Bleepingcomputer
Cyberattack on Polish CHP Plant via Private APN Disrupts Operations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Hackers compromised a small Polish combined heat-and-power (CHP) plant through a private Access Point Name (APN) and a Fortinet device. The attack, linked to the Russian Electrum threat group, occurred on December 29, 2025, following a series of destructive cyberattacks on Poland's energy sector. The attackers disabled the steam turbine and water treatment systems, impacting operations for a brief period. The Polish Computer Emergency Response Team (CERT) reported that the attacker exploited a misconfigured network, allowing unauthorized communication between devices. Initial access was gained through a compromised FortiGate VPN/firewall at a nearby wind farm. The incident highlights vulnerabilities in operational technology (OT) networks, particularly in energy infrastructure. Fortunately, the plant staff quickly restored systems, minimizing disruption to the local population. The attack underscores the need for improved security measures in critical infrastructure.
Key Points: • Attackers used a private APN to breach a Polish CHP plant, disrupting key systems. • The incident is linked to the Russian Electrum threat group, highlighting state-sponsored cyber threats. • Quick recovery by plant staff minimized the impact on local residents despite significant system disruptions.