CERT.PL details Russian sabotage of Polish CHP plant via private APN
This digest was compiled by AI from multiple sources — links to the originals are below.

Poland's computer emergency response team (CERT.PL) has revealed that Russian military hackers sabotaged a combined heat and power plant in December 2025, causing a steam turbine and water treatment system to shut down but no interruption of heat or electricity supply. The attackers exploited a private APN network to pivot from a wind farm edge device into the plant's industrial control systems, marking the first known use of this attack vector. The attack occurred in parallel with a broader Sandworm campaign that targeted 30 Polish energy sites, though no outages resulted from either operation.
The Sabotage
In December 2025, during maintenance at a Polish CHP plant, hackers linked to Russia's Sandworm group caused the shutdown of a steam turbine and water treatment system. The disruption halted the cogeneration process, but plant operators quickly restored systems, preventing any interruption to heat supply for the plant's 50,000 residents or to electricity generation. Initial suspicion fell on an engineering error, but CERT.PL's investigation confirmed malicious activity. The attack occurred alongside a broader Sandworm operation that targeted roughly 30 Polish energy sites, including other CHP plants and renewable dispatch centers.
Private APN Pivot
The attackers first compromised a Fortinet VPN/firewall device at a wind farm, then accessed a Teltonika cellular router's admin interface. Using an SSH tunnel, they pivoted into a private APN network used by the distribution system operator to connect SCADA systems with substation ICS. Scanning this network revealed a Wago PLC at the CHP plant with SSH enabled, granting access to the plant's OT systems. After a week of reconnaissance, the hackers halted Siemens PLCs and password-protected them to block operator intervention, leading to the shutdown. CERT.PL warned that such vulnerable private APN configurations are common globally, making this a significant new attack vector.
What's Next
The Polish CERT has issued guidance to secure private APN deployments, and the distribution system operator is reviewing network configurations. It remains unclear whether other countries' energy sectors have been probed using the same technique.
2 sources
CERT.PL details Russian sabotage of Polish CHP plant via private APN



