Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers breached a small Polish energy plant via private APN last year

0
High
Breachics
Published: 08/10/2026 (08/10/2026, 23:07:21 UTC)
Source: Bleeping Computer

Description

In late 2025, a small combined heat-and-power (CHP) plant in Poland was breached by attackers using a private APN to access its operational technology (OT) network. The attackers exploited a misconfiguration that allowed devices within the private APN network to communicate freely, enabling lateral movement. They compromised a FortiGate VPN/firewall and a Teltonika cellular router to tunnel into the private APN, then accessed a WAGO PFC200 PLC with default credentials. The attackers subsequently disabled key systems including a steam turbine and water treatment system by switching PLCs to STOP mode and activating password protection. The outage was short-lived and did not impact the population. This incident is notable as the first known real-world cyberattack leveraging lateral movement through a private APN to reach OT networks. The Polish CERT recommends treating private APNs as untrusted external networks and implementing client isolation and traffic allowlists.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 23:11:32 UTC

Technical Analysis

The breach involved an attacker initially compromising a FortiGate VPN/firewall at a wind farm and using a Teltonika cellular router to tunnel into a private APN managed by the distribution system operator. Due to a misconfiguration lacking client isolation, the attacker could scan and communicate with devices across the APN network. They found a WAGO PFC200 PLC exposed with default admin credentials, enabling SSH access and lateral movement into the CHP plant's OT network. Over a week, the attacker scanned for SCADA and industrial devices, then on December 29, 2025, accessed Siemens PLCs to switch them into STOP mode, password-protect them, and shut down critical plant systems. The attacker also reset and corrupted devices and logs to hinder recovery and forensic analysis. CERT Polska identified this as the first known real-world attack using lateral movement through a private APN to access OT networks and noted that similar configurations were common in Poland and likely internationally. Recommendations include treating private APNs as untrusted, enabling client isolation, using allowlists, and disabling exposed SSH and Telnet services.

Potential Impact

The attack caused shutdown of a steam turbine and the plant’s process-water treatment system, interrupting cogeneration operations at the CHP plant. The outage was short-lived and had no impact on the population due to rapid restoration by plant staff. The attacker also destroyed logs and corrupted devices to impede forensic analysis and recovery efforts. Although the attack targeted critical infrastructure, energy generation and distribution were not disrupted. This incident demonstrates a novel attack vector via private APN lateral movement into OT networks.

Defensive Guidance

The Polish CERT recommends treating private APNs as untrusted external networks and enabling client isolation to prevent arbitrary device communication within the APN. Use allowlists to restrict essential traffic between APN gateways and OT systems. Disable exposed SSH and Telnet administration services on OT devices. Ensure default credentials are changed and web interfaces are not exposed. Regularly test network segmentation and access controls to prevent lateral movement. Patch and secure VPN/firewall and cellular router devices to prevent initial compromise. These measures address the specific misconfigurations exploited in this attack.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/","fetched":true,"fetchedAt":"2026-08-10T23:11:22.206Z","wordCount":921}

Threat ID: 6a7a5a9abf8831d539b6021d

Added to database: 08/10/2026, 23:11:22 UTC

Last enriched: 08/10/2026, 23:11:32 UTC

Last updated: 08/11/2026, 03:50:34 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses