Hackers used private APN to disable Polish CHP plant

In December 2025 attackers used a private APN pivot to reach a combined heat and power plant, stopping a steam turbine and a water treatment system without cutting heat or power.
Poland’s computer emergency response team reported that in December 2025 attackers used a private APN pivot to access a combined heat and power (CHP) plant serving roughly 50,000 residents. The intruders stopped a steam turbine and a water treatment system; heat and electricity supply to the local population were not interrupted.
CERT.PL said the disruption occurred during maintenance and was initially treated as an engineering error before investigators identified deliberate activity. The report places the incident alongside a larger December campaign that targeted communications and control systems at about 30 energy sites.
According to the report, the attackers first accessed an internet-facing Fortinet VPN and firewall at a wind farm. From that device they discovered a Teltonika cellular router on the same network and logged into its administration interface. An SSH service on the router was used to establish a tunnel into a private APN managed by the regional distribution system operator. Private APNs connect a DSO’s SCADA system to industrial control equipment at substations.
Once on the private APN the intruders scanned for devices and located a WAGO programmable logic controller at the CHP plant. An enabled SSH service on that controller provided entry to the plant’s operational technology network. Over about a week of reconnaissance the attackers connected to Siemens PLCs, switched them to stop mode and set passwords that prevented operators from changing controller states or logic.
Those actions halted the plant’s steam turbine and water treatment operations and disrupted the cogeneration process. Plant staff limited downtime by resetting affected PLCs to factory settings and reloading control logic from backups, restoring systems and maintaining heat and power delivery to residents.
The attackers also targeted Moxa serial device servers and Moxa network switches, reconfiguring them to block legitimate operator access. ABB and Schneider Electric variable frequency drives were probed, but some connection attempts failed and the specific impact on those drives remains unclear. Investigators found that some ICS devices were permanently damaged. The report states: ‘The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot. No valuable logs could be recovered from the device during the investigation.’
Polish authorities linked the larger parallel campaign to the Russian government-associated group Sandworm and described that operation as purely destructive. CERT.PL warned that exposed management interfaces on routers and controllers combined with private APN access paths are common in Poland and other countries, and highlighted that internet-facing office and edge devices can be used to reach isolated OT networks through trusted communication links like private APNs.








