A newly published follow-up from CERT Polska reveals that hackers used a misconfigured private access point name (APN) on a cellular network to reach the operational technology network of a Polish combined heat and power plant, forcing a steam turbine and process-water treatment system offline in late December 2025.[9][1] The facility, which supplies heat to roughly 50,000 residents, stayed online thanks to rapid operator response, even as the attackers remained present in the network.[1][11][12] CERT Polska describes the use of a shared private APN as a lateral-movement path between independent organizations as, to its knowledge, the first time this attack vector has been observed in a real-world cyberattack on critical infrastructure.[9][10]
Investigators say the intruders first compromised a FortiGate VPN appliance at a renewable-energy site that lacked multi-factor authentication and relied on reused credentials, then pivoted to a Teltonika cellular router connected to the grid operator’s private APN.[5][10][11] An SSH tunnel into that APN, combined with a configuration that allowed arbitrary devices on the network to communicate, gave the attackers a direct route into other participants’ environments, including the CHP plant.[9][10] Inside the plant’s OT network, the hackers logged into a WAGO PFC200 programmable logic controller using default credentials and used it as a stepping stone to reach Siemens S7-300 controllers, which they switched into STOP mode to shut down the turbine and water treatment systems.[10][11] Reporting on the incident notes that the attackers relied primarily on legitimate device functionality and industrial protocols rather than deploying custom malware to achieve the shutdown.[9][10][12]
The interference at the CHP plant occurred on the morning of December 29, 2025, with restoration work beginning around 7:30 a.m. local time while the adversary was still active inside the network.[1][9] Although the cogeneration process was interrupted, plant staff managed to restore control before any disruption to heat or electricity deliveries, and national authorities later stressed that the stability of Poland’s power system was never at risk.[1][4][7] The same campaign also hit more than 30 wind and solar farms, a manufacturing company, and another large CHP facility serving nearly 500,000 customers elsewhere in Poland.[5][6][14]
Polish officials have publicly blamed the coordinated December attacks on groups linked to Russia’s Federal Security Service, describing the operation as one of the most serious cyber incidents to hit the country’s energy sector in recent years.[3][4][7] CERT Polska’s analysis of domains and IP addresses tied to the operation found overlaps with infrastructure previously associated with the Dragonfly, Static Tundra, or Berserk Bear threat actor, while separate research by ESET pointed toward the Sandworm group, leaving final attribution an open question.[6][14] According to public reporting, the attackers deployed destructive wiper malware such as DynoWiper and LazyWiper at other victim sites and sought to permanently erase data at the CHP plant as well, but existing defenses blocked that phase of the operation.[3][5][6]
For defenders, the case underscores that private cellular networks and APNs must be treated as untrusted shared infrastructure, with strict segmentation between customers and no default any-to-any connectivity within the same logical network. Security teams operating industrial environments should harden remote-access paths by enforcing multi-factor authentication on VPNs, eliminating default credentials on PLCs and gateways, and closely monitoring access from cellular routers and other edge devices. The incident also adds urgency to prior research showing that vulnerabilities in industrial cellular routers and their cloud management platforms, including multiple high-severity flaws in Teltonika’s remote management system and router firmware tracked under several CVE identifiers, can expose OT networks to remote compromise if left unpatched.[13] Separate analyses of wireless industrial IoT solutions from vendors such as Sierra, InHand, and ETIC have identified dozens of web-interface bugs that enable remote code execution, illustrating how weaknesses at the connectivity layer can cascade into deep access to critical control systems.[15]
References
- Hackers Breach Polish Power Plant Controls via Private …
- Polish officials blame Russian domestic spy agency for Dec 29 cyberattacks
- Poland Stops Cyberattacks on Energy Infrastructure – Gov.pl
- CERT Polska Report: Coordinated Cyberattacks Disrupt …
- Poland faced a surge in cyberattacks in 2025, including a major …
- Massive cyberattack on Polish power system in December …
- Follow-Up Report of the December 2025 Energy Sector …
- Disruption of Polish CHP: Wind Farm to OT via Private APN
- Radoslav Krehlik’s Post
- Hackers Breach Polish Power Plant Controls via Private …
- Industrial Cellular Routers at Risk: 11 New Vulnerabilities Expose OT Networks
- Explained: OT Cyber Attack on Poland – OMICRON cybersecurity
- Flaws in industrial wireless IoT solutions can give attackers deep access into OT networks
