Sandworm Used Private APN to Reach CHP Controls

CERT.PL says a December 29 attack on a Polish combined heat and power plant shut down a steam turbine and water-treatment system after Sandworm reached the plant through a private Access Point Name (APN), the first documented OT compromise through that cellular trust path. The three-month post-mortem ties the pivot to a compromised FortiGate at a wind farm and a Teltonika cellular router on the same network. The attackers used the router to tunnel into the private APN, scanned it repeatedly, and found a WAGO PFC200 controller at the CHP site whose web interface was reachable and protected only by default admin credentials. After taking that controller, they used Secure Shell (SSH) to enter the plant’s OT network and then reached Siemens PLCs, which were switched to STOP mode, halting the cogeneration process. They also destroyed logs and reset devices to slow recovery. For operators that use private APNs or shared cellular backhaul between renewable sites and central plants, the trust boundary is the story: a compromise at one field location can become access to a separate OT network if the APN and exposed controllers are not truly isolated. In this case, the blast radius ran from the initial wind-farm foothold into CHP controls serving 50,000 residents.

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: Sandworm Used Private APN to Reach CHP Controls

Sources