Home / Blog / Hackers breached a small Polish energy plant via private…
Tech News

Hackers breached a small Polish energy plant via private APN last year

I'll pull the full BleepingComputer report so the body stays grounded in named facts, then draft plain-prose paragraphs only.Hackers used a private mobile…

By Dillip Chowdary • Aug 12, 2026 • Source: BleepingComputer

Hackers breached a small Polish energy plant via private APN last year

What happened

I'll pull the full BleepingComputer report so the body stays grounded in named facts, then draft plain-prose paragraphs only.Hackers used a private mobile APN to reach the operational technology network of a small Polish combined heat-and-power plant that supplies heat to about 50,000 residents, shutting a steam turbine and the process-water treatment system and interrupting cogeneration. The Polish Computer Emergency Response Team disclosed the case in a follow-up report as a second facility hit during the destructive cyberattacks on Poland’s energy sector last year. On December 29, 2025, an actor linked in reporting to the Russian Electrum group had already targeted about 30 wind and solar installations and a large CHP plant, destroying equipment, corrupting OT devices, and wiping Windows systems without stopping generation or distribution. At this smaller plant the attacker switched programmable logic controllers into STOP mode and password-protected them; staff restored systems quickly, so the outage was short and did not affect the population.

The path was architectural, not a single exotic exploit. Investigators say the attacker first compromised a FortiGate VPN and firewall at a wind farm, then used a Teltonika cellular router on that network to tunnel into a private Access Point Name managed by the distribution system operator. The APN had no client isolation, so devices on the network could talk to one another. From December 18 the attacker found a WAGO PFC200 PLC at the CHP plant whose web interface sat on the APN behind default administrator credentials, enabled SSH, and bridged into the plant’s OT network. Over the next week they scanned for SCADA and industrial gear; on December 25 they connected to three Siemens PLCs, likely as rehearsal. At about 5:30 a.m. on December 29 they used the SCADA path and Siemens controllers to stop the turbine and water treatment system, reset and reconfigured several Moxa devices to slow recovery, and corrupted or factory-reset the WAGO controller, Teltonika router, and FortiGate so logs and forensics suffered.

The technical detail

Hackers breached a small Polish energy plant via private APN last year
Illustration · Pexels

For engineers who build or defend industrial systems, the lesson is that “private cellular” is not a security boundary. A private APN is a shared L2/L3 domain for remote telemetry and control; if client-to-client traffic is allowed, a foothold at one DER site becomes a lateral path into another facility’s PLCs. Edge devices that exist only to carry serial or protocol traffic—cellular routers, VPN concentrators, management ports on PLCs—often sit on a second interface behind the firewall that operators think is the only gate. Default web admin credentials on a WAGO PFC200 and exposed SSH or Telnet on APN-reachable interfaces turn that shared medium into a bridge. The wind farm met protocol requirements for remote terminal unit traffic and still supplied the entry route because management of the carrier device was never part of those requirements.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Why it matters for builders

The incident sits in a wider energy-sector pressure campaign rather than an isolated one-off. Reporting ties the December activity to Electrum and to hits across distributed energy resources and larger CHP sites, with parallel public assessments from the Polish government, CERT Polska, ESET, and Dragos scoped to different slices of the same wave. CERT Polska states that, to its knowledge, this is the first observed real-world case of entering an OT network by moving laterally through a private APN. Post-incident surveys found the permissive APN layout common in Poland at the time, and CERT estimates similar arrangements are widely used internationally—so the market context is not a rare misconfiguration but a default design pattern for how grid operators and plant owners connect remote sites over cellular.

Market and competitive context

Practical next steps follow the report’s recommendations and the failure modes that showed up on the wire. Treat private APNs as untrusted external networks from the OT side: enable client isolation, allowlist only essential traffic between APN gateways and control systems, and strip management services from APN-facing interfaces. Change default credentials on every web and SSH surface that can see the APN, including PLCs and cellular routers. Segment so a VPN-admin compromise at one wind farm cannot reach every VLAN that happens to host a second Ethernet port on a router. Watch for APN scans, unexpected SSH tunnels through cellular gateways, and new admin sessions on controllers whose only intended role is field I/O. Recovery plans should assume attackers will factory-reset edge devices, reassign unreachable addresses such as 127.0.0.1, and destroy logs—so offline config backups and out-of-band management matter as much as detection.

What to watch next

Open questions remain on attribution for this specific plant, how the Teltonika SSH password was obtained, and whether an unpublished router flaw played any role; investigators could not pin a CVE as the root cause. The broader risk is design assumption: private APNs still appear in guidance as an isolation option for cellular access to OT, including recent federal advice for water-sector PLCs, while this case shows that isolation fails if the APN itself is a flat mesh. Related prior art is less “novel malware” than the long record of OT disruption via legitimate controller functions—STOP modes, password locks, factory resets—once network reachability exists. No wiper was required here; every destructive step used supported device features over protocols the plant already ran. Operators who inventory APN membership, enforce client isolation, and treat every remote cellular path as hostile will close the exact gap CERT says was used first in the wild.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →