Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack
Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack
NEWS

Russian Hackers Breached Polish Energy Plant via Private APN in World-First DER Cyberattack

ELECTRUM/Sandworm compromised a Polish heat-and-power plant serving 50,000 residents through a private cellular APN, marking the first recorded cyberattack on distributed energy resources.

Dylan H.

News Desk

August 10, 2026
4 min read

A Russian state-sponsored threat group breached a combined heat-and-power (CHP) plant in Poland that supplies thermal energy to approximately 50,000 residents, using a private cellular Access Point Name (APN) as the attack vector — marking what OT cybersecurity firm Dragos describes as the first observed instance of a private APN being weaponized in a real-world cyberattack.

The incident, which occurred in December 2025 and was disclosed publicly in August 2026, was part of a coordinated campaign that simultaneously targeted 30 wind and solar power installations across Poland. Poland's Prime Minister Donald Tusk briefed government officials on the attack on January 14, 2026.

Attribution

The attack is attributed with medium confidence to ELECTRUM, also tracked as Sandworm, APT44, and Seashell Blizzard — a Russian state-sponsored threat group with overlaps with the KAMACITE cluster. ELECTRUM is the same group behind the 2015 Ukrainian power grid attacks that caused the first confirmed electricity blackout from a cyberattack, as well as the 2016 Industroyer/Crashoverride attack on a Ukrainian transmission substation.

This latest campaign represents a strategic evolution: rather than attacking centralized distribution control centers as in 2015-2016, ELECTRUM has pivoted to targeting distributed energy resources (DERs) — renewable wind/solar installations and smaller CHP plants that are increasingly woven into modern energy grids.

Attack Timeline and Methodology

The attack chain, reconstructed from Dragos's investigation, unfolded over 11 days:

December 18, 2025 — Attackers compromised a Fortinet FortiGate VPN/firewall at a wind farm connected to the internet. A Teltonika cellular router on the same network was then identified and exploited, with its SSH service used to tunnel into the private APN managed by the distribution system operator.

The critical flaw: the APN lacked client isolation, allowing the attacker to scan across all facilities connected to it — including the CHP plant. This turned a routine cellular connectivity solution into a direct pathway into operational technology (OT) networks across multiple sites.

Discovery of the CHP Plant — Scanning the APN revealed a WAGO PFC200 PLC at the CHP plant with its web management interface exposed and protected only by default administrator credentials that had never been changed.

December 25, 2025 — After compromising the WAGO controller and enabling SSH to establish a persistent foothold in the OT network, attackers pre-positioned by connecting to three Siemens PLCs in preparation for the destructive phase.

December 29, 2025 (~5:30 a.m.) — Attackers accessed the SCADA interface and Siemens PLCs, switching them into STOP mode and activating password protection — triggering an immediate shutdown of both the steam turbine and process-water treatment system.

Following the destructive action, attackers performed deliberate anti-forensic measures: they reset network devices, corrupted the WAGO controller's partition table to prevent forensic recovery, and wiped logs to hinder investigation.

Systems Targeted

The attack engaged a broad range of industrial equipment at the CHP plant and connected facilities:

  • WAGO PFC200 PLC — initial entry point; partition table subsequently corrupted by attackers
  • Three Siemens PLCs — switched to STOP mode during the attack
  • Moxa serial device servers and network switches
  • ABB and Schneider Electric variable frequency drives
  • Steam turbine control systems
  • Process-water treatment controls

Impact and Strategic Significance

Staff restored impacted systems relatively quickly via factory reset and backup reload, resulting in no lasting outage for the 50,000 residents the plant serves. However, the broader December 29 campaign was far more consequential across the 30 DER sites targeted simultaneously: attackers destroyed equipment beyond repair, severed communications between DERs and grid operators, and removed remote supervisory control at the grid connection layer.

Dragos analysts emphasize this demonstrates that strategic grid impact is achievable without an immediate blackout — the goal appears to be degrading grid resilience and operator visibility rather than delivering a single dramatic disruption.

Lessons for ICS/OT Defenders

The private APN attack vector carries significant implications for energy operators relying on cellular connectivity to manage distributed assets:

Network segmentation: Treat private APNs as untrusted external networks, not trusted internal ones. APN traffic should traverse the same security controls as internet-facing connections.

Client isolation: Enable client isolation on APN infrastructure so connected devices cannot scan or communicate with each other.

Traffic allowlisting: Implement allowlists for essential APN-to-OT traffic rather than permitting broad connectivity.

Credential hygiene: Change all default credentials on internet-facing OT devices. The WAGO PLC's default credentials were the initial foothold that enabled the entire attack.

Patch exposed infrastructure: Fortinet FortiGate VPN appliances were the initial entry point — maintaining patches on internet-facing security appliances is critical.

OT network visibility: Organizations that cannot detect lateral movement across their APN infrastructure will not see this attack until the lights go out.

References

  • Dragos — ELECTRUM DER Attack Analysis
  • BleepingComputer Coverage
#ICS Security#OT Security#Sandworm#Russia#Critical Infrastructure#Energy Security#Poland#ELECTRUM

Related Articles

Exposed Fuel Tank Gauges Under Attack in the US

Threat actors are actively targeting Internet-exposed Automatic Tank Gauges (ATGs) at US gas stations, exploiting decades-old unprotected interfaces to…

5 min read

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Attackers penetrated the operational technology network of a Polish combined heat and power plant through the grid operator's private cellular network, successfully shutting down a steam turbine and water treatment systems serving roughly 50,000 residents.

3 min read

Senate Democrats Introduce Water Cyber Shield Act to Fund $300M Annual Water System Cybersecurity

Senators Schiff and Klobuchar introduce legislation directing $300 million per year to secure U.S. water and wastewater infrastructure following coordinated Iranian-linked attacks on municipal systems across 12 states.

5 min read
Back to all News