A Second Polish Energy Plant Compromised via Private APN, Highlighting a Novel Attack Vector
In a significant revelation, Poland’s Computer Emergency Response Team (CERT) has disclosed that a second energy plant was breached by hackers last year using an unconventional approach. The attack, which occurred on December 29, 2025, highlights the growing threat of sophisticated cyberattacks targeting operational technology (OT) networks, particularly through private Access Point Names (APNs).
The compromised facility is a small combined heat-and-power (CHP) plant that supplies heat to approximately 50,000 residents. While the attack was eventually contained and did not impact the broader energy grid, it serves as a stark reminder of the vulnerabilities in OT systems. The hackers exploited a misconfigured private APN network, which allowed them to access the facility’s operational technology (OT) devices.
The attackers’ approach involved using a dedicated mobile gateway to compromise the second facility during the destructive cyberattacks that hit Poland’s energy sector last year. They accessed the plant’s programmable logic controllers (PLC) and protected access with a password, effectively deactivating the steam turbine and process-water treatment system. This led to a short-lived outage, which was quickly restored by the plant staff.
Upon investigating the incident, the Polish CERT determined that the attacker initially compromised a FortiGate VPN/firewall at a wind farm using a Teltonika cellular router on its network. The APN lacked client isolation, allowing the attacker to scan for and communicate with devices at other facilities. They then discovered a WAGO PFC200 PLC whose web interface was exposed on the APN and protected with default administrator credentials.
The attackers’ actions demonstrate a novel attack path that has significant implications for OT security. By exploiting vulnerabilities in private APNs, hackers can potentially gain access to multiple facilities connected to the same network. The Polish CERT believes this is the first known real-world cyberattack where an attacker entered an OT network by moving laterally through a private APN.
The surveys conducted after the investigation revealed that similar configurations were common in Poland at the time and are likely widely used internationally. In light of these findings, it is essential for organizations to treat private APNs as untrusted external networks and implement robust security measures, including enabling isolation between connected clients, using allowlists for essential traffic between APN gateways and OT systems, and disabling exposed SSH and Telnet administration services.
As the cybersecurity landscape continues to evolve, it is crucial that organizations prioritize OT security and regularly test their defenses against potential threats. By doing so, they can identify vulnerabilities before attackers exploit them, ultimately preventing devastating attacks like this one from occurring in the future.
Source: Bleeping Computer — 2026-08-10