Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

Renewable energy facility hacking

Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”.

In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities.

In that attack, the hackers gained access to ICS, but mainly targeted grid safety and stability monitoring systems rather than active power generation systems. While some ICS devices were permanently damaged, the attack did not cause any electrical outages.  

In a report published over the weekend, CERT.PL revealed that the country’s energy sector was targeted in a second attack in December 2025. An investigation revealed that this attack, conducted in parallel with the previously disclosed hack, was aimed at a smaller CHP plant supplying heat to 50,000 residents. 

The Polish CERT’s report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world. 

The cyberattack caused the shutdown of a steam turbine and a water treatment system, which resulted in a disruption of the cogeneration process. However, the systems were quickly restored, and heat and electricity supply were not interrupted. 

The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption, but the CERT soon determined that it was the result of hacker activity. 

Advertisement. Scroll to continue reading.

From an edge device to an energy facility’s OT network

The intrusion started on a Fortinet VPN and firewall device located at a wind farm and connected to the internet. The hackers then identified a Teltonika cellular router on the same network and accessed its admin interface. 

An SSH service running on the device was then used to establish a tunnel that enabled communication to a private APN network managed by the distribution system operator (DSO). These private APN networks enable communication between the DSO’s SCADA system and ICS installed at the substation.

The attacker scanned the private APN network and identified a Wago programmable logic controller (PLC) running at a CHP plant. An SSH service enabled on this controller gave the attacker access to the plant’s operational technology (OT) networks. 

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

After conducting reconnaissance over the course of one week, the threat actor connected to Siemens PLCs, switched them to ‘stop’ mode, and set a password to prevent operators from changing the controllers’ operating state and control logic. These actions caused the shutdown of the steam turbine and water treatment systems.

Staff managed to limit the downtime by resetting the affected PLCs to their factory settings and reloading logic from backups. 

Moxa serial device servers and Moxa network switches were also targeted by the attackers and configured to prevent the legitimate operators from accessing them. ABB and Schneider Electric variable frequency drives were also targeted by the attackers, but it’s unclear what actions they carried out on these devices, and some attempts to connect to them were unsuccessful. 

Similar to the attack on the first energy facility, the hackers bricked some of the compromised ICS devices.

According to the Polish CERT, some devices were permanently damaged as part of the attackers’ attempts to cover their tracks. 

“The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot. No valuable logs could be recovered from the device during the investigation.”

Related: Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector

Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Related: Water Sector Cyberattacks Reportedly Hit at Least 12 States

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.