<- ALL CYBER NEWS

High

ICS, OT, Critical Infrastructure, Power Plant, APN, CERT Polska, SCADA

Polish Power Plant Hacked via Private Cellular APN

A Polish power plant cyberattack shut a turbine by pivoting over a shared private cellular APN, per CERT Polska. How it happened and OT defenses.

Polish Power Plant Cyberattack Shut a Turbine via a Private Cellular APN

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. CERT Polska, which disclosed the December 2025 incident on August 8, 2026 after a three-month investigation, says the intruders pivoted from a compromised wind-farm network to a controller at the plant because the private APN let arbitrary devices on it talk to one another. It is, to CERT's knowledge, the first real-world attack to reach an industrial control network through a private cellular APN. The plant supplies heat to roughly 50,000 residents, who lost neither heat nor power.

The route is the whole story. An APN, or access point name, is a dedicated cellular data network a distribution system operator uses to manage geographically scattered equipment. In this case the APN was configured so that any device attached to it could communicate with any other, which meant a foothold on one facility's cellular-connected gear opened a path to another's. The wind farm and the CHP plant are separate operations run by different parties, and neither of them owns the network that connected them, so the shared APN quietly became a bridge between an intermittent renewable site and base-load generation. Recovery began around 7:30 a.m. while the attackers were still inside.

CERT was careful about attribution and cause. The report does not pin the intrusion on a specific CVE, and investigators could not confirm whether a vulnerability in the Teltonika cellular router involved was exploited, so there is no single flaw to patch here. Poland's prime minister had said in January that two CHP plants were hit; this is the second. That framing matters, because the lesson is architectural rather than a one-off bug: a flat, trusted transport layer under the control system was the real weakness.

How did attackers reach the plant's control system?

By abusing shared connectivity, not a known software flaw. The attacker compromised a wind-farm network first, then used the permissive private APN, where client-to-client traffic was allowed, to reach a controller inside the CHP plant. Because the cellular network treated every attached device as a peer, segmentation that operators assume exists at the carrier layer simply was not there. No exploit of the plant's own controllers was needed; the transport did the pivoting.

How should OT operators defend a private cellular network?

Stop trusting the APN as an inherently private, segmented medium. Ask your carrier to enforce intra-APN blocking so devices cannot talk peer-to-peer and are restricted to the central SCADA gateway through APN ACLs or carrier firewalling. Wrap control traffic in an authenticated IPsec or WireGuard overlay so raw protocols are never exposed on the cellular link. Harden the edge routers by disabling management interfaces (web UI, SSH, TR-069) on cellular and WAN sides and isolating them in an out-of-band management VLAN rather than bridging them into the PLC network. And verify that third-party renewable assets do not share a segment or APN with base-load generation.

Detail

Value

Target

Polish combined heat and power (CHP) plant

Impact

Steam turbine and water-treatment system shut down

Route

Compromised wind farm to plant controller over a shared private APN

Novelty

First observed real-world ICS breach via a private cellular APN

Cause

Permissive APN allowing client-to-client traffic (no CVE confirmed)

Disclosure

CERT Polska, Aug 8, 2026 (Dec 2025 incident)

Residents served

~50,000 (no loss of heat or power)

Our read

Continuous verification is the whole lesson of a breach that used no exploit at all. The attackers did not defeat the plant's controllers; they walked in over a transport layer everyone assumed was private and segmented, and no one had verified that assumption. Our position on critical infrastructure has been consistent: the exposure that gets you is rarely the flashy zero-day, it is the trusted connection nobody was checking. Treat every shared network, including a carrier-managed APN, as untrusted until proven otherwise, segment control traffic explicitly rather than relying on the medium, and verify continuously that a foothold in one facility cannot become a foothold in another.

Reporting by The Hacker News, citing CERT Polska. Sources linked above.

Related: Cisco ASA/FTD CVE-2026-20349 exploited for remote DoS · Progress Kemp LoadMaster CVE-2026-8037 in CISA KEV

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.