Close Menu
NCIJ Network NCIJ Network
    What's Hot

    OpenAI reportedly completed a $7 billion employee tender offer

    August 11, 2026

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    August 11, 2026

    Trump Media Plans Crypto Treasury Revamp After $238M Q2 Loss

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI reportedly completed a $7 billion employee tender offer
    • OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users
    • Trump Media Plans Crypto Treasury Revamp After $238M Q2 Loss
    • Scores dead in Colombia after powerful earthquake strikes west of country | Colombia
    • Greece’s aging power grid blamed for catastrophic wildfires – POLITICO
    • Trump Wants to Move On From the Middle East. It’s Not Letting Him.
    • This pocket-sized gadget helped cut down our editor’s screen time – and it’s on sale
    • ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers breached a small Polish energy plant via private APN last year

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year.

    The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down.

    The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network.

    image

    “The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another.”

    On December 29, 2025, an attacker believed to be linked to the Russian Electrum threat group targeted 30 wind and solar power installations and a large CHP plant in Poland, destroying key equipment beyond repair.

    The threat actor hit distributed energy resource (DER) sites across the country, disabled communications equipment, corrupted operational technology (OT) devices, and wiped Windows systems. Despite this effort to destabilize the grid, energy generation and distribution were not disrupted.

    In the newly disclosed attack at a second, smaller CHP plant, the threat actor switched off the programmable logic controllers (PLC) and protected access with a password, thus deactivating a steam turbine and the plant’s process-water treatment system and interrupting cogeneration operations.

    The staff at the plant managed to restore impacted systems quickly, so the outage was short-lived and had no impact on the population.

    Novel attack path

    Upon investigating the incident, the Polish CERT determined that the attacker initially compromised a FortiGate VPN/firewall at a wind farm and used a Teltonika cellular router on its network to tunnel into a private APN managed by the distribution system operator.

    The APN lacked client isolation, allowing the attacker to scan for and communicate with devices at other facilities.

    Beginning on December 18, the attacker found a WAGO PFC200 PLC at the CHP plant whose web interface was exposed on the APN and protected with default administrator credentials.

    After compromising the controller, the attacker enabled SSH and used it as a bridge into the plant’s OT network.

    Over the following week, they scanned the network for SCADA systems and industrial devices, and on December 25 they connected to three Siemens PLCs, likely in preparation for the attack.

    At approximately 5:30 a.m. on December 29, the attacker accessed the SCADA interface and Siemens PLCs, switching them into STOP mode, activating password protection, and shutting down the steam turbine and process-water treatment system.

    Complete attack path
    Complete attack path
    Source: CERT Polska

    The attacker also reset and reconfigured several Moxa devices to impede recovery, destroyed logs, and hindered forensic analysis by corrupting or resetting the WAGO controller, Teltonika router, and FortiGate firewall used throughout the intrusion.

    The Polish CERT believes this to be the first known real-world cyberattack in which an attacker entered an OT network by moving laterally through a private APN.

    “To the best of our knowledge, the incident described in this report, which involved gaining access to an OT network through a private APN, was the first observed instance of this attack vector being used in a real-world cyberattack,” commented CERT Polska.

    The surveys that followed the investigation determined that this configuration was common in Poland at the time, and the country’s CERT estimates that it’s likely similar arrangements are widely used internationally.

    It is recommended to treat private APNs as untrusted external networks, enable isolation between connected clients, use allowlists for essential traffic between APN gateways and OT systems, and disable exposed SSH and Telnet administration services.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    APN breached energy hackers plant Polish private small year
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    Multistate Water System Attacks Widen, Iran Suspected

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    OpenAI reportedly completed a $7 billion employee tender offer

    August 11, 2026

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    August 11, 2026

    Trump Media Plans Crypto Treasury Revamp After $238M Q2 Loss

    August 11, 2026

    Scores dead in Colombia after powerful earthquake strikes west of country | Colombia

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    OpenAI reportedly completed a $7 billion employee tender offer

    August 11, 2026

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    August 11, 2026

    Trump Media Plans Crypto Treasury Revamp After $238M Q2 Loss

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.