Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

A devastating cyberattack on a Polish power plant has left industry experts reeling, as hackers exploited a private cellular network to gain control of critical systems and shut down a turbine. The attack, which occurred in late July 2026, raises serious concerns about the vulnerability of industrial control systems (ICS) and highlights the need for greater investment in cybersecurity measures.

The Polish power plant, located in the city of Krakow, was connected to a private cellular network that allowed operators to monitor and control equipment remotely. However, an investigation by CyberNews.work has revealed that hackers gained unauthorized access to this network, using it as a springboard to infiltrate the plant’s ICS. The attackers exploited vulnerabilities in the cellular network’s configuration, allowing them to bypass security controls and gain unrestricted access to the system.

Once inside the ICS, the hackers used their newfound control to shut down one of the plant’s turbines, causing significant disruptions to power generation and supply. The attack is believed to have been carried out by a sophisticated group of attackers, with ties to Eastern Europe. While the exact motivations behind the attack are still unclear, it is thought that the hackers may have been seeking to test their capabilities or disrupt energy supplies for financial gain.

The breach highlights serious concerns about the vulnerability of ICS to cyber threats. Industrial control systems, which manage and monitor critical infrastructure such as power plants, water treatment facilities, and transportation networks, are increasingly connected to private cellular networks and other digital systems. This creates a potential entry point for hackers, who can use their skills and resources to exploit vulnerabilities in these systems.

The attack also underscores the importance of effective cybersecurity measures in protecting ICS from cyber threats. While the plant’s operators had implemented some security controls, it appears that these were insufficient to prevent the breach. Industry experts are now calling for greater investment in cybersecurity measures, including robust threat detection and incident response capabilities, as well as regular penetration testing and vulnerability assessments.

For individuals working with industrial control systems, this attack serves as a stark reminder of the need for vigilance and proactive security measures. By understanding the potential vulnerabilities of ICS and taking steps to mitigate these risks, organizations can reduce their exposure to cyber threats and ensure the continued reliability and safety of critical infrastructure. As we move forward in an increasingly interconnected world, it is essential that industry leaders prioritize cybersecurity and invest in robust measures to protect against future attacks.


Source: The Hacker News — 2026-08-11