Cyberattack on Polish Energy Sector Exploits Private APN Vulnerability

Cyberattack on Polish Energy Sector Exploits Private APN Vulnerability

First seen 11 Aug 2026, 00:22 UTC Securityaffairs.CoBleepingcomputerFeeds2.FeedburnerGbhackersButtondown+2 77.0

Article Content

Browse articles
ThreatCluster

In December 2025, hackers breached a Polish combined heat and power (CHP) plant using a private Access Point Name (APN) to access the operational technology network. The attack, attributed to the Russian Electrum threat group, resulted in the shutdown of a steam turbine and water treatment system, affecting a facility that serves 50,000 residents. The attackers initially compromised a FortiGate VPN/firewall at a wind farm and exploited a misconfiguration that allowed devices within the private APN to communicate. They accessed the plant's PLCs and SCADA systems, disrupting operations but causing no significant impact on energy distribution. The Polish Computer Emergency Response Team (CERT) confirmed the incident, marking it as the first known case of such an attack vector in the energy sector. Recovery efforts were swift, and the outage was brief. The incident highlights vulnerabilities in network configurations within critical infrastructure.

Key Points: • Attackers exploited a private APN to breach a Polish CHP plant's OT network. • The incident involved the Russian Electrum threat group targeting critical infrastructure. • Quick recovery measures minimized the impact on energy distribution and local residents.

Timeline

2025-12-18
Initial compromise of FortiGate VPN/firewall
Attackers breached a wind farm's network, gaining access to a private APN managed by the distribution system operator.
Bleepingcomputer
2025-12-29
Cyberattack on Polish CHP plant
Hackers accessed PLCs and SCADA systems, shutting down the steam turbine and water treatment system.
Bleepingcomputer
2026-08-10
CERT Polska discloses second incident
The Polish CERT reported on the second attack on a CHP plant, revealing the use of a private APN as an entry vector.
Bleepingcomputer
2026-08-11
Public awareness of attack vector
The incident is highlighted as the first observed case of using a private APN to breach an OT network in Poland.
Feeds2.Feedburner