Compromised FortiGate VPN Leads to Polish Energy Sector Attack

A recent cyberattack on Poland’s energy sector has underscored the critical vulnerabilities that can arise from compromised remote-access devices. The incident, which took place on December 29, 2025, involved an attacker leveraging a compromised FortiGate VPN device to infiltrate a wind farm’s network and subsequently disrupt operations at a combined heat and power (CHP) plant.

The initial breach occurred when the attacker gained access to a perimeter device at the wind farm that functioned as both a firewall and VPN gateway. This device was internet-facing and lacked multi-factor authentication for locally defined accounts. With administrative control, the intruder obtained credentials for a VPN account that provided access to all network segments within the wind farm.

Within the wind farm’s network, the attacker identified a cellular router connected to both the wind farm and a private Access Point Name (APN)—a mobile network used by the distribution system operator for operational communications. By exploiting the router’s web console and SSH service, the attacker established a bridge into the private APN.

Through this private APN, the attacker targeted the CHP plant’s controller, which was accessible via the APN. The controller’s web administration interface was secured with default credentials, making it an easy target. After enabling SSH access, the attacker created another tunnel into the plant’s operational technology network.

Between December 18 and 25, the intruder conducted reconnaissance, scanning for remote-control and industrial services, and exploring the CHP network. The attacker attempted access to the plant’s firewall and remote desktop systems and successfully contacted three Siemens controllers, indicating a deliberate and well-planned operation.

On December 29, the attacker accessed the plant’s supervisory interface and Siemens S7 controllers, placing them in STOP mode. This action halted the steam turbine and water-treatment system, disrupting cogeneration processes. Although heat and electricity supplies to approximately 50,000 residents continued, the incident highlighted the potential for significant operational disruption.

Recovery efforts were complicated by the attacker’s actions. They reset serial-device servers and network switches, changed passwords, and altered network settings to impede restoration. Additionally, the attacker damaged the gateway controller, reset the cellular router, and restored the original perimeter device to factory settings, erasing crucial forensic evidence.

This incident serves as a stark reminder of the importance of securing remote-access devices and implementing robust authentication measures. Organizations must ensure that all network devices, especially those with internet-facing interfaces, are protected with strong, unique passwords and multi-factor authentication. Regular security audits and network segmentation can also help mitigate the risk of such attacks.