Poland’s computer emergency response team (CERT.PL) recently disclosed a second cyberattack on the nation’s energy infrastructure. This attack, which occurred in December 2025, targeted industrial control systems (ICS) with the intent to cause destruction.
Details of the December 2025 Attack
In late December, cyber attackers linked to the Russian APT group Sandworm infiltrated communication and control systems across approximately 30 energy sites, including combined heat and power (CHP) plants and renewable energy facilities. The hackers mainly focused on grid monitoring systems, leaving power generation systems largely unaffected. Some ICS devices were damaged, but power outages were avoided.
The latest report by CERT.PL reveals that a smaller CHP plant, responsible for heating 50,000 residents, was the focus of this second attack, which occurred simultaneously with the first. Notably, it marked the first known use of a private APN as an attack vector, a configuration commonly found in Poland and globally.
Technical Aspects of the Intrusion
The attackers began their intrusion through a Fortinet VPN and firewall device at a wind farm. They then located a Teltonika cellular router on the same network, exploiting its admin interface. By using an SSH service, they established a tunnel to the private APN network, which facilitated communication between the distribution system operator’s SCADA system and ICS at substations.
Once inside, the attackers identified a Wago programmable logic controller (PLC) at the CHP plant. By accessing this controller, they infiltrated the plant’s operational technology (OT) networks. Over a week of reconnaissance, they gained control of Siemens PLCs, disabling them by setting them to ‘stop’ mode and securing them with a password.
Impact and Mitigation Efforts
The cyberattack resulted in the shutdown of a steam turbine and a water treatment system, disrupting the cogeneration process. However, swift actions by staff, including resetting affected PLCs to their factory settings, minimized downtime and prevented a supply interruption of heat and electricity.
The attackers also targeted Moxa serial device servers and network switches, attempting to block legitimate access. While some ICS devices were irreparably damaged, the attackers’ efforts to hide their tracks included corrupting the partition table of the Wago controller used as a network gateway.
Broader Implications and Future Outlook
This incident underscores the vulnerabilities in energy sector networks, especially concerning private APN configurations. With similar vulnerabilities identified globally, energy sectors worldwide must bolster their cybersecurity measures to prevent future attacks.
As cyber threats continue to evolve, energy facilities must adopt robust security protocols to protect critical infrastructure, ensuring operational resilience against such sophisticated attacks.
