"According to statements provided by CHP plant personnel, the PLCs were switched to STOP mode and protected with a password that prevented changes to their operating state and modification of the control logic," the Polish CERT (CERT.PL) reported — describing how attackers forced a combined heat and power (CHP) plant into a controlled shutdown during a late‑December 2025 campaign.
Compromise began at a wind farm FortiGate VPN and firewall
CERT.PL’s post‑mortem, completed three months after the incident, says the intrusion sequence began with the compromise of a FortiGate VPN + firewall at a wind farm in Poland. From there, the adversaries pivoted into cellular networking equipment on the same network — a Teltonika cellular router — and used that router to build an SSH tunnel targeting a private Access Point Name (APN) managed by a distribution system operator (DSO).
The incident was investigated as part of a wider suspected Russian cyber campaign in December 2025 that CERT.PL had previously linked to Sandworm; initial reporting on that campaign in January 2026 did not include this attack because the post‑mortem took longer to complete.
Private APN access: the first documented case of OT compromise via APN
CERT.PL describes this as the first known documented case in which threat actors accessed an operational technology (OT) network through a private APN. The attackers repeatedly scanned the APN and discovered a WAGO PFC200 programmable logic controller (PLC) at the CHP plant whose web interface was reachable over the APN and — crucially — protected only by default administrative credentials.
After compromising the WAGO controller, the actors used SSH access into the plant’s OT network and then located three Siemens PLCs. That lateral movement across OT gear was possible because the APN did not provide effective client isolation and the gateway device exposed interfaces with multiple OT targets.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSteam turbine and water treatment systems forced offline; outage brief and non‑customer affecting
CERT.PL reports the attackers switched the Siemens PLCs into STOP mode and set passwords that prevented state changes and control‑logic modifications. The direct operational consequence was the shutdown of a steam turbine and the plant’s water treatment system — systems required for the cogeneration process that provides heat and electricity.
The CHP plant serves approximately 50,000 residents. CERT.PL notes the outage was short and did not cause customer power loss in this instance, but it occurred amid a larger assault that targeted 30 Polish renewable energy facilities and another large CHP plant on December 29 and 30, 2025.
Sabotage to slow recovery: Moxa, WAGO, Teltonika and FortiGate damaged or reset
As part of efforts to impede remediation, the attackers sabotaged multiple components: several Moxa network devices were damaged, the WAGO controller was rendered inoperable, logs were destroyed, the Teltonika router was reset, and the FortiGate device was restored to factory defaults. Those destructive actions complicated incident response and hampered forensic tracing.
What this means for DSOs, CHP plant operators, and security teams
- Distribution system operators (DSOs) managing private APNs are urged to audit APN configurations, enable client isolation, and treat private APNs as untrusted networks — in other words, reduce direct reachable paths from APNs into OT networks.
- CHP plant operators should review exposed device interfaces and remove default credentials from devices such as WAGO PFC200 controllers, and minimize the number of open ports reachable via APN‑accessible interfaces.
- Security teams and incident responders must centralize logging and monitoring for gateway devices, strictly limit communications between OT networks and APN gateways, include APNs in penetration tests and red team exercises, and monitor APN traffic to flag abnormal scanning or SSH tunnelling activity.
Recommendations from CERT.PL and a closing observation
CERT.PL’s formal recommendations mirror the technical path the attackers used: audit private APN configurations and client isolation; segment APNs from OT; strictly limit and monitor gateway communications; centralize logging for gateway devices; reduce open ports; change default credentials; and include APN‑exposed devices in penetration testing and security architecture reviews.
This case is notable for two specific facts CERT.PL highlights: it documents a novel access vector — a private APN used to reach OT equipment — and it occurred during a concentrated campaign on December 29–30, 2025, linked by CERT.PL to Sandworm and affecting dozens of energy facilities. Those two facts together make the advisory more than a postmortem of a single plant: it is a practical warning about a pathway now demonstrated in the wild and a prompt for DSOs and plant operators to reassess how cellular networks and APNs are connected to critical control systems.
Original reporting: https://www.infosecurity-magazine.com/news/attack-polish-power-plant-2025-led/




