CERT.PL: Russian-linked hackers accessed Polish CHP plant OT network via private APN
This digest was compiled by AI from multiple sources — links to the originals are below.

Poland's CERT.PL publishes a report on a suspected Russian campaign that shut down a steam turbine and water treatment system at a Polish CHP plant serving 50,000 residents. Attackers used a private access point name to reach the OT network after breaching a wind farm FortiGate VPN and a Teltonika router.
Key Facts
- CERT.PL says the attack is the first documented case of threat actors accessing an OT network through a private APN.
- The post-mortem analysis took three months and was therefore not included in the January 2026 initial report.
- The initial January 2026 report linked a late 2025 wiper malware attack on Poland's energy infrastructure to Sandworm.
- After breaching the plant's OT network, the attackers switched three Siemens PLCs to STOP mode and password-protected them.
- The attackers sabotaged Moxa network devices, destroyed logs, damaged the WAGO controller, reset the Teltonika router, and restored the FortiGate device to factory settings.
The APN Intrusion
The attack began after adversaries compromised a FortiGate VPN and firewall at a wind farm in Poland. They then used a Teltonika cellular router on the same network to target a private APN network managed by a distribution system operator. Repeated scanning of the APN located a WAGO PFC200 programmable logic controller at the CHP plant. The controller's web interface was accessible via the APN and protected only by default admin credentials. After compromising the WAGO controller, the attackers used SSH to reach the plant's OT network and found three Siemens PLCs.
Shutdown and Sabotage
CHP plant personnel said the three Siemens PLCs were switched to STOP mode and protected with a password that blocked operating-state changes. The steam turbine and the water treatment system used to produce process water were shut down, interrupting the cogeneration process. The attackers sabotaged several Moxa network devices, destroyed logs, damaged the WAGO controller, reset the Teltonika router, and restored the FortiGate device to factory settings. CERT.PL said the post-mortem took three months to complete and was therefore not included in the initial January 2026 report. That initial report detailed a late 2025 wiper malware attack attributed to Sandworm.
1 source
CERT.PL: Russian-linked hackers accessed Polish CHP plant OT network via private APN



