Particle.news
Download on the App Store

Hackers Used Private Cellular APN to Breach Polish CHP Plant

CERT Polska says this was the first observed real‑world use of a private APN to reach industrial control systems, signaling that common APN misconfigurations leave other operators exposed.

Overview

  • CERT Polska published a follow‑up report showing attackers moved from internet‑reachable edge gear into a small combined heat‑and‑power plant on December 29, 2025, and stopped a steam turbine and the plant’s water treatment system.
  • Investigators reconstructed an intrusion path that began at a FortiGate VPN/firewall at a wind farm, used SSH through a Teltonika cellular router to tunnel into the distribution operator’s private APN, and then reached a WAGO PLC that gave access to the plant’s OT network.
  • Once inside, the intruder spent days mapping systems, then switched three Siemens PLCs to STOP mode, set passwords to block operators, corrupted the WAGO controller’s partition table and reset network gear to erase logs, which hindered forensic work.
  • Security firm ESET links parts of the late‑December destructive campaign to the Russia‑aligned Sandworm APT with medium confidence, and CERT Polska says the December activity was part of coordinated attacks that also targeted about 30 renewable sites and a larger CHP plant.
  • CERT Polska recommends treating private APNs as untrusted, enabling client isolation and allowlists, removing exposed admin services and weak credentials, and testing layered IT/OT defenses to prevent a single compromised device from reaching control systems.