Destructive Cyberattack on Polish Energy Grid Used Novel Private APN Vector, CERT Polska Reports
A newly disclosed cyberattack against a Polish combined heat and power plant marks the first known instance of threat actors using a private cellular network to breach operational technology.
For years, critical infrastructure operators have operated under a comforting assumption: if a network is physically separated from the public internet, it is inherently secure. This premise has driven the widespread adoption of private cellular networks to connect remote substations and renewable energy sites. However, a newly disclosed cyberattack against a Polish combined heat and power plant has shattered that assumption, revealing that the very infrastructure designed to isolate industrial systems can be weaponized to breach them.[1][2]
In a supplementary report released in August 2026, Poland’s computer emergency response team, CERT Polska, detailed a previously undisclosed intrusion that occurred on December 29, 2025. The attack targeted a combined heat and power plant supplying heat to approximately 50,000 residents. While the incident happened concurrently with a broader, Russian-linked campaign against 30 Polish renewable energy facilities, this specific breach stood out for its unprecedented methodology: the attackers bypassed traditional perimeter defenses by pivoting through a private Access Point Name (APN) network.[3][4]
The attack sequence began not at the power plant itself, but at a remote wind farm. Threat actors first compromised a FortiGate device serving as a firewall and virtual private network concentrator. Once inside the wind farm's network, they identified a Teltonika cellular router. By accessing the router's web administration interface and logging into its Secure Shell service, the attackers established a tunnel that allowed them to communicate directly with the private APN network managed by the local distribution system operator.[1][5]
A private APN is a dedicated mobile data network purchased from a cellular carrier, intended to provide secure connectivity for distributed equipment. Because it is isolated from the broader internet, operators often treat it as a trusted environment. In this case, a critical misconfiguration allowed arbitrary devices within the APN to communicate freely with one another—a setup that effectively turned a sprawling, multi-site infrastructure into a flat, unsegmented network.[2][4]
Exploiting this lack of client isolation, the attackers spent over a week scanning the private APN for vulnerable services and industrial protocols. They eventually discovered a WAGO programmable logic controller at the power plant that exposed its web administration interface to the wide area network. Protected only by default credentials, the controller provided the attackers with administrative access, which they used to establish a secure tunnel deep into the plant's operational technology network.[3][5]
On the morning of December 29, the attackers executed their destructive payload. They targeted three Siemens controllers, switching them to a stopped state and locking operators out with new passwords. This action successfully shut down the plant's steam turbine and the water treatment system required for the cogeneration process. To hinder recovery efforts, the hackers then deployed automated scripts to wipe the configurations of network equipment and corrupt the partition table of the WAGO controller they had used as a gateway.[1][2]
Despite the sophistication of the attack, the real-world impact was blunted by sheer coincidence. Routine maintenance was already underway at the plant, leading staff to initially attribute the sudden shutdown to a contractor error.
Operators initiated recovery procedures within two hours—while the attackers were still active in the network—and managed to restore the systems before any disruption to customer heating or electricity occurred. The incident was initially filed as an operational anomaly, and it took CERT Polska investigators more than three months to reconstruct the digital forensic trail from surviving router logs.[4][5]
The Polish incident serves as a stark warning for utility operators worldwide. CERT Polska noted that the permissive APN configuration exploited in this attack is not unique to Poland, but is widely deployed internationally. As the energy sector continues its digital transformation, integrating more private cellular networks, the attack surface is expanding. The breach underscores that network boundaries are increasingly porous, and that securing critical infrastructure requires treating every internal connection—even those on private cellular networks—as potentially hostile.[1][3]
Viewpoints in depth
Cybersecurity Investigators
Argue that the attack exposes a fundamental flaw in how utilities approach network segmentation.
Security researchers emphasize that relying on the inherent isolation of private cellular networks is no longer a viable defense strategy. They point out that treating an APN as a trusted environment often leads to relaxed internal controls, allowing an attacker who breaches a single edge device to move laterally across an entire infrastructure. Investigators advocate for strict client isolation, zero-trust architectures, and the immediate elimination of default credentials on all internet-facing and APN-facing devices.
Critical Infrastructure Operators
View the incident as a wake-up call regarding the complexities of securing distributed energy resources.
For utility operators, the attack highlights the operational challenges of retrofitting legacy systems and managing shared network boundaries. They note that responsibility for securing a private APN is often blurred between the utility and the telecommunications provider. While acknowledging the vulnerabilities exposed by the CERT Polska report, operators stress the difficulty of implementing comprehensive segmentation without disrupting the real-time communication required to manage distributed grids.
Geopolitical Analysts
Frame the attack within the broader context of state-sponsored cyber warfare and critical infrastructure probing.
Analysts observe that while this specific intrusion was not formally attributed, its timing alongside the Sandworm-linked campaign against Polish infrastructure suggests a coordinated effort by state-backed actors. They argue that such attacks are designed not just to cause immediate disruption, but to test novel attack vectors and probe the resilience of European energy grids during periods of high demand, mapping out vulnerabilities for potential future conflicts.
Key points
- Attackers breached a Polish combined heat and power plant in December 2025 using a private Access Point Name (APN).
- The incident occurred alongside a broader campaign targeting 30 renewable energy facilities.
- Hackers pivoted from a compromised wind farm VPN to the private APN, exploiting a misconfiguration that allowed unrestricted device communication.
- The attack shut down a steam turbine and water treatment system, though operators restored functionality before heating supplies were disrupted.
What we don’t know
- Whether the threat actors intended to cause a prolonged blackout or were simply testing their capability to disrupt the cogeneration process.
- The exact identity of the attackers, as CERT Polska did not formally attribute the APN breach to the Sandworm group responsible for the broader campaign.
- How many other critical infrastructure facilities globally are currently operating with similarly misconfigured private APN networks.
How we got here
Dec 18, 2025
Attackers begin scanning the private APN network for vulnerable industrial protocols and web services.
Dec 25, 2025
Hackers probe industrial equipment and test credentials against the plant's firewall to map their targets.
Dec 29, 2025
Threat actors initiate destructive actions, disabling Siemens controllers and shutting down a steam turbine.
Jan 30, 2026
CERT Polska publishes its initial report on the broader December attacks, omitting the smaller CHP plant incident pending further investigation.
Aug 8, 2026
CERT Polska releases a supplementary report detailing the private APN attack vector after a three-month forensic analysis.
- Cybersecurity Investigators
- Advocate for strict network segmentation and zero-trust architectures, arguing that private cellular networks can no longer be treated as inherently secure.
- Critical Infrastructure Operators
- Highlight the operational complexities of securing legacy systems and managing shared network boundaries with telecommunications providers.
- Geopolitical Analysts
- View the incident as part of a broader state-sponsored effort to probe and map vulnerabilities in European energy grids.
Perspectives this story doesn't cover
- Telecommunications Providers
- Industrial Control System Manufacturers
Sources
[1]Help Net SecurityCybersecurity InvestigatorsPoland energy sector cyberattack traced to private APN
Read on Help Net Security →
[2]SecurityWeekCybersecurity InvestigatorsNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Read on SecurityWeek →
[3]Industrial CyberCritical Infrastructure OperatorsCERT Polska exposes multi-stage cyberattack on energy infrastructure involving VPN, private APN, OT network tunneling
Read on Industrial Cyber →
[4]CERT PolskaCybersecurity InvestigatorsUzupełnienie raportu z incydentu w sektorze energii w grudniu 2025 roku
Read on CERT Polska →
[5]CERT Polska ReportCybersecurity InvestigatorsCERT Polska Energy Sector Incident Follow-up Report 2025
Read on CERT Polska Report →
More in Defense & Security
See all →AUMF Doctrine
How the 2001 AUMF's 'Associated Forces' Clause Legally Authorizes U.S. Military Action Against Non-State Actors
6 sources
Terminal Ballistics
The Cubic Root of Mass: How the Physics of High-Explosive Fragmentation Determines Lethality Radius
8 sources
Nuclear Deterrence
How the US Nuclear Command and Control System Actually Works
3 sources
Combat Readiness
Defining Military Readiness: How Manning, Training, Equipping, and Sustainment Dictate Combat Power
8 sources
Comments
Every angle. Every day.
Get Defense & Security stories with full source coverage and perspective breakdowns, free every day.




