Protect.Computer
NEWS

First-Ever APN Lateral Move in OT Attack Hit Polish Heat Plant

· 1 min read · Got hacked Network safety
First-Ever APN Lateral Move in OT Attack Hit Polish Heat Plant

Polish security authorities have disclosed the details of a second cyberattack on the country’s energy sector that occurred on December 29, 2025, alongside the previously reported strikes on 30 wind and solar farms and a large combined heat-and-power (CHP) plant. The newly revealed target was a smaller CHP facility supplying heat to around 50,000 residents. The threat actor, believed to be linked to the Russian Electrum group, shut down the facility’s steam turbine and process-water treatment system by switching programmable logic controllers (PLCs) into STOP mode and locking them with a password — halting cogeneration operations. Staff managed to restore systems quickly, and there was no disruption to heat supply for residents.

What makes this incident notable is the attack path. The threat actor began on December 18, 2025 by compromising a FortiGate VPN/firewall at a separate wind farm. From there, they pivoted through a Teltonika cellular router on the wind farm’s network into a private Access Point Name (APN) — a dedicated mobile data channel shared across multiple industrial facilities in the region. Because the APN lacked client isolation (devices within the same APN could communicate freely with one another), the attacker was able to scan and reach industrial equipment at the distant CHP plant. They found a WAGO PFC200 programmable logic controller with its web interface exposed on the APN and protected only by default administrator credentials. Once inside the PLC, they enabled SSH as a pivot point into the plant’s full OT network, spent the following week mapping SCADA systems and Siemens PLCs, then executed the attack on Christmas morning. CERT Polska calls this the first known real-world case of an attacker entering an OT network by moving laterally through a private APN. Post-incident surveys found the misconfiguration was widespread across Polish industrial operators at the time, and the agency estimates the window remained open long enough that similar undetected intrusions at other sites are possible.

Sources

Related reading