Cyberattack on Polish CHP Plant via Private APN Disrupts Operations

Cyberattack on Polish CHP Plant via Private APN Disrupts Operations

First seen 11 Aug 2026, 00:22 UTC Securityaffairs.CoBleepingcomputerwiz.io 85% similarity 77.9

Article Content

Browse articles
ThreatCluster

Hackers compromised a small Polish combined heat-and-power (CHP) plant through a private Access Point Name (APN) and a Fortinet device. The attack, linked to the Russian Electrum threat group, occurred on December 29, 2025, following a series of destructive cyberattacks on Poland's energy sector. The attackers disabled the steam turbine and water treatment systems, impacting operations for a brief period. The Polish Computer Emergency Response Team (CERT) reported that the attacker exploited a misconfigured network, allowing unauthorized communication between devices. Initial access was gained through a compromised FortiGate VPN/firewall at a nearby wind farm. The incident highlights vulnerabilities in operational technology (OT) networks, particularly in energy infrastructure. Fortunately, the plant staff quickly restored systems, minimizing disruption to the local population. The attack underscores the need for improved security measures in critical infrastructure.

Key Points: • Attackers used a private APN to breach a Polish CHP plant, disrupting key systems. • The incident is linked to the Russian Electrum threat group, highlighting state-sponsored cyber threats. • Quick recovery by plant staff minimized the impact on local residents despite significant system disruptions.

ThreatCluster AI How this analysis works

Timeline

2025-12-18
Initial compromise of wind farm's FortiGate device
The attacker gained access through a compromised FortiGate VPN/firewall, enabling further exploitation.
Bleepingcomputer
2025-12-25
Preparation for attack on CHP plant
The attacker connected to three Siemens PLCs at the CHP plant, likely in preparation for the attack.
Bleepingcomputer
2025-12-29
Attack on CHP plant executed
The attacker accessed the SCADA interface, shutting down the steam turbine and water treatment systems.
Bleepingcomputer
2026-08-10
CERT reports second incident
Poland's CERT disclosed the second attack on the energy sector, emphasizing the vulnerabilities in OT networks.
Bleepingcomputer

Community

Browse all →

Tracked Entities in This Story