were hacked or remotely compromised, the consequences would be disastrous. 

Not the first incident in the EU  

Similar incidents have been reported across Europe, including in Poland (where attacks have been more extensive) as well as in Norway and Denmark. Bohlin described the trend as evidence of more “risk-prone and careless” behaviour by Russia, with the potential to cause significant societal harm. 

According to John Billow, head of the Swedish National Cyber Security Centre, the agency has been ramping up efforts in helping businesses manage critical infrastructure. This encompasses greater visibility into potential threats, increased collaboration across industries, and pre-incident and incident response support. 

Billow further cautioned that there is a “security debt” in Sweden regarding cybersecurity preparedness. 

This means that although some well-defended sectors show great resilience, we have to raise the baseline for all. Investment is needed, but the price of failing is much steeper, Billow added. 

A chilling shift in the EU threat landscape 

Damon Small, Board of Directors, at Xcape Inc, commented: “Sweden’s attribution of the failed 2025 thermal plant attack to Russian-linked actors signals a chilling shift in the European threat landscape. It is the graduation from digital harassment to attempted kinetic destruction. By targeting Industrial Control Systems (ICS) rather than mere public-facing websites, these actors are signalling an intent to cause physical suffering. In this case, the adversary is doing so by attempting to disable heating during freezing temperatures. 

Small said the real danger, as seen in the parallel 2025 Polish power plant attacks, is not just a temporary service outage, but the deployment of destructive wiper malware like DynoWiper to permanently “brick” field devices such as Remote Terminal Units and Programmable Logic Controllers. 

“For infrastructure operators, this move from cyber vandalism to disrupting Operational Technology (OT) means the era of treating Information Technology (IT) and OT as separate security domains is over. Attacks against critical infrastructure must be expected as a primary instrument of modern geopolitical conflict. Where missiles cannot reach, packets sent across the Internet can.” 

He added that the fact that this attack was successfully defended is a testament to Sweden’s “built-in protection mechanisms,” but it also serves as a final warning that national defence now begins at the firewall. Security teams must prioritize the immediate hardening of the IT/OT boundary. 
 

“If your thermal plant’s security is still relying on “security through obscurity,” you’re not a defender; you’re a volunteer for a Russian stress test.” 

No incentive to overshare  

Steven Swift, Managing Director, at Suzu Labs added that there’s not much detail provided in the public statement from Sweden. “That’s normal for this sort of thing, they don’t have an incentive to over share. In fact, the only meaningful thing they really shared was that one, an attack was attempted and two, they were prepared for it, resulting in no impact. That’s mostly just PR on their part.” 

Swift said: “Critical infrastructure has long been a high value target. Both for cyber as well as traditional attacks. Cyber is interesting here, in that these attacks can be launched with less fanfare, at higher frequency, against a larger number of targets.” 

He added that while it’s obviously a win for Sweden that this attack failed, it should be noted that most attacks fail. “Attackers don’t care that much about the success of individual campaigns. They solve this with scaling. Both by targeting a large number of targets, and by running a variety of independent campaigns. 

 “Defenders have to get it right 100% of the time, or they experience a breach. Attackers are the opposite, they only need 1 success, it doesn’t matter much how many failures it takes to get there.” 

It’s down to the states, municipalities, utilities to figure this out 

Josh Marpet, Senior Product Security Consultant at Finite State, said: “Cyberattacks against utilities are common and increasing in number and sophistication. That curve doesn’t appear to be flattening, suggesting that a stronger response is indicated. Since most utilities are municipal and revenue-constrained, it’s difficult for them to up their defences quickly. Larger utility companies can, but there are many municipal water and power transmission organizations that would have to do a bond issue in order to fund any such expenditures.” 
 
He added that effectively, power generation, power transmission, water, internet, and other such utilities are finding themselves increasingly targeted by attackers growing in sophistication and motivation. “Unless they outsource their defences, it seems almost inevitable that they will have incidents and be breached. Whether it’s customer data or mass disruption, none of the outcomes are desirable. 
 
“Unless and until the federal government provides some help, it’s down to the states, municipalities, and utilities themselves to figure out this issue. 
 
Marpet said raising prices is perpetually unpopular. “So, outsourcing for maximum efficiency, and working as community members in the various ISAC’s and associations, is the way to go. With the sheer volume of IoT and OT equipment in the utilities, they need to pick the right outsourced help and get it soon.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Eurail User Records Up for Sale on the Dark Web

February 18, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}