← All stories
● Covered by 5 sources · 7 reportsMedium impact5 negative2 neutral

Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine

🔄 Updated 38d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Second Polish energy sector attack in December 2025.
  • Targeted a CHP plant supplying heat to 50,000 residents.
  • Attack caused temporary shutdown of steam turbine and water treatment.
  • Used a private APN as a novel attack vector.
  • Misconfiguration allowed communication between arbitrary devices.
  • Attack occurred in July.
  • Attack shut down a UK power plant for four days.
  • Hackers linked to Iran carried out the attack.
  • US authorities warned about cyberattacks on water facilities in seven states.
  • UK government spokesperson declined to attribute blame or identify the facility.
  • UK Department of Energy Security and Net Zero briefed energy CEOs and updated cybersecurity regulations.
  • The Telegraph reported the attack on August 22, 2026.
  • The attack occurred in July 2026.
  • US sanctioned six Iranian nationals for cyberattacks.
  • Sanctioned individuals operated on behalf of Iran's Ministry of Intelligence and Security (MOIS).
  • Four sanctioned individuals indicted for breaching employee email accounts.
  • Breached accounts at Department of Labor, Federal Energy Regulatory Commission, and United Nations.
  • Sanctioned individuals are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi.
  • Two other sanctioned individuals were previously sanctioned.
  • Hacking team conducted cyberattacks since 2023.

Second Cyberattack on Polish Energy Sector Revealed

Poland's computer emergency response team (CERT) has disclosed details of a second cyberattack on the country's energy sector in December 2025. This incident, which went unrecognized as a cyberattack at the time, targeted a smaller combined heat and power (CHP) plant that supplies heat to approximately 50,000 residents.

Impact on Operations

The attack resulted in the temporary shutdown of the plant's steam turbine and water treatment system. While customers did not lose heat or electricity, the incident occurred during one of the coldest European winters in over a decade, posing a risk to the heat supply for tens of thousands of people.

Novel Attack Vector: Private APN

The investigation by CERT.PL revealed that attackers gained access to the operational technology network by exploiting a private Access Point Name (APN). This method involved using a dedicated mobile gateway and a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another. CERT Polska believes this is the first documented instance of a private APN being used as an attack vector in a real-world cyberattack against industrial control systems.

Context of Coordinated Attacks

This attack occurred in parallel with other coordinated cyberattacks in December 2025, which struck around 30 other renewable energy installations and a larger CHP plant. Those attacks, attributed to the Russian government-linked APT Sandworm, primarily targeted grid safety and stability monitoring systems, causing damage to some ICS devices but no electrical outages. The additional attack on the smaller CHP plant was initially misidentified as a contractor error.

Vulnerabilities Highlighted

The incident highlights vulnerabilities in critical infrastructure network segmentation and security practices. The misconfiguration allowing arbitrary device communication within the private APN network was a key factor enabling the attack, demonstrating how novel attack vectors can be exploited to disrupt essential services.

Updates

🕒 2026-08-25 · new reporting from The Record
  • US sanctioned six Iranian nationals for cyberattacks.
  • Sanctioned individuals operated on behalf of Iran's Ministry of Intelligence and Security (MOIS).
  • Four sanctioned individuals indicted for breaching employee email accounts.
  • Breached accounts at Department of Labor, Federal Energy Regulatory Commission, and United Nations.
  • Sanctioned individuals are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi.
  • Two other sanctioned individuals were previously sanctioned.
  • Hacking team conducted cyberattacks since 2023.
🕒 2026-08-24 · new reporting from SecurityWeek
  • The Telegraph reported the attack on August 22, 2026.
  • The attack occurred in July 2026.
🕒 2026-08-23 · new reporting from CNBC Technology
  • Attack occurred in July.
  • Attack shut down a UK power plant for four days.
  • Hackers linked to Iran carried out the attack.
  • US authorities warned about cyberattacks on water facilities in seven states.
  • UK government spokesperson declined to attribute blame or identify the facility.
  • UK Department of Energy Security and Net Zero briefed energy CEOs and updated cybersecurity regulations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The U.S. sanctioned six Iranian nationals for cyberattacks on critical infrastructure, including government offices and energy companies. These individuals are accused of operating on behalf of Iran's Ministry of Intelligence and Security (MOIS) and conducting financially motivated cyber theft.

Iran-linked hackers reportedly shut down a British power plant for four days in July 2026, a detail revealed by The Telegraph on August 22, 2026. This incident highlights the vulnerability of critical infrastructure to cyberattacks and raises questions about recovery times and preparedness for smaller operators.

A small power plant in the UK was shut down for four days in July due to a cyberattack reportedly carried out by hackers linked to Iran. This incident follows warnings from US authorities about malicious cyber actors targeting water facilities and highlights ongoing cyber warfare activities.

Attackers breached a Polish combined heat and power plant's controls by exploiting a private cellular network, shutting down a steam turbine and water treatment system. This incident highlights a novel attack vector through private APNs, which CERT Polska believes is a first-of-its-kind real-world cyberattack, posing a significant risk to critical infrastructure globally.

Hackers compromised a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) and default credentials on a PLC. This incident, disclosed by Polish CERT, resulted in the temporary shutdown of the plant's steam turbine and water treatment system, highlighting vulnerabilities in critical infrastructure network segmentation and security practices.

Polish authorities disclosed a previously unknown cyberattack on a heat and power plant that occurred during last winter's cold snap, threatening heat supply to 50,000 residents. This incident, initially misidentified as contractor error, was discovered during an investigation into other coordinated attacks on energy installations, and represents the first known use of a private cellular network to access an industrial control system.

Poland's CERT reported a second cyberattack in December 2025 on the country's energy sector, targeting a CHP plant and causing a temporary shutdown of a steam turbine and water treatment system. This incident is notable as it marks the first documented use of a private APN as an attack vector, a configuration identified as common globally.