Threats

Poland Energy Facility Hack

August 11, 2026 04:18 · 10 min read
Poland Energy Facility Hack

Poland Energy Facility Sabotaged by Hackers

Poland's computer emergency response team (CERT) has published a report detailing a second attack on the country's power grid. The attackers targeted industrial control systems (ICS) and their objective was 'purely destructive'.

In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities.

Attack Vector: Private APN Pivot

The Polish CERT's report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world.

The cyberattack caused the shutdown of a steam turbine and a water treatment system, which resulted in a disruption of the cogeneration process. However, the systems were quickly restored, and heat and electricity supply were not interrupted.

Attack Timeline

The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption, but the CERT soon determined that it was the result of hacker activity.

The intrusion started on a Fortinet VPN and firewall device located at a wind farm and connected to the internet. The hackers then identified a Teltonika cellular router on the same network and accessed its admin interface.

An SSH service running on the device was then used to establish a tunnel that enabled communication to a private APN network managed by the distribution system operator (DSO). These private APN networks enable communication between the DSO's SCADA system and ICS installed at the substation.

Targeted Devices

The attacker scanned the private APN network and identified a Wago programmable logic controller (PLC) running at a CHP plant. An SSH service enabled on this controller gave the attacker access to the plant's operational technology (OT) networks.

After conducting reconnaissance over the course of one week, the threat actor connected to Siemens PLCs, switched them to 'stop' mode, and set a password to prevent operators from changing the controllers' operating state and control logic.

Moxa serial device servers and Moxa network switches were also targeted by the attackers and configured to prevent the legitimate operators from accessing them. ABB and Schneider Electric variable frequency drives were also targeted by the attackers, but it's unclear what actions they carried out on these devices, and some attempts to connect to them were unsuccessful.

Damage and Recovery

Similar to the attack on the first energy facility, the hackers bricked some of the compromised ICS devices. According to the Polish CERT, some devices were permanently damaged as part of the attackers' attempts to cover their tracks.

The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot.

No valuable logs could be recovered from the device during the investigation.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free