A Polish cogeneration plant has been hit by a devastating cyberattack, with attackers exploiting a private APN to reach the operational technology network. The attack temporarily shut down a steam turbine and water treatment system, without disrupting the heat supply to residents.

The incident is described in a supplementary report by CERT Polska, published after more than three months of investigation. The agency links the incident to the coordinated attacks on December 29, 2025, against Polish energy infrastructure.
See also: CERT Polska: Details on cyberattacks on wind and photovoltaic plants
How the private APN entered the attack chain
According to CERT Polska, the wider campaign affected around 30 wind and photovoltaic power plants, a large cogeneration plant and, in parallel, a second smaller plant supplying heat to around 50,000 residents. The new element of the report is the revelation that the private APN was used as part of the route to the OT network.
SecurityWeek ’s technical analysis describes the access chain. The attackers started from a Fortinet VPN appliance and firewall at a wind farm, located a Teltonika mobile connectivity router, and used an enabled SSH service to tunnel to the distribution manager’s private APN.
Through the private APN, the attackers scanned the network and located a Wago PLC controller in a cogeneration unit. The enabled SSH service on the controller gave them access to the internal OT environment. CERT Polska notes that the incorrect configuration allowed arbitrary devices within the private APN to communicate with each other, a pattern that is often seen in other countries.

From private APN to industrial controllers
The perpetrators remained in the environment for about a week, conducting reconnaissance before attempting to affect the equipment. They then connected to Siemens PLCs, put them in stop , and set a password so that operators could not change the operating state or control logic.
These actions stopped a steam turbine and the water treatment system for technical use, temporarily interrupting the cogeneration process. The quick reaction of the personnel limited the duration of the incident and did not cause an interruption in the supply of heat to consumers.
The attack was not limited to PLCs. The official government briefing notes activity on Moxa networking devices and Siemens PLCs, while technical coverage documents attempts to access ABB and Schneider Electric frequency converters. The Wago used as a gateway suffered a partition table corruption and did not recover after a factory reset.
See also: Polish security service reports ICS breaches at facilities

What needs to be changed in APN connections
CERT Polska describes the private APN as an unprecedented, according to available evidence, attack vector in a real incident. The service does not consider that the private telecommunications infrastructure should be treated as trusted in itself. On the contrary, organizations should check whether the relevant setting creates unwanted communication between devices.
Official recommendations include checking the APN configuration, treating it as an untrusted network in relation to the OT, and strictly restricting communication between the OT and the gateway device. Traffic monitoring, centralized event logging, limiting open ports, changing default credentials, and including APN devices in penetration testing are also required.
See also: Exploiting default ICS credentials in energy facilities

The recovery relied on restoring the PLCs and loading the logic from backups, but the Wago crash deprived researchers of useful logs. Therefore, audits must cover gateway devices, SSH services, changes in PLC operation, and any unusual communication within the private APN.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The case shows that a network that is called private is not automatically isolated. The SecNews technical team recommends that energy operators review remote access routes, limit connections to the absolute minimum, and maintain verified backups so that a breach of the telecommunications gateway does not escalate into production sabotage.
