HomeSecurityPoland: Attack on energy unit via private APN

Poland: Attack on energy plant via private APN

A Polish cogeneration plant has been hit by a devastating cyberattack, with attackers exploiting a private APN to reach the operational technology network. The attack temporarily shut down a steam turbine and water treatment system, without disrupting the heat supply to residents.

Private APN in attack on Polish energy unit

The incident is described in a supplementary report by CERT Polska, published after more than three months of investigation. The agency links the incident to the coordinated attacks on December 29, 2025, against Polish energy infrastructure.

See also: CERT Polska: Details on cyberattacks on wind and photovoltaic plants

How the private APN entered the attack chain

According to CERT Polska, the wider campaign affected around 30 wind and photovoltaic power plants, a large cogeneration plant and, in parallel, a second smaller plant supplying heat to around 50,000 residents. The new element of the report is the revelation that the private APN was used as part of the route to the OT network.

SecurityWeek ’s technical analysis describes the access chain. The attackers started from a Fortinet VPN appliance and firewall at a wind farm, located a Teltonika mobile connectivity router, and used an enabled SSH service to tunnel to the distribution manager’s private APN.

Through the private APN, the attackers scanned the network and located a Wago PLC controller in a cogeneration unit. The enabled SSH service on the controller gave them access to the internal OT environment. CERT Polska notes that the incorrect configuration allowed arbitrary devices within the private APN to communicate with each other, a pattern that is often seen in other countries.

Private APN and access to OT energy network

From private APN to industrial controllers

The perpetrators remained in the environment for about a week, conducting reconnaissance before attempting to affect the equipment. They then connected to Siemens PLCs, put them in stop , and set a password so that operators could not change the operating state or control logic.

These actions stopped a steam turbine and the water treatment system for technical use, temporarily interrupting the cogeneration process. The quick reaction of the personnel limited the duration of the incident and did not cause an interruption in the supply of heat to consumers.

The attack was not limited to PLCs. The official government briefing notes activity on Moxa networking devices and Siemens PLCs, while technical coverage documents attempts to access ABB and Schneider Electric frequency converters. The Wago used as a gateway suffered a partition table corruption and did not recover after a factory reset.

See also: Polish security service reports ICS breaches at facilities

PLC and industrial installation after attack via private APN

What needs to be changed in APN connections

CERT Polska describes the private APN as an unprecedented, according to available evidence, attack vector in a real incident. The service does not consider that the private telecommunications infrastructure should be treated as trusted in itself. On the contrary, organizations should check whether the relevant setting creates unwanted communication between devices.

Official recommendations include checking the APN configuration, treating it as an untrusted network in relation to the OT, and strictly restricting communication between the OT and the gateway device. Traffic monitoring, centralized event logging, limiting open ports, changing default credentials, and including APN devices in penetration testing are also required.

See also: Exploiting default ICS credentials in energy facilities

Private APN security audit in critical energy infrastructure

The recovery relied on restoring the PLCs and loading the logic from backups, but the Wago crash deprived researchers of useful logs. Therefore, audits must cover gateway devices, SSH services, changes in PLC operation, and any unusual communication within the private APN.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The case shows that a network that is called private is not automatically isolated. The SecNews technical team recommends that energy operators review remote access routes, limit connections to the absolute minimum, and maintain verified backups so that a breach of the telecommunications gateway does not escalate into production sabotage.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS