OT / ICS · 47 days ago
CERT.PL says a December 29 attack on a Polish combined heat and power plant shut down a steam turbine and water-treatment system after Sandworm reached the plant through a private Access Point Name (APN), the first documented OT compromise through that cellular trust path. The three-month post-mortem ties the pivot to a compromised FortiGate at a wind farm and a Teltonika cellular router on the same network.
The attackers used the router to tunnel into the private APN, scanned it repeatedly, and found a WAGO PFC200 controller at the CHP site whose web interface was reachable and protected only by default admin credentials. After taking that controller, they used Secure Shell (SSH) to enter the plant’s OT network and then reached Siemens PLCs, which were switched to STOP mode, halting the cogeneration process. They also destroyed logs and reset devices to slow recovery.
For operators that use private APNs or shared cellular backhaul between renewable sites and central plants, the trust boundary is the story: a compromise at one field location can become access to a separate OT network if the APN and exposed controllers are not truly isolated. In this case, the blast radius ran from the initial wind-farm foothold into CHP controls serving 50,000 residents.
6 sources covering this story
Russian-Linked Hackers Accessed Polish Power Plant OT Through APN
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers pivoted through a private cellular APN to shut a turbine and water treatment system at a Polish CHP plant serving 50,000 residents.
Previously unseen entry vector used to breach Polish energy plant - Help Net Security
CERT Polska traced a Poland energy sector cyberattack from a wind farm into a CHP plant via a private APN, a first observed attack path.
The Record from Recorded Future
Poland uncovers second heat plant cyberattack that went hidden for months
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
Follow-Up Report of the December 2025 Energy Sector Incident
We are publishing a report detailing an investigation that lasted more than three months and led to the discovery of a previously unobserved attack vector involving a private APN.
Part of the PlainSec briefing for 2026-08-13