CyberSecurity SEE

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Polish CERT Reports Insights from Cyber-Attack on Energy Infrastructure Amid Russian Campaign

The Polish Computer Emergency Response Team (CERT.PL) has recently disclosed significant findings related to a cyber-attack targeting its energy infrastructure, an incident believed to be part of a broader Russian cyber offensive that occurred in December 2025. This latest revelation follows a comprehensive investigation that took three months to complete, thus not being included in an initial report released in January 2026.

This earlier report highlighted a dangerous cyber-attack involving wiper malware, linked to the notorious Sandworm group, a state-sponsored advanced persistent threat (APT) organization from Russia. The implications of such attacks are profound, especially as they threaten critical infrastructure that serves millions of citizens.

The most recent investigation unveiled an array of innovative techniques employed by the attackers, which successfully led to the shutdown of a steam turbine and a water treatment system at a large combined heat and power (CHP) plant. This facility is crucial as it provides energy to approximately 50,000 residents, underscoring the potential impact of such disruptions on the community’s daily lives.

In a significant development, this attack marks the first known instance where cyber adversaries accessed an operational technology (OT) network through a private Access Point Name (APN). According to CERT.PL, the breach initiated when the attackers compromised a FortiGate VPN and firewall located within a wind farm in Poland. Utilizing a Teltonika cellular router situated on the same network, the threat actors targeted the private APN, which is managed by a distribution system operator (DSO), by establishing an SSH tunnel.

The attackers meticulously scanned the APN, eventually locating a WAGO PFC200 programmable logic controller (PLC) at the CHP plant. Alarmingly, the web interface of this controller was accessible via the APN and secured only by default administrator credentials, a significant vulnerability. Once they gained access to the PLC, they leveraged SSH to infiltrate the plant’s OT network, subsequently scanning and identifying three Siemens PLCs within.

According to the report, personnel from the CHP plant divulged that the PLCs were configured in STOP mode and had passwords designed to prevent modifications of their operational states or control logic. However, the attackers managed to circumvent these defenses, resulting in the shutdown of both the steam turbine and the water treatment system, and consequently interrupting the cogeneration process.

Intent on stalling recovery efforts, the attackers also vandalized various network devices from Moxa, eradicated logs, damaged the WAGO controller, reset the Teltonika router, and reverted the FortiGate device to factory settings. Such actions illustrate a calculated approach to ensure maximum disruption and chaos.

In light of these events, CERT.PL has issued a series of recommendations aimed at organizations utilizing private APNs, emphasizing the need for heightened security measures. The agency advises conducting thorough audits of private APN configurations and enabling client isolation between end devices connected to these networks. Furthermore, it stresses treating private APNs as untrusted networks while implementing segmentation from OT environments.

Entities are urged to restrict communications between their OT networks and devices that serve as gateways to the private APNs, while also recommending rigorous monitoring of traffic for any unusual activity. Centralized logging and monitoring of events generated by devices connected to the private APN should be prioritized, and the number of open ports accessible through interfaces linked to these private networks must be minimized.

One of the most critical changes highlighted in the CERT’s recommendations is altering default credentials for all services available on devices linked to the private APN, particularly for administrative functionalities. Additionally, organizations are motivated to include private APNs and their access devices in the scope of penetration testing, red teaming exercises, and security architecture reviews to enhance their defenses.

Fortunately, despite the chaos wrought by this cyber-attack, the outage was brief, and no customers experienced power loss. This incident unfolded during a major Russian cyber campaign attributed to the Sandworm group, which targeted not only the Polish CHP plant but also 30 renewable energy facilities across the nation, indicating the scale and ambition of these cyber operations.

The attacks spanned December 29 and 30, 2025, illustrating an alarming trend in the targeting of critical energy infrastructure by state-sponsored cyber adversaries. As nations increasingly rely on interconnected technology for energy production and distribution, strengthening cybersecurity measures becomes vital to safeguarding essential services against future threats.

Source link

Exit mobile version