CERT.PL says Sandworm used a private APN pivot to sabotage a second Polish heat and power plant

Poland says Russian government-linked hackers sabotaged a second energy facility in December 2025 by reaching its industrial control systems through a private mobile network path. CERT.PL said the attackers first compromised a Fortinet device, then a Teltonika cellular router, tunneled into a private APN used for supervisory control and data acquisition (SCADA) communications, found a Wago controller, and then put Siemens programmable logic controllers (PLCs) into stop mode while locking operators out. Moxa devices and ABB and Schneider Electric drives were also targeted, and some ICS equipment was reportedly permanently damaged.
Why it matters: This is a rare, destructive attack path into operational technology that could exist in other utilities using similar remote-access and private-APN setups. Energy and industrial operators should urgently review Fortinet, Teltonika, Wago, Siemens, Moxa, ABB, and Schneider Electric exposure, disable unnecessary management services, and audit private-APN trust assumptions.

Sources

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
info@thehackernews.com (The Hacker News) 2026.08.11 98% relevant
This appears to be coverage of the same underlying incident: Russian Sandworm actors allegedly used a private cellular access point name (APN) path to reach industrial control systems at a Polish energy facility and shut down a turbine, adding mainstream reporting and context around the plant-control intrusion.
Hackers breached a small Polish energy plant via private APN last year
Bill Toulas 2026.08.10 99% relevant
This article is a direct report on the same newly disclosed second Polish CHP plant incident, adding attack-chain details including the initial compromise of a FortiGate at a wind farm, pivoting via a Teltonika router into a private APN, use of default credentials on a WAGO PFC200 PLC, and shutdown of Siemens PLC-controlled systems.
Poland uncovers second heat plant cyberattack that went hidden for months
2026.08.10 99% relevant
This article appears to be reporting that same newly disclosed second Polish heat-plant attack, adding plain-language context on timing during the winter cold snap, the near-miss impact on heating for 50,000 residents, and details on how attackers moved from compromised wind-farm firewalls through a private cellular network into Siemens controllers using default credentials.
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Eduard Kovacs 2026.08.10 100% relevant
The article establishes a distinct second December 2025 sabotage incident against a separate Polish CHP plant and adds the novel private-APN intrusion method, making it a standalone tracked story rather than just a generic follow-up.
← Back to all stories