Robin’s Newsletter #398

1 February 2026. Volume 9, Issue 5
More on Polish power grid attack. ShinyHunters target 100 orgs in latest vishing campaign. CISA director's ChatGPT slip.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 1st February 2026

  • Default creds used in Polish power grid attack
  • CISA chief accidentally uploaded sensitive docs to ChatGPT
  • 100 Orgs targeted in latest ShinyHunters campaign
  • Calls for UK offensive cyber investment
  • MoltBot security considerations abound

Interesting stats

31.4 Tbps record DDoS attack, according to Cloudflare, from the Aisuru/Kimwolf botnet

(<)1/1,000 conversations with Claude.ai had potential for “severe forms of disempowerment” of the human user, according to analysis of harm by Anthropic (paper (PDF)) … 0.1% strikes me as a pretty high rate for human harm at the hands of AI.

Five things

  1. Poland power grid: Poland’s Computer Emergency Response Team has published a technical report (PDF) from its investigation into an attack against the country’s grid at the end of 2025, attributed to Russia’s Sandworm government hackers. The remarkably speedy investigation may be a product of the ease with which Russia’s Sandworm group gained access: default usernames, passwords, and no multi-factor authentication. The attackers also deployed wiper malware — a common Russian tactic — in an attempt to disable and destroy the ability to manage and operate the infrastructure. A combined heat-and-power plant, along with wind and solar farms, was targeted. Defenders prevented the wiper attack at the CHP plant, but it was successful against the renewable generation sites. At least 12 affected sites have been confirmed, though OT cyber outfit Dragos says the number is approximately 30. The disruption, amounting to 1.2GW, or 5% of Poland’s energy supply, didn’t disrupt the overall grid.

  2. CISA: The acting director of CISA, Madhu Gottumukkala, triggered alarms at his agency when he accidentally uploaded sensitive files to the public version of ChatGPT. While none of the documents were classified, they were marked “for official use,” and access to ChatGPT itself was restricted: Gottumukkala had requested special access for himself upon arrival at the agency. The public version of ChatGPT may use user input to train the model. Other conflicts mark his time at the helm of America’s cyber agency, leaving many feeling he doesn’t have widespread support from the organisation, which is struggling following significant layoffs in the last 12 months.

  3. ShinyHunters has targeted ~100 organisations in its latest campaign. The cybercriminal group, known for its social engineering, set its sights on Okta single sign-on accounts at “high-value enterprises”. Some of these may have resulted in incidents (see below). The campaign appears to use a new vishing (voice phishing) kit, in which attackers guide the victim to a web page they control and can manipulate to display, for example, the correct form of multi-factor authentication the user expects. Phishing-resistant forms of MFA — think FIDO2 YubiKeys or passkeys — are the solution to this problem, rather than one-time codes.

  4. Offence is the best defence? Former national security advisor and member of the Joint Committee on the National Security Strategy, Lord Sedwill, warned a parliamentary hearing that the UK needs offensive capability to act as a deterrence in cyber and hybrid conflicts. Sedwill says, “There needs to be essentially an offensive element to deterrence, as well as simply a defensive element”. The argument is that many cyber intrusions or attacks (for example, see Poland’s power grid above) do not elicit the same response as a physical or kinetic attack would, and that adversaries are exploiting this to inflict “strategically consequential effects,” according to NATO allies. Europe’s cyber agency, ENISA, describes a “loophole” created by not investing in cyber security, while telling Politico, “We just don’t need an upgrade. We need a rethink,” he said. “Doubling the capacity is the absolute minimum.”

  5. MoltBot (neé ClawdBot): An open source, locally hosted “AI personal assistant” has exploded in popularity in 2026. Originally known as ClawdBot, MoltBot allows users to hook up a personal AI to their preferred messaging channel, like WhatsApp, Discord, or Teams, and have it carry out actions on their devices, like replying to emails, managing calendars, and other ‘skills’ that you can plug into the system. Beyond concerns about handing over credentials for all your accounts, there are specific threats to be aware of. Firstly, as with most AI automation, is the prospect of prompt injection due to the shared control/content channel, from emails, invites, or other inputs, or straight up poor configurations or missing authentication. Another is not unique to AI, but the unforeseen or unexpected threat vectors from fast-moving, growing technology projects. This week saw researchers demo a proof-of-concept exploiting the supply chain of a popular ‘skill’ on a package management platform. Typosquatting skills wouldn’t surprise me either, something still affecting many more mature ecosystems, let alone ones facing such meteoric rises. Mature security functions are rarely baked into projects in less than a month.

In brief

And finally

  • Scam compounds: The remarkable story of day-to-day life for enslaved works in a Southeast Asian scam compound. These financial losses and the human cost of these organised criminal enterprises are massive. The conditions, team structures, call scripts, use of AI, and more come from a trove of information, totalling 4,200 pages, supplied to WIRED by a whistleblower. The conditions, team structures, call scripts, use of AI, and more come from a trove of information, totalling 4,200 pages, supplied to WIRED by a whistleblower. It’s well worth your time.
Robin

  Robin's Newsletter - Volume 9

  Poland Russia Grid Operational technology Electricity Cybersecurity and Infrastructure Agency (CISA) ChatGPT Data loss Default credentials ShinyHunters Vishing (voice phishing) Offensive cyber" MoltBot Scam compounds