Sandworm Used Private APN to Reach Polish Energy ICS

CERT.PL said Sandworm carried out a second destructive December 2025 intrusion against Polish energy industrial control systems, this time hitting a smaller combined heat and power plant supplying heat to 50,000 residents. The attack disrupted a steam turbine and water treatment system, but heat and electricity stayed on. The chain started on an internet-facing Fortinet VPN/firewall at a wind farm, moved to a Teltonika cellular router, and used SSH to tunnel into a private access point network run by the distribution system operator. That carrier-managed path connected into SCADA-linked substation equipment, letting the attackers reach a Wago programmable logic controller and then the plant’s OT network; CERT.PL says this is the first reported use of a private APN as the pivot. For operators that use private APNs or cellular routers to tie field gear into control networks, the lesson is that a telecom-managed link can still become an internal path into OT. If that bridge is present, an edge-device compromise can reach SCADA-side assets even when the public internet never touches them.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Sandworm Used Private APN to Reach Polish Energy ICS

Sources