Polish Energy Plant Breach via Private APN
Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland's energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down.
The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report, saying that the attacker used a private Access Point Name (APN) to access the operational technology network. The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another.
Background
On December 29, 2025, an attacker believed to be linked to the Russian Electrum threat group targeted 30 wind and solar power installations and a large CHP plant in Poland, destroying key equipment beyond repair. The threat actor hit distributed energy resource (DER) sites across the country, disabled communications equipment, corrupted operational technology (OT) devices, and wiped Windows systems.
Despite this effort to destabilize the grid, energy generation and distribution were not disrupted. In the newly disclosed attack at a second, smaller CHP plant, the threat actor switched off the programmable logic controllers (PLC) and protected access with a password, thus deactivating a steam turbine and the plant’s process-water treatment system and interrupting cogeneration operations.
Novel Attack Path
Upon investigating the incident, the Polish CERT determined that the attacker initially compromised a FortiGate VPN/firewall at a wind farm and used a Teltonika cellular router on its network to tunnel into a private APN managed by the distribution system operator. The APN lacked client isolation, allowing the attacker to scan for and communicate with devices at other facilities.
Beginning on December 18, the attacker found a WAGO PFC200 PLC at the CHP plant whose web interface was exposed on the APN and protected with default administrator credentials. After compromising the controller, the attacker enabled SSH and used it as a bridge into the plant’s OT network.
Over the following week, they scanned the network for SCADA systems and industrial devices, and on December 25 they connected to three Siemens PLCs, likely in preparation for the attack. At approximately 5:30 a.m. on December 29, the attacker accessed the SCADA interface and Siemens PLCs, switching them into STOP mode, activating password protection, and shutting down the steam turbine and process-water treatment system.
Recommendations
The Polish CERT believes this to be the first known real-world cyberattack in which an attacker entered an OT network by moving laterally through a private APN. It is recommended to treat private APNs as untrusted external networks, enable isolation between connected clients, use allowlists for essential traffic between APN gateways and OT systems, and disable exposed SSH and Telnet administration services.
Security teams should test every layer before attackers do, as 54% of successful attacks are logged and only 14% are alerted on. The rest move through the environment unseen, highlighting the need for breach and attack simulation tests to stop threats from slipping by detection.
Source: BleepingComputer