Hackers Breach Polish Plant via Private Mobile Network, Halting Cogeneration
Cyber attackers infiltrated a Polish combined heat and power plant by exploiting a private cellular network, temporarily disrupting heat and electricity generation. The breach, which occurred on December 29, 2025, revealed a novel attack vector targeting operational technology systems.
Key takeaways
- Hackers breached a Polish CHP plant on December 29, 2025, using a private cellular network.
- The attack temporarily halted heat and electricity generation, impacting 50,000 residents.
- Attackers moved from a wind farm, through a distribution operator's APN, into the plant's operational technology.
- The breach utilized default credentials and exploited the trusted nature of private networks.
- The incident was part of a wider campaign against Poland's energy infrastructure.
What Happened
Hackers successfully penetrated a Polish combined heat and power (CHP) plant by leveraging a private cellular network, a route previously considered secure. The intrusion led to the manipulation of industrial controllers and a temporary cessation of cogeneration, impacting a facility that provides heating for approximately 50,000 residents. The incident occurred on December 29, 2025, as part of a wider cyber campaign targeting Poland's energy infrastructure.
Investigators determined that the attackers first compromised an internet-facing device at a wind farm before moving into a private access point name (APN) network utilized by a distribution system operator. This network served as a conduit into the separate CHP plant's operational technology environment. The attack resulted in the shutdown of a steam turbine and a process-water treatment system, thereby interrupting the plant's capacity to produce both electricity and heat simultaneously.
Plant operators were able to restore operations swiftly, preventing a loss of heating services for consumers and limiting the outage to a brief period. The breach is noteworthy because the private APN, commonly used to connect remote industrial equipment without direct public internet exposure, was believed to be a trusted communication channel. The configuration allowed connected devices to communicate with each other, facilitating the attackers' lateral movement between different facilities.
Key Facts
- Hackers breached a Polish combined heat and power plant on December 29, 2025.
- The attack temporarily halted cogeneration, affecting heat supply to about 50,000 residents.
- Attackers entered through a private cellular network (APN) after compromising a wind farm.
- The intrusion manipulated industrial controllers, including Siemens and WAGO devices.
- The attackers disabled a steam turbine and a process-water treatment system.
- Operators restored operations before consumers lost heating services.
- The attackers used default credentials on a WAGO controller and later created an SSH tunnel.
- Reconnaissance within the APN began by December 18, 2025.
- The attackers attempted to hinder recovery and erase forensic evidence.
- The incident was part of a broader campaign targeting Poland's energy infrastructure.
- Over 30 wind and photovoltaic installations were also affected by coordinated destructive activity on December 29, 2025.
Background
The attackers' methodology involved compromising an internet-exposed FortiGate device at a wind farm. Subsequently, they accessed a Teltonika RUTX50 cellular router connected to the distribution operator’s private APN. The precise method for acquiring the router's credentials remains undetermined. Initial reconnaissance within the APN, starting around December 18, involved scanning for services like VNC and HTTP, as well as industrial protocols such as Siemens S7 and Modbus. They identified a WAGO PFC200 controller at the CHP facility accessible via the APN, which was still using default administrative credentials.
Gaining control of the WAGO device allowed attackers to enable SSH access and use it as a secondary tunnelling point into the CHP plant's internal industrial network. This compromised controller had connections to SCADA systems and network segments critical for plant operations. For approximately one week, the intruders explored the CHP environment, attempting to access administrative interfaces, remote access services, and industrial equipment. By December 25, they had established communication with three Siemens programmable logic controllers (PLCs), indicating preparations for disruptive actions. At approximately 5:30 AM on December 29, the attackers connected to Siemens S7-300, S7-1200, and S7-1500 PLCs within the facility. These controllers were switched to a STOP mode, and password protections were applied to impede operator intervention.
In addition to affecting the turbine and process-water systems, other industrial devices were targeted. Moxa serial device servers and network switches were reset or reconfigured. Systems associated with ABB and Schneider Electric equipment were also examined. Evidence suggests the attackers sought to complicate recovery efforts and obscure their presence. The gateway devices used in the intrusion were damaged or reset, and the WAGO controller was subjected to partition table corruption, preventing normal booting and hindering forensic analysis. Interference with the wind farm infrastructure also occurred after operations at the CHP plant concluded.
Story by Project Chintan
Related stories
Valve Warns Steam Users of Data Breach via Logistics Partner
Compromised LiteLLM Package Highlights AI Software Supply Chain Vulnerabilities
OpenAI Restricts New AI Model 'Astra' Amid Escalating Cyber Risk Concerns

