Bleepingcomputer
Cyberattack on Polish Energy Sector Exploits Private APN Vulnerability
Article Content
In December 2025, hackers breached a Polish combined heat and power (CHP) plant using a private Access Point Name (APN) to access the operational technology network. The attack, attributed to the Russian Electrum threat group, resulted in the shutdown of a steam turbine and water treatment system, affecting a facility that serves 50,000 residents. The attackers initially compromised a FortiGate VPN/firewall at a wind farm and exploited a misconfiguration that allowed devices within the private APN to communicate. They accessed the plant's PLCs and SCADA systems, disrupting operations but causing no significant impact on energy distribution. The Polish Computer Emergency Response Team (CERT) confirmed the incident, marking it as the first known case of such an attack vector in the energy sector. Recovery efforts were swift, and the outage was brief. The incident highlights vulnerabilities in network configurations within critical infrastructure.
Key Points: • Attackers exploited a private APN to breach a Polish CHP plant's OT network. • The incident involved the Russian Electrum threat group targeting critical infrastructure. • Quick recovery measures minimized the impact on energy distribution and local residents.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.