Polish Energy Facility Sabotaged by Sophisticated Hackers, Raising Concerns About Grid Vulnerability
A disturbing trend is emerging in Poland’s energy sector as a second attack on an industrial control system (ICS) facility has been discovered. The hackers’ goal was “purely destructive,” targeting grid safety and stability monitoring systems to cause significant disruption. This latest incident serves as a stark reminder of the ongoing threat to critical infrastructure, particularly in Eastern Europe.
The attackers, linked to the Russian government’s APT named Sandworm, used an innovative tactic involving a private APN (Access Point Name) network to breach the system. This attack vector appears to be new and has been identified by Poland’s computer emergency response team (CERT) as a vulnerable configuration that could be exploited globally.
The second attack on an energy facility occurred in December 2025, concurrently with another disclosed hack targeting roughly 30 sites, including combined heat and power (CHP) plants. This time, the hackers focused on a smaller CHP plant providing heat to 50,000 residents. The attackers’ actions caused the shutdown of a steam turbine and water treatment system, disrupting the cogeneration process. However, thanks to swift action by facility staff, the systems were quickly restored, and no electrical outages occurred.
The intruders exploited vulnerabilities in various devices connected to the ICS network. They began by accessing an edge device’s Fortinet VPN and firewall, then identified a Teltonika cellular router on the same network and accessed its admin interface via SSH (Secure Shell) service. From there, they breached the private APN network managed by the distribution system operator (DSO), enabling communication between the DSO’s SCADA system and ICS installed at the substation.
The attackers then scanned the private APN network to identify a Wago programmable logic controller (PLC) running at a CHP plant. By exploiting an SSH service enabled on this controller, they gained access to the plant’s operational technology (OT) networks. The hackers spent one week conducting reconnaissance before connecting to Siemens PLCs, switching them to ‘stop’ mode, and setting passwords that prevented operators from changing the controllers’ operating state or control logic.
The attackers also targeted Moxa serial device servers and network switches, as well as ABB and Schneider Electric variable frequency drives. While it’s unclear what actions they carried out on these devices, some attempts to connect to them were unsuccessful. The hackers even went so far as to brick some of the compromised ICS devices and permanently damage others in an effort to cover their tracks.
The Polish CERT warns that this private APN pivot attack vector could be used globally, given its widespread presence in Poland and other countries. This latest incident underscores the need for robust security measures, ongoing monitoring, and regular device updates to prevent similar attacks from occurring.
As a result of this incident, facility staff learned an important lesson about the importance of maintaining up-to-date security patches and regularly monitoring their network’s activity. For all readers, this incident serves as a reminder to prioritize cybersecurity in industrial control systems and stay vigilant for emerging threats.
Source: SecurityWeek — 2026-08-10