<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5" -->

---
title: Hackers breached a small Polish energy plant via private...
description: Polish CERT disclosed a second cyberattack on Poland&#x27;s energy sector, targeting a small combined heat-and-power plant supplying heat to ~50,000 residents. The...
canonical: https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers breached a small Polish energy plant via private APN last year | daily.dev
og:description: Polish CERT disclosed a second cyberattack on Poland&#x27;s energy sector, targeting a small combined heat-and-power plant supplying heat to ~50,000 residents. The...
og:url: https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5
og:image: https://api.daily.dev/og/posts/LPc204fs5.png
og:image:alt: Hackers breached a small Polish energy plant via private APN last year
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers breached a small Polish energy plant via private APN last year

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

Polish CERT disclosed a second cyberattack on Poland's energy sector, targeting a small combined heat-and-power plant supplying heat to ~50,000 residents. The attacker, believed to be linked to the Russian Electrum threat group, used a novel attack path: compromising a FortiGate VPN at a wind farm, then pivoting through a Teltonika cellular router into a private APN (Access Point Name) that lacked client isolation. From there, they found a WAGO PFC200 PLC with default credentials, enabled SSH, and spent days mapping the OT network before striking on December 29, 2025. The attack shut down a steam turbine and water treatment system by putting Siemens PLCs into STOP mode and locking them with passwords. The attacker also destroyed logs and reset devices to hinder forensics. CERT Polska calls this the first known real-world cyberattack using lateral movement through a private APN to reach an OT network, and warns that similar APN misconfigurations are likely widespread internationally. Recommended mitigations include treating private APNs as untrusted networks, enabling client isolation, and using allowlists for APN-to-OT traffic.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year>

## Questions this post answers

### How did attackers use a private APN to breach an OT network in the Polish energy plant attack?

Attackers first compromised a FortiGate VPN/firewall at a wind farm, then used a Teltonika cellular router on that network to tunnel into a private APN managed by the distribution system operator. Because the APN lacked client isolation, they could scan and communicate with devices at other facilities. They found a WAGO PFC200 PLC with default credentials, enabled SSH, and used it as a bridge into the CHP plant's OT network.

_Teams securing OT environments against lateral movement through shared network infrastructure track emerging attack vectors on daily.dev._

### What is the significance of the Polish CHP plant cyberattack in terms of OT security attack vectors?

CERT Polska assessed this as the first known real-world cyberattack where an attacker entered an OT network by moving laterally through a private APN. The APN lacked client isolation, allowing the attacker to reach a WAGO PLC with default credentials at a separate facility. CERT Polska also noted that similar APN misconfigurations are likely common internationally, making this a broadly relevant threat model.

_ICS security engineers evaluating APN exposure in their own environments can follow related disclosures on daily.dev._

### What mitigations does CERT Polska recommend for private APN security in OT environments?

CERT Polska recommends treating private APNs as untrusted external networks rather than trusted internal ones, enabling isolation between connected APN clients, using allowlists to restrict traffic between APN gateways and OT systems, and disabling exposed SSH and Telnet administration services on OT devices. The WAGO PFC200 PLC in this incident was reachable via its web interface and protected only by default administrator credentials.

_Practitioners hardening industrial network perimeters against this class of misconfiguration find peer discussions on daily.dev._

## Similar posts on daily.dev

- [Critical infrastructure’s long, undefended tail exposed by UK energy attack](https://daily.dev/posts/critical-infrastructure-s-long-undefended-tail-exposed-by-uk-energy-attack-hajfwhwyk) · CSO Online · 0 upvotes · 0 comments
- [Poland Energy Survives Attack on Wind, Solar Infrastructure](https://daily.dev/posts/poland-energy-survives-attack-on-wind-solar-infrastructure-mtx8cxkdw) · Dark Reading · 0 upvotes · 0 comments

---

[View this post on daily.dev](https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers breached a small Polish energy plant via private APN last year","url":"https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5"},"datePublished":"2026-08-10T23:09:25.995Z","dateModified":"2026-08-13T00:23:13.278Z","description":"Polish CERT disclosed a second cyberattack on Poland's energy sector, targeting a small combined heat-and-power plant supplying heat to ~50,000 residents. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3ee33a5e4bee17965255190b5594b24f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3ee33a5e4bee17965255190b5594b24f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Hackers breached a small Polish energy plant via private APN last year"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year-lpc204fs5#faq","mainEntity":[{"@type":"Question","name":"How did attackers use a private APN to breach an OT network in the Polish energy plant attack?","acceptedAnswer":{"@type":"Answer","text":"Attackers first compromised a FortiGate VPN/firewall at a wind farm, then used a Teltonika cellular router on that network to tunnel into a private APN managed by the distribution system operator. Because the APN lacked client isolation, they could scan and communicate with devices at other facilities. They found a WAGO PFC200 PLC with default credentials, enabled SSH, and used it as a bridge into the CHP plant's OT network. Teams securing OT environments against lateral movement through shared network infrastructure track emerging attack vectors on daily.dev."}},{"@type":"Question","name":"What is the significance of the Polish CHP plant cyberattack in terms of OT security attack vectors?","acceptedAnswer":{"@type":"Answer","text":"CERT Polska assessed this as the first known real-world cyberattack where an attacker entered an OT network by moving laterally through a private APN. The APN lacked client isolation, allowing the attacker to reach a WAGO PLC with default credentials at a separate facility. CERT Polska also noted that similar APN misconfigurations are likely common internationally, making this a broadly relevant threat model. ICS security engineers evaluating APN exposure in their own environments can follow related disclosures on daily.dev."}},{"@type":"Question","name":"What mitigations does CERT Polska recommend for private APN security in OT environments?","acceptedAnswer":{"@type":"Answer","text":"CERT Polska recommends treating private APNs as untrusted external networks rather than trusted internal ones, enabling isolation between connected APN clients, using allowlists to restrict traffic between APN gateways and OT systems, and disabling exposed SSH and Telnet administration services on OT devices. The WAGO PFC200 PLC in this incident was reachable via its web interface and protected only by default administrator credentials. Practitioners hardening industrial network perimeters against this class of misconfiguration find peer discussions on daily.dev."}}]}
```

