OT / ICS · 47 giorni fa
La separazione tra siti saltava nel punto che si dava per affidabile: un firewall di campo compromesso e un private APN hanno permesso di entrare in un impianto CHP passando da un altro asset energetico. Il risultato non è stato solo la compromissione di due apparati, ma un accesso alla rete OT attraverso un confine cellulare pensato per tenerla isolata.
CERT.PL aggiunge il percorso concreto del pivot: da un FortiGate compromesso in un wind farm, gli attaccanti hanno usato un router Teltonika per raggiungere un private APN gestito dal distributore, poi hanno trovato un controller WAGO esposto via web con credenziali admin di default. Da lì hanno aperto un ponte verso l’OT dell’impianto, fino a spegnere una steam turbine e il sistema di water treatment che produceva process water.
Per chi usa private APN o connettività cellulare condivisa tra siti, il punto non è il singolo dispositivo bucato ma la fiducia di rete che li collega. Questa vicenda è il primo caso documentato di accesso a una rete OT attraverso un private APN, e sposta il problema dal perimetro locale al disegno stesso dell’isolamento tra impianti.
6 fonti che coprono questa storia
Russian-Linked Hackers Accessed Polish Power Plant OT Through APN
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers pivoted through a private cellular APN to shut a turbine and water treatment system at a Polish CHP plant serving 50,000 residents.
Previously unseen entry vector used to breach Polish energy plant - Help Net Security
CERT Polska traced a Poland energy sector cyberattack from a wind farm into a CHP plant via a private APN, a first observed attack path.
The Record from Recorded Future
Poland uncovers second heat plant cyberattack that went hidden for months
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
Follow-Up Report of the December 2025 Energy Sector Incident
We are publishing a report detailing an investigation that lasted more than three months and led to the discovery of a previously unobserved attack vector involving a private APN.
Part of the PlainSec briefing for 2026-08-13