Private APNs Hid a Second Heat Plant Intrusion

Poland’s CERT has uncovered a previously unknown cyberattack on a combined heat and power plant that unfolded during last winter’s cold snap and went unnoticed for months. The plant’s operators first treated the shutdown of a steam turbine and water treatment system as a contractor problem; only a later investigation tied it to the same FSB-attributed campaign that hit other Polish energy sites on that day. The intrusion crossed from a private cellular data network into industrial control systems, which matters because those links are usually treated as walled-off infrastructure. In this case, the carrier-style connection itself was the trust boundary that failed, not an internet-facing service. For operators using private APN or cellular links for OT telemetry or remote control, the exposed surface includes the network fabric between sites, not just the plant endpoints. Unexplained outages that look operational can still belong to a cyber campaign, and they may sit outside the normal incident queue until someone correlates them.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Private APNs Hid a Second Heat Plant Intrusion

Sources