Hackers found a new way into one of Poland’s energy facilities, and investigators say the route they took had never been documented before. According to a follow-up report from Poland’s national computer emergency response team, CERT Polska, attackers broke into a small combined heat and power (CHP) plant that supplies heat to roughly 50,000 residents, then used a private cellular network normally reserved for grid operators to slip past the boundary between IT and industrial control systems.
The incident happened alongside a much larger wave of attacks on December 29, 2025, when more than 30 renewable energy sites and a major CHP plant in Poland were targeted in a coordinated campaign. That earlier event was already documented in a January 2026 report. This second, smaller attack took investigators over three months to fully unravel, largely because the intrusion method was so unusual that it did not initially register as a cyberattack at all.
For plant operators and grid regulators well beyond Poland, the case is a warning. Hackers did not need a sophisticated zero-day exploit to reach turbine controllers and water treatment systems. They needed one exposed firewall, one overlooked cellular router, and enough patience to move quietly through the network for about a week before pulling the trigger.
How the Attackers Got In
A Wind Farm Was the Starting Point
CERT Polska’s report traces the intrusion back to a wind farm, where hackers compromised a Fortinet VPN and firewall appliance that was reachable from the public internet. From that foothold, they located a Teltonika cellular router and used SSH to build an encrypted tunnel through it.
That tunnel gave the attackers access to something unusual: a private Access Point Name, or APN, the dedicated mobile network that the local distribution system operator (DSO) uses to communicate with remote infrastructure. CERT Polska says this is the first time it has documented attackers pivoting through a private APN to reach operational technology (OT).
“To the best of our knowledge, the attack vector used in this case has not previously been observed in any known incidents,” the agency wrote in its report.
From Cellular Router to Plant Floor
Once inside the private APN, the attackers reached the CHP plant’s network and found a Wago programmable logic controller (PLC) that had SSH access enabled. That controller became their gateway into the operational environment.
CERT Polska’s analysis found that the cellular router at the heart of the breach, a Teltonika RUTX50, had been configured correctly for its intended purpose but incompletely secured overall.
| Requirement | Status |
|---|---|
| Serial link to the RTU using DNP3.0 protocol | Configured as required by the DSO |
| Rules governing the router’s administrative interface | Not defined |
| Ethernet interface connected to a VLAN | Left reachable through the compromised central firewall |
“An important aspect of this architecture is that DSOs require all communication between the DSO’s ICT network and the RTU to take place over a serial protocol, in this case DNP3.0,” the report states. “However, no requirements had been defined regarding the handling of the cellular router’s administrative interface.”
That single gap, an unmanaged Ethernet interface sitting on a VLAN tied to an already-breached firewall, gave the hackers a second path into the plant’s control systems.
What the Attackers Did Once Inside
A Week of Silent Reconnaissance
After reaching the Wago controller, the attackers spent roughly a week studying the network before taking any disruptive action. This kind of dwell time is common in OT-focused intrusions, giving attackers a chance to map out which devices control physical processes before they act.
Investigators found that the hackers eventually reached Siemens PLCs, switched them into stop mode, and locked out plant operators by setting a password that blocked changes to the controllers’ logic and operating state.
Physical Systems Went Down
The consequences were immediate and physical. The plant’s steam turbine and water treatment system both shut down, and the cogeneration process that converts fuel into heat and electricity was interrupted. Staff at the facility restored the affected systems quickly enough that residents did not lose heat or power, but the plant did lose service continuity during the incident.
Beyond the core systems, CERT Polska found that the attackers also touched a wider set of industrial equipment, including Moxa serial device servers and network switches, which were reconfigured to block legitimate operator access, and ABB and Schneider Electric variable frequency drives, some of which showed only partial or failed connection attempts from the attackers.
Covering Their Tracks
Before leaving the network, the attackers tried to erase evidence of their presence. CERT Polska reports that they deliberately damaged the Wago controller that had served as their gateway by corrupting its partition table, rendering it unreadable.
“In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot,” the report notes. “No valuable logs could be recovered from the device during the investigation.”
Why the Incident Was Almost Missed
Mistaken for a Maintenance Error
One of the more striking details in CERT Polska’s report is how close the attack came to going unnoticed as a cyberattack at all. Because contractor maintenance work happened to be underway at the facility around the same time, plant staff initially assumed the process interruption was caused by a technician’s mistake and filed the report purely for informational purposes.
“Due to its awareness of other similar events, CERT Polska initiated incident handling under the assumption that the event may have resulted from a cyberattack,” the agency wrote. “Further analysis confirmed this hypothesis.”
That confusion is part of why the full investigation took more than three months, well after the broader December 29 campaign against Poland’s energy sector had already been reported publicly.
A Pattern That Extends Beyond One Plant
CERT Polska cautioned that the private APN architecture exploited in this case is not a one-off configuration unique to this plant. Similar setups are used elsewhere in Poland’s distribution grid, which is why the agency flagged the finding as relevant well beyond this single incident.
The Bigger Picture: Sandworm and a Coordinated Campaign
Researchers Point to a Russia-Linked Group
The private APN intrusion did not happen in isolation. It came just weeks after ESET researchers uncovered a separate, more destructive tool used in the December 29 campaign against Poland’s energy sector: a wiper malware family the firm has named DynoWiper, tracked in ESET’s detection engine as Win32/KillFiles.NMO.
ESET attributed that attack to the Russia-aligned Sandworm advanced persistent threat (APT) group with medium confidence, citing overlap with tactics the group has used in previous destructive operations.
“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed,” ESET researchers said. The firm added that it is “not aware of any successful disruption occurring as a result of this attack.”
Timing That Raises Questions
ESET noted that the December 29 campaign coincided with the ten-year anniversary of Sandworm’s 2015 attack on Ukraine’s power grid, the first confirmed malware-induced blackout in history, which left about 230,000 people without electricity. The timing, combined with the peak winter demand period in Poland, has led researchers to view the attempted disruption as a deliberate and symbolic choice rather than a coincidence.
ESET has shared indicators of compromise, including an associated file hash, with subscribers to its private Threat Intelligence APT reports to support faster detection and response by defenders.
What This Means for Energy Sector Security
The Polish CHP plant incident underscores a lesson that cybersecurity researchers have repeated for years but that keeps recurring in real-world attacks: hackers rarely need cutting-edge exploits when ordinary infrastructure is left loosely secured. An internet-facing firewall, a cellular router with an unmanaged administrative interface, and a private network path that was assumed to be safe because of its limited purpose were enough to give attackers a route from the internet all the way to turbine controls.
For utilities and grid operators, the case strengthens the argument that private APNs, remote access routers, and OT gateways need to be treated with the same security discipline applied to any other internet-facing asset, not exempted because they were designed for a narrow operational purpose.
CERT Polska’s full technical findings are detailed in its official follow-up report on the 2025 energy sector incidents.



