
Hackers Breached Polish Energy Plant Through Private APN
Hackers used a private mobile Access Point Name (APN) to enter the operational technology network of a small combined heat-and-power (CHP) plant in Poland. The facility supplies heat to around 50,000 residents, and the intrusion shut down its steam turbine and process-water treatment system. CERT Polska disclosed the incident in a follow-up report on destructive attacks against Poland’s energy sector on December 29, 2025. Those attacks targeted 30 wind and solar installations and a large CHP plant. The attacker, believed to be linked to the Russian Electrum threat group, destroyed key equipment, disabled communications hardware, corrupted operational technology devices, and wiped Windows systems. Energy generation and distribution were not disrupted. At the smaller CHP plant, the attacker switched programmable logic controllers (PLCs) into STOP mode and enabled password protection. This deactivated the turbine and water treatment system and interrupted cogeneration. Plant staff restored the affected systems quickly, making the outage brief and preventing any impact on the population. CERT Polska found that the attacker had initially compromised a FortiGate VPN and firewall at a wind farm. A Teltonika cellular router on that network was then used to tunnel into a private APN managed by the distribution system operator. Because the APN lacked client isolation, the attacker could scan for and communicate with devices at other facilities. Beginning on December 18, the attacker found a WAGO PFC200 PLC at the smaller CHP plant. Its web interface was exposed on the APN and protected with default administrator credentials. After compromising the controller, the attacker enabled SSH and used the device as a bridge into the plant’s OT network. Over the following week, the attacker scanned for SCADA systems and industrial equipment. On December 25, connections were made to three Siemens PLCs, likely in preparation for the attack. At approximately 5:30 a.m. on December 29, the attacker accessed the SCADA interface and Siemens PLCs, placed the controllers in STOP mode, enabled password protection, and shut down the turbine and water treatment system. Several Moxa devices were also reset and reconfigured to impede recovery. Logs were destroyed, while the WAGO controller, Teltonika router, and FortiGate firewall were corrupted or reset to hinder forensic analysis. CERT Polska believes this was the first known real-world cyberattack in which an attacker entered an OT network by moving laterally through a private APN. Surveys after the investigation found that this configuration was common in Poland at the time, and the agency estimates that similar arrangements are probably used internationally. The agency recommends treating private APNs as untrusted external networks, isolating connected clients, and using allowlists for essential traffic between APN gateways and OT systems. Exposed SSH and Telnet administration services should also be disabled. The incident gives operators of remotely connected infrastructure a concrete warning: a network being private does not make it inherently secure, and one poorly protected device can provide a route into critical operational systems.
Read our sourcing and corrections policy



Be the first to comment on this story!