Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Infostealers Harvest 1.7 Billion Credentials in Six Months

August 17, 2026

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

August 17, 2026

ETSI Proposes 17 Cybersecurity Standards to Support EU CRA

August 17, 2026
Facebook X (Twitter) Instagram
Monday, August 17
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
News

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Team-CWDBy Team-CWDAugust 17, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.

The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat nor electricity.

CERT Polska disclosed the December 2025 incident on August 8 after an investigation lasting more than three months. Poland’s prime minister had said in January that two CHP plants were hit. This is the second.

The route ran through a private APN, or access point name: a dedicated cellular data network managed by the distribution system operator. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant.

CERT says reaching an industrial control network through a private APN was, to the best of its knowledge, “the first instance of this attack vector being observed in a real-world cyberattack.” The wind farm and the plant are separate facilities, and neither of them runs the network that linked them.

The report does not establish a CVE as the cause of the intrusion, and investigators could not determine whether a vulnerability in the Teltonika router had been exploited, so there is no single software patch to apply.

The WAGO controller reachable through the APN still had default admin credentials, while the private APN allowed client-to-client traffic. CERT’s first recommendation is to audit the private APN configuration and switch on client isolation.

It also advises treating the APN as untrusted from the operational technology (OT) side, segmenting and restricting traffic, removing unnecessary management services from APN-reachable interfaces, and changing default credentials.

CERT says its surveys found that Polish organizations running private APNs commonly let any device on the network reach any other. It believes similar configurations are widely deployed in other countries. The router’s SSH service, the controller’s web interface and the permissive APN were all working as configured.

The attack path began at a wind farm, where a FortiGate device served as both firewall and VPN concentrator. Its VPN was exposed to the internet and allowed accounts without multi-factor authentication. The attacker had administrative privileges on the device and likely used them to obtain VPN credentials that could reach all network segments.

The distribution operator required communications to the substation’s remote terminal unit to run over the serial DNP3.0 protocol, and that requirement was met. But no equivalent requirements covered the cellular router’s management interface, which sat on a second interface, an Ethernet port connected to a VLAN behind the compromised firewall.

The wind farm met the DNP3.0 requirement it had been given and still supplied the route in. That requirement governed how data travelled, not how the device carrying it was administered.

The router was a Teltonika RUTX50 whose default password had been changed during deployment. Investigators recovered repeated successful SSH logins but could not establish how the attacker obtained that password.

As of August 11, The Hacker News reviewed the published vulnerabilities in the router’s own firmware and found none that would hand an unauthenticated attacker its password. The two RUT-series flaws in CISA’s 2023 Teltonika advisory, CVE-2023-32349 and CVE-2023-32350, both require existing privileges on the device, and the RUTX50’s modem flaws cause only denial of service. An unpublished flaw is not ruled out.

Mobile-operator logs led CERT to assess that the attacker most likely used SSH tunneling through the router to reach the private APN. Starting December 18, the attacker scanned the APN and found a WAGO PFC200 controller exposing its web administration interface with default admin credentials. Subsequent SSH activity suggests the service was likely enabled through that interface, and timestamp correlation led CERT to assess that the attacker most likely tunneled through the WAGO into the plant’s OT network.

On December 25, the attacker successfully connected to three Siemens PLCs over the S7 protocol, activity CERT considers most likely to have been reconnaissance for the later destructive actions.

On December 29, attacker activity inside the CHP network ran from about 5:30 a.m. until about 10:10 a.m., with plant recovery beginning at about 7:30 a.m. According to plant personnel, Siemens S7-300, S7-1200, and S7-1500 controllers were switched to STOP mode and password-protected, shutting down the turbine and the process-water treatment system and interrupting cogeneration.

Seven Moxa serial device servers and three switches were also factory-reset, given changed passwords and assigned unreachable IP addresses such as 127.0.0.1. CERT says the timing indicates with a high degree of confidence that those actions were automated. None of it required malware, and the report describes none.

Every destructive step used a supported device function, invoked over the protocols the plant runs on.

The attacker then damaged the way in. The WAGO controller’s partition table was corrupted, leaving it unable to boot and yielding no useful logs. About 30 minutes after the last observed activity at the CHP plant, the attacker factory-reset the Teltonika router, changed its administrator password and assigned it the unreachable address 127.0.0.1, then factory-reset the FortiGate, causing its logs to be lost.

CERT says RutOS versions earlier than 7.07 retained their event database after a factory reset, which is why the SSH login records survived.

The plant did not initially read it as an attack. Maintenance was underway, so the operator logged the interruption as probable contractor error and reported it for information only; CERT opened an incident because it already knew of similar events. Reconnaissance inside the plant’s network had run from December 18 to 25, including a port scan that started at the SCADA system’s address.

No actor is named for this incident. The wider December campaign drew four separate assessments in January, from Poland’s government, CERT Polska, ESET, and Dragos. Each is scoped differently, to the campaign’s preparation, its infrastructure, the wiper malware used against its other targets, and its broader shape. None of them addresses this intrusion.

Private APNs still appear in federal guidance as an isolation option. A July 30 FBI and EPA advisory on attacks against internet-facing water-sector PLCs lists a private APN among the isolated architectures operators should consider for reaching OT equipment over cellular links.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleETSI Proposes 17 Cybersecurity Standards to Support EU CRA
Next Article Infostealers Harvest 1.7 Billion Credentials in Six Months
Team-CWD
  • Website

Related Posts

News

Infostealers Harvest 1.7 Billion Credentials in Six Months

August 17, 2026
News

ETSI Proposes 17 Cybersecurity Standards to Support EU CRA

August 17, 2026
News

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

August 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

AI-powered financial scams swamp social media

September 11, 2025

Don’t let “back to school” become “back to bullying”

September 11, 2025

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.