Destructive Cyberattack on Polish Energy Grid Used Novel Private APN Vector, CERT Polska Reports
A newly disclosed cyberattack against a Polish combined heat and power plant marks the first known instance of threat actors using a private cellular network to breach operational technology.
- Cybersecurity Investigators
- Advocate for strict network segmentation and zero-trust architectures, arguing that private cellular networks can no longer be treated as inherently secure.
- Critical Infrastructure Operators
- Highlight the operational complexities of securing legacy systems and managing shared network boundaries with telecommunications providers.
- Geopolitical Analysts
- View the incident as part of a broader state-sponsored effort to probe and map vulnerabilities in European energy grids.
For years, critical infrastructure operators have operated under a comforting assumption: if a network is physically separated from the public internet, it is inherently secure. This premise has driven the widespread adoption of private cellular networks to connect remote substations and renewable energy sites. However, a newly disclosed cyberattack against a Polish combined heat and power plant has shattered that assumption, revealing that the very infrastructure designed to isolate industrial systems can be weaponized to breach them.[1][2]
In a supplementary report released in August 2026, Poland’s computer emergency response team, CERT Polska, detailed a previously undisclosed intrusion that occurred on December 29, 2025. The attack targeted a combined heat and power plant supplying heat to approximately 50,000 residents. While the incident happened concurrently with a broader, Russian-linked campaign against 30 Polish renewable energy facilities, this specific breach stood out for its unprecedented methodology: the attackers bypassed traditional perimeter defenses by pivoting through a private Access Point Name (APN) network.[3][4]
The attack sequence began not at the power plant itself, but at a remote wind farm. Threat actors first compromised a FortiGate device serving as a firewall and virtual private network concentrator. Once inside the wind farm's network, they identified a Teltonika cellular router. By accessing the router's web administration interface and logging into its Secure Shell service, the attackers established a tunnel that allowed them to communicate directly with the private APN network managed by the local distribution system operator.[1][5]
A private APN is a dedicated mobile data network purchased from a cellular carrier, intended to provide secure connectivity for distributed equipment. Because it is isolated from the broader internet, operators often treat it as a trusted environment. In this case, a critical misconfiguration allowed arbitrary devices within the APN to communicate freely with one another—a setup that effectively turned a sprawling, multi-site infrastructure into a flat, unsegmented network.[2][4]
A private APN is a dedicated mobile data network purchased from a cellular carrier, intended to provide secure connectivity for distributed equipment.
Exploiting this lack of client isolation, the attackers spent over a week scanning the private APN for vulnerable services and industrial protocols. They eventually discovered a WAGO programmable logic controller at the power plant that exposed its web administration interface to the wide area network. Protected only by default credentials, the controller provided the attackers with administrative access, which they used to establish a secure tunnel deep into the plant's operational technology network.[3][5]
On the morning of December 29, the attackers executed their destructive payload. They targeted three Siemens controllers, switching them to a stopped state and locking operators out with new passwords. This action successfully shut down the plant's steam turbine and the water treatment system required for the cogeneration process. To hinder recovery efforts, the hackers then deployed automated scripts to wipe the configurations of network equipment and corrupt the partition table of the WAGO controller they had used as a gateway.[1][2]
Despite the sophistication of the attack, the real-world impact was blunted by sheer coincidence. Routine maintenance was already underway at the plant, leading staff to initially attribute the sudden shutdown to a contractor error. Operators initiated recovery procedures within two hours—while the attackers were still active in the network—and managed to restore the systems before any disruption to customer heating or electricity occurred. The incident was initially filed as an operational anomaly, and it took CERT Polska investigators more than three months to reconstruct the digital forensic trail from surviving router logs.[4][5]
The Polish incident serves as a stark warning for utility operators worldwide. CERT Polska noted that the permissive APN configuration exploited in this attack is not unique to Poland, but is widely deployed internationally. As the energy sector continues its digital transformation, integrating more private cellular networks, the attack surface is expanding. The breach underscores that network boundaries are increasingly porous, and that securing critical infrastructure requires treating every internal connection—even those on private cellular networks—as potentially hostile.[1][3]
Key points
- Attackers breached a Polish combined heat and power plant in December 2025 using a private Access Point Name (APN).
- The incident occurred alongside a broader campaign targeting 30 renewable energy facilities.
- Hackers pivoted from a compromised wind farm VPN to the private APN, exploiting a misconfiguration that allowed unrestricted device communication.
- The attack shut down a steam turbine and water treatment system, though operators restored functionality before heating supplies were disrupted.
- CERT Polska warns that the vulnerable APN configuration exploited in the attack is widely used by utilities globally.
Key terms
- Private APN
- A dedicated mobile data network provided by a cellular carrier, allowing an organization's remote devices to communicate securely outside the public internet.
- Operational Technology (OT)
- Hardware and software that detects or causes a change through the direct monitoring and control of physical industrial devices and processes.
- Programmable Logic Controller (PLC)
- An industrial computer control system that continuously monitors the state of input devices and makes decisions to control output devices.
- Combined Heat and Power (CHP)
- A highly efficient process that captures and utilizes the heat that is a by-product of the electricity generation process.
- Client Isolation
- A network security feature that prevents devices connected to the same network from communicating directly with one another.
Sources
[1]Help Net SecurityCybersecurity InvestigatorsPoland energy sector cyberattack traced to private APN
Read on Help Net Security →
[2]SecurityWeekCybersecurity InvestigatorsNovel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Read on SecurityWeek →
[3]Industrial CyberCritical Infrastructure OperatorsCERT Polska exposes multi-stage cyberattack on energy infrastructure involving VPN, private APN, OT network tunneling
Read on Industrial Cyber →
[4]CERT PolskaCybersecurity InvestigatorsUzupełnienie raportu z incydentu w sektorze energii w grudniu 2025 roku
Read on CERT Polska →
[5]CERT Polska ReportCybersecurity InvestigatorsCERT Polska Energy Sector Incident Follow-up Report 2025
Read on CERT Polska Report →
Comments
Every angle. Every day.
Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.
