Cyberattack Disrupts Polish Power Plant Operations
A significant cyberattack targeted a Polish combined heat and power plant in December 2025, bringing its steam turbine and water treatment systems to a halt. The perpetrators exploited a private cellular network, typically used by local grid operators for remote equipment management, to infiltrate the plant’s systems.
The facility, crucial for providing heat to approximately 50,000 residents, managed to initiate recovery efforts around 7:30 a.m., even as the attackers remained active within the network. Fortunately, the disruption did not affect the supply of heat or electricity to the consumers.
Investigation and Disclosure by CERT Polska
After an extensive investigation lasting over three months, CERT Polska publicly disclosed the incident on August 8, 2025. This cyber intrusion was the second of its kind reported by Poland’s prime minister earlier in January, indicating a broader campaign targeting critical infrastructure in the region.
The breach leveraged a private APN (Access Point Name), a specialized cellular data network managed by the distribution system operator. This configuration flaw allowed the attackers to transition from a compromised wind-farm network to the control systems of the power plant, marking a novel attack vector in real-world cyberattacks.
Security Vulnerabilities and Recommendations
The investigation did not identify a specific security vulnerability (CVE) as the cause of the breach. While the Teltonika router involved had changed its default password, the WAGO controller was found with default admin credentials. This, alongside the permissive private APN, facilitated the attack.
CERT Polska recommends auditing the APN configurations and implementing client isolation. Furthermore, it advises treating the APN as untrusted, segmenting network traffic, and changing default credentials to enhance security.
Broader Implications and Future Outlook
The attack highlights vulnerabilities in the use of private APNs, commonly deployed in Polish and potentially other international industrial networks. The incident underscores the need for stringent security measures, particularly in configurations that permit widespread network access.
The attacker’s pathway began at a wind farm, exploiting a FortiGate device with exposed VPN capabilities. CERT Polska’s observations suggest SSH tunneling was used to navigate through the network, leading to the turbine shutdown and other destructive actions within the plant.
As global reliance on interconnected industrial systems grows, the importance of robust cybersecurity measures becomes increasingly critical. The recommendations from CERT Polska aim to bolster defenses against future attacks and ensure the resilience of essential infrastructure.
