Poland's national computer emergency response team has revealed that Russian-backed hackers forced a steam turbine and water treatment system offline at a combined heat and power plant serving 50,000 residents during a December 2025 cyber campaign. CERT.PL published the findings in a detailed post-mortem report that took three months to complete, making it too late for inclusion in an earlier January 2026 summary of attacks on the country's energy infrastructure. The agency says this marks the first documented instance of threat actors breaching an operational technology network through a private Access Point Name, a cellular network gateway typically considered secure.

The intrusion began when adversaries compromised a FortiGate VPN and firewall protecting a wind farm, then leveraged a Teltonika cellular router on the same network to tunnel into a private APN managed by a distribution system operator. After repeatedly scanning the APN, the attackers located a WAGO PFC200 programmable logic controller at the combined heat and power facility, which was accessible through the APN's web interface and protected only by factory-set administrator passwords. Once inside that controller, the threat actors used SSH to penetrate the plant's operational technology network and discovered three Siemens programmable logic controllers. Plant staff reported that the attackers switched the controllers to STOP mode and locked them with passwords that prevented any changes to their operating state or control logic, causing the steam turbine and water treatment system to shut down and halting the cogeneration process.

To delay restoration efforts, the hackers sabotaged multiple Moxa network devices, wiped logs, damaged the WAGO controller, reset the Teltonika router, and restored the FortiGate device to its original factory configuration. The attack occurred on December 29 or 30, 2025, as part of a broader Russian campaign linked to the Sandworm advanced persistent threat group that targeted 30 Polish renewable energy facilities and another large combined heat and power plant during the same two-day period. CERT.PL urges organizations using private APN solutions to audit their configurations, enable client isolation between devices, and treat the private APN as an untrusted network requiring segmentation from operational technology environments.

The agency's recommendations include strictly limiting communications between operational technology networks and gateways to private APNs, monitoring traffic for unusual activity, and implementing centralized logging for all events generated by gateway devices. Organizations should change default credentials on all services available through devices connected to private APNs, particularly administrative interfaces, and include private APNs and their access devices in penetration tests, red team exercises, and security architecture reviews. No customers lost power during this incident, and the outage was brief, but the attack demonstrates that cellular network gateways long assumed safe from external threats now represent a viable entry point for sophisticated state-sponsored actors. The breach underscores a fundamental shift in how operators must approach network segmentation: treating every connection point as hostile until proven otherwise, regardless of whether it sits behind cellular authentication or vendor-managed infrastructure. Industrial control system defenders can no longer afford to assume that private mobile networks offer meaningful isolation from internet-based threats.