A Second Polish Energy Plant Falls Victim to Sophisticated Cyber Attackers, Exposing a Novel Attack Path
Last year’s devastating cyber attacks on Poland’s energy sector have revealed an alarming new threat vector. A small combined heat-and-power (CHP) plant in Poland was compromised by hackers who exploited a private Access Point Name (APN) network, demonstrating a previously unseen attack path.
The attackers, believed to be linked to the Russian Electrum threat group, had already targeted 30 wind and solar power installations and a large CHP plant on December 29, 2025. However, in this second incident, they focused on a smaller CHP plant that supplies heat to around 50,000 residents. The breach resulted in the shutdown of the steam turbine and the water treatment system, but fortunately, the outage was short-lived, and the staff managed to restore impacted systems quickly.
Investigation by the Polish Computer Emergency Response Team (CERT) revealed that the attackers initially compromised a FortiGate VPN/firewall at a wind farm using a Teltonika cellular router on its network. The private APN, managed by the distribution system operator, lacked client isolation, allowing the attacker to scan for and communicate with devices at other facilities.
The attackers then exploited a WAGO PFC200 Programmable Logic Controller (PLC) whose web interface was exposed on the APN and protected with default administrator credentials. After compromising the controller, they enabled SSH and used it as a bridge into the plant’s Operational Technology (OT) network. Over the following week, they scanned the network for SCADA systems and industrial devices, before connecting to three Siemens PLCs on December 25.
The attackers finally accessed the SCADA interface and Siemens PLCs on December 29, switching them into STOP mode, activating password protection, and shutting down critical systems. They also reset and reconfigured several Moxa devices to impede recovery, destroyed logs, and hindered forensic analysis by corrupting or resetting key systems.
The Polish CERT believes this incident is the first known real-world cyber attack in which an attacker entered an OT network by moving laterally through a private APN. The surveys that followed the investigation suggest that similar configurations are common in Poland and likely internationally, highlighting a critical vulnerability.
To mitigate this risk, it’s essential to treat private APNs as untrusted external networks, enable isolation between connected clients, use allowlists for essential traffic between APN gateways and OT systems, and disable exposed SSH and Telnet administration services. By taking these precautions, organizations can significantly reduce the likelihood of such attacks.
As the cybersecurity landscape continues to evolve, it’s crucial that security teams prioritize testing every layer of their defenses before attackers do. The risk of missing critical vulnerabilities is too great to ignore, and the consequences of a successful attack can be devastating.
Source: Bleeping Computer — 2026-08-10