Hackers Exploit Private Cellular Network to Breach Polish Power Plant

In December 2025, a Polish combined heat and power (CHP) plant experienced a cyberattack that led to the shutdown of a steam turbine and the process-water treatment system. The facility provides heating to approximately 50,000 residents. Despite the intrusion, recovery efforts commenced around 7:30 a.m. while the attackers were still active within the network, ensuring that customers did not experience any disruption in heat or electricity supply.

The breach was facilitated through a private Access Point Name (APN), a dedicated cellular data network managed by the local distribution system operator. This network configuration permitted devices on the APN to communicate with each other, allowing the attackers to pivot from a compromised wind farm network to a controller at the CHP plant. Notably, this method of accessing an industrial control network via a private APN was unprecedented in real-world cyberattacks.

Investigations revealed that the WAGO controller accessible through the APN retained its default administrative credentials. Additionally, the private APN’s configuration permitted unrestricted client-to-client communication. These factors collectively enabled the attackers to infiltrate the system. The initial point of entry was identified as a wind farm where a FortiGate device functioned as both a firewall and VPN concentrator. The VPN was exposed to the internet and lacked multi-factor authentication, providing the attackers with administrative privileges and access to all network segments.

In response to the incident, CERT Polska recommended several measures to enhance security. These include auditing private APN configurations to enable client isolation, treating APNs as untrusted from the operational technology perspective, segmenting and restricting traffic, removing unnecessary management services from APN-reachable interfaces, and changing default credentials. Surveys indicated that many Polish organizations operating private APNs allow unrestricted device communication, a practice likely prevalent in other countries as well.

This incident underscores the critical need for robust security measures in industrial control systems, especially concerning private cellular networks. Organizations must reassess their network configurations, implement stringent access controls, and regularly update credentials to mitigate potential cyber threats. The attack also highlights the evolving tactics of cyber adversaries, emphasizing the importance of proactive defense strategies in safeguarding critical infrastructure.