Poland's computer emergency response team (CERT) has disclosed details of a second cyberattack on the country's energy sector in December 2025. This incident, which went unrecognized as a cyberattack at the time, targeted a smaller combined heat and power (CHP) plant that supplies heat to approximately 50,000 residents.
The attack resulted in the temporary shutdown of the plant's steam turbine and water treatment system. While customers did not lose heat or electricity, the incident occurred during one of the coldest European winters in over a decade, posing a risk to the heat supply for tens of thousands of people.
The investigation by CERT.PL revealed that attackers gained access to the operational technology network by exploiting a private Access Point Name (APN). This method involved using a dedicated mobile gateway and a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another. CERT Polska believes this is the first documented instance of a private APN being used as an attack vector in a real-world cyberattack against industrial control systems.
This attack occurred in parallel with other coordinated cyberattacks in December 2025, which struck around 30 other renewable energy installations and a larger CHP plant. Those attacks, attributed to the Russian government-linked APT Sandworm, primarily targeted grid safety and stability monitoring systems, causing damage to some ICS devices but no electrical outages. The additional attack on the smaller CHP plant was initially misidentified as a contractor error.
The incident highlights vulnerabilities in critical infrastructure network segmentation and security practices. The misconfiguration allowing arbitrary device communication within the private APN network was a key factor enabling the attack, demonstrating how novel attack vectors can be exploited to disrupt essential services.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Attackers breached a Polish combined heat and power plant's controls by exploiting a private cellular network, shutting down a steam turbine and water treatment system. This incident highlights a novel attack vector through private APNs, which CERT Polska believes is a first-of-its-kind real-world cyberattack, posing a significant risk to critical infrastructure globally.
Hackers compromised a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) and default credentials on a PLC. This incident, disclosed by Polish CERT, resulted in the temporary shutdown of the plant's steam turbine and water treatment system, highlighting vulnerabilities in critical infrastructure network segmentation and security practices.
Polish authorities disclosed a previously unknown cyberattack on a heat and power plant that occurred during last winter's cold snap, threatening heat supply to 50,000 residents. This incident, initially misidentified as contractor error, was discovered during an investigation into other coordinated attacks on energy installations, and represents the first known use of a private cellular network to access an industrial control system.
Poland's CERT reported a second cyberattack in December 2025 on the country's energy sector, targeting a CHP plant and causing a temporary shutdown of a steam turbine and water treatment system. This incident is notable as it marks the first documented use of a private APN as an attack vector, a configuration identified as common globally.