> Back to All Posts

Polish Energy Plant Breach: Hackers Pivoted via Private APN

Polish energy plant breach

Investigators in Poland have now detailed a second victim from the destructive attacks that struck the country’s energy sector in December 2025. The newly disclosed Polish energy plant breach hit a small combined heat-and-power facility that supplies warmth to roughly 50,000 residents. Attackers shut down its steam turbine and its process-water treatment system. Staff restored operations quickly, so people in the area never felt an interruption.

The route the attackers took matters more than the damage they caused. They reached the plant’s control systems through a private mobile network, known as an APN, operated by the regional distribution company. Nobody had documented that path in a live attack before. As a result, the case now carries weight for utilities well outside Poland.

How the Polish Energy Plant Breach Began

The intrusion started somewhere else entirely. Attackers first compromised a FortiGate VPN and firewall appliance at a wind farm. From there they reached a Teltonika cellular router on the same network. That router handed them a tunnel into the private APN linking the operator’s remote sites.

A private APN works as a walled-off slice of a mobile carrier’s network. Companies rely on it so field equipment can report back without touching the public internet. In theory, traffic stays contained. However, this network lacked client isolation, so any device inside could talk to any other device inside.

That single gap turned a foothold at one wind farm into reach across the operator’s entire estate. The attacker scanned the APN and found hardware belonging to a completely different site. On December 18, they spotted a WAGO PFC200 controller at the heat-and-power plant with its web interface exposed. The device still used default administrator credentials.

A Week of Quiet Reconnaissance

After taking over the controller, the attacker switched on SSH. The device then worked as a bridge into the plant’s operational technology network. Over the following week, they mapped SCADA systems and industrial hardware without setting off alarms. On December 25, they connected to three Siemens programmable logic controllers.

Their patience deserves attention. Eleven days passed between the first foothold and the moment equipment stopped running. During that window, the attacker learned the process, picked out the right controllers, and planned a shutdown that would bite.

The Morning the Turbine Stopped

At roughly 5:30 a.m. on December 29, the attacker opened the SCADA interface and reached the Siemens controllers. They flipped the devices into STOP mode and applied password protection to lock operators out. The steam turbine went offline, and so did the process-water treatment system. Cogeneration at the site halted.

The same morning, a wider campaign struck around 30 wind and solar installations plus a larger heat-and-power plant. That operation wrecked equipment beyond repair, corrupted control devices, and wiped Windows machines. Analysts tie the activity to a threat actor associated with the Russian Electrum group. Despite the scale of it, national generation and distribution kept running.

Covering the Trail

The attacker also worked hard to slow the cleanup. They reset and reconfigured several Moxa devices, which made restoration far harder for engineers on site. Then they destroyed logs and corrupted the WAGO controller, the Teltonika router, and the FortiGate firewall used along the way.

Those steps served two purposes. First, they stretched out recovery at a moment when every hour counted. Second, they stripped away the forensic trail. Even so, enough evidence survived for investigators tracing the Polish energy plant breach to rebuild the full attack path.

Why the Polish Energy Plant Breach Matters Beyond Poland

Poland’s national CERT describes this as the first observed case of an attacker entering an OT network by moving sideways through a private APN. The technique itself is not exotic. It leans on trust that operators placed in a network they assumed was sealed.

Follow-up surveys found the same configuration at other Polish operators. Analysts expect similar arrangements abroad, because the design pattern suits any utility managing scattered assets. Wind farms, solar arrays, substations, and pumping stations all need cheap remote connectivity, and a carrier-run private APN answers that need well. So the exposure reaches far past one company.

How Utilities Can Close the Gap

The guidance coming out of the investigation is refreshingly practical. Treat a private APN as an untrusted external network, exactly as you would treat public internet access. Enable client isolation so connected devices cannot see each other. Then apply allowlists that permit only essential traffic between APN gateways and OT systems.

Basic Hygiene Still Does Heavy Lifting

Several doors in the Polish energy plant breach were left open by simple oversights. Default credentials on the WAGO controller handed the attacker an easy win. An exposed web interface made that device findable in the first place. Disabling SSH and Telnet administration on remotely reachable gear removes another favourite pivot point.

Final Thoughts

Attackers keep finding value in the plumbing that connects industrial sites. The Polish energy plant breach worked because a chain of small oversights lined up neatly, and none of them demanded advanced tooling. A missing isolation setting, a default password, and an exposed interface were enough to stop a turbine.

For utilities, the work starts with mapping every network that touches OT equipment, including the ones a carrier runs on their behalf. For everyone else, it is worth remembering that privacy at the network layer rests on configuration rather than labels. A private connection stays private only while someone checks the settings.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.