Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Wildfire ravages Indonesia’s Bromo Tengger Semeru National Park

    August 11, 2026

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Wildfire ravages Indonesia’s Bromo Tengger Semeru National Park
    • Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty
    • What We Know About the Earthquake in Colombia
    • A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington
    • Maga ignores the many meanings of Mount Rushmore
    • Why recovery readiness has become the new standard for cyber resilience
    • webAI Releases TwIL-LM: A 1.7B and 3B Formal-Logic Model Family for Autoformalization on Local Hardware
    • Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.

    The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat nor electricity.

    CERT Polska disclosed the December 2025 incident on August 8 after an investigation lasting more than three months. Poland’s prime minister had said in January that two CHP plants were hit. This is the second.

    The route ran through a private APN, or access point name: a dedicated cellular data network managed by the distribution system operator. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant.

    CERT says reaching an industrial control network through a private APN was, to the best of its knowledge, “the first instance of this attack vector being observed in a real-world cyberattack.” The wind farm and the plant are separate facilities, and neither of them runs the network that linked them.

    Cybersecurity

    The report does not establish a CVE as the cause of the intrusion, and investigators could not determine whether a vulnerability in the Teltonika router had been exploited, so there is no single software patch to apply.

    The WAGO controller reachable through the APN still had default admin credentials, while the private APN allowed client-to-client traffic. CERT’s first recommendation is to audit the private APN configuration and switch on client isolation.

    It also advises treating the APN as untrusted from the operational technology (OT) side, segmenting and restricting traffic, removing unnecessary management services from APN-reachable interfaces, and changing default credentials.

    CERT says its surveys found that Polish organizations running private APNs commonly let any device on the network reach any other. It believes similar configurations are widely deployed in other countries. The router’s SSH service, the controller’s web interface and the permissive APN were all working as configured.

    The attack path began at a wind farm, where a FortiGate device served as both firewall and VPN concentrator. Its VPN was exposed to the internet and allowed accounts without multi-factor authentication. The attacker had administrative privileges on the device and likely used them to obtain VPN credentials that could reach all network segments.

    The distribution operator required communications to the substation’s remote terminal unit to run over the serial DNP3.0 protocol, and that requirement was met. But no equivalent requirements covered the cellular router’s management interface, which sat on a second interface, an Ethernet port connected to a VLAN behind the compromised firewall.

    The wind farm met the DNP3.0 requirement it had been given and still supplied the route in. That requirement governed how data travelled, not how the device carrying it was administered.

    The router was a Teltonika RUTX50 whose default password had been changed during deployment. Investigators recovered repeated successful SSH logins but could not establish how the attacker obtained that password.

    As of August 11, The Hacker News reviewed the published vulnerabilities in the router’s own firmware and found none that would hand an unauthenticated attacker its password. The two RUT-series flaws in CISA’s 2023 Teltonika advisory, CVE-2023-32349 and CVE-2023-32350, both require existing privileges on the device, and the RUTX50’s modem flaws cause only denial of service. An unpublished flaw is not ruled out.

    Mobile-operator logs led CERT to assess that the attacker most likely used SSH tunneling through the router to reach the private APN. Starting December 18, the attacker scanned the APN and found a WAGO PFC200 controller exposing its web administration interface with default admin credentials. Subsequent SSH activity suggests the service was likely enabled through that interface, and timestamp correlation led CERT to assess that the attacker most likely tunneled through the WAGO into the plant’s OT network.

    Cybersecurity

    On December 25, the attacker successfully connected to three Siemens PLCs over the S7 protocol, activity CERT considers most likely to have been reconnaissance for the later destructive actions.

    On December 29, attacker activity inside the CHP network ran from about 5:30 a.m. until about 10:10 a.m., with plant recovery beginning at about 7:30 a.m. According to plant personnel, Siemens S7-300, S7-1200, and S7-1500 controllers were switched to STOP mode and password-protected, shutting down the turbine and the process-water treatment system and interrupting cogeneration.

    Seven Moxa serial device servers and three switches were also factory-reset, given changed passwords and assigned unreachable IP addresses such as 127.0.0.1. CERT says the timing indicates with a high degree of confidence that those actions were automated. None of it required malware, and the report describes none.

    Every destructive step used a supported device function, invoked over the protocols the plant runs on.

    The attacker then damaged the way in. The WAGO controller’s partition table was corrupted, leaving it unable to boot and yielding no useful logs. About 30 minutes after the last observed activity at the CHP plant, the attacker factory-reset the Teltonika router, changed its administrator password and assigned it the unreachable address 127.0.0.1, then factory-reset the FortiGate, causing its logs to be lost.

    CERT says RutOS versions earlier than 7.07 retained their event database after a factory reset, which is why the SSH login records survived.

    The plant did not initially read it as an attack. Maintenance was underway, so the operator logged the interruption as probable contractor error and reported it for information only; CERT opened an incident because it already knew of similar events. Reconnaissance inside the plant’s network had run from December 18 to 25, including a port scan that started at the SCADA system’s address.

    No actor is named for this incident. The wider December campaign drew four separate assessments in January, from Poland’s government, CERT Polska, ESET, and Dragos. Each is scoped differently, to the campaign’s preparation, its infrastructure, the wiper malware used against its other targets, and its broader shape. None of them addresses this intrusion.

    Private APNs still appear in federal guidance as an isolation option. A July 30 FBI and EPA advisory on attacks against internet-facing water-sector PLCs lists a private APN among the isolated architectures operators should consider for reaching OT equipment over cellular links.

    breach Cellular controls hackers Network plant Polish power private Shut turbine
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Mozilla Issues New Firefox GPG Key Following Exposure

    New Jersey, Alabama Join States Targeted in Water Cyberattacks

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    Greece’s aging power grid blamed for catastrophic wildfires – POLITICO

    ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    Hackers breached a small Polish energy plant via private APN last year

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Wildfire ravages Indonesia’s Bromo Tengger Semeru National Park

    August 11, 2026

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026

    A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Wildfire ravages Indonesia’s Bromo Tengger Semeru National Park

    August 11, 2026

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.