In a stark demonstration of critical infrastructure vulnerability, attackers successfully breached the operational technology (OT) controls of a Polish combined heat and power plant — entering not through the internet, but through the private cellular network the local grid operator uses to manage remote equipment.
The attack resulted in the forced shutdown of a steam turbine and the facility's process-water treatment system. The plant supplies heat to approximately 50,000 residents, and recovery operations began roughly seven hours after the initial intrusion was detected.
Attack Vector: The Private Cellular Network
This incident highlights a growing concern in industrial cybersecurity: the assumption that private or air-gapped networks are inherently secure. The attacker leveraged the cellular infrastructure used by the grid operator to reach remote monitoring and control equipment — bypassing traditional IT perimeter defenses entirely.
Private LTE and 5G networks are increasingly deployed in industrial and utility environments for their reliability and bandwidth advantages. However, this case demonstrates that without proper segmentation and authentication controls, they can become a direct entry path into safety-critical OT systems.
What Was Disrupted
Once inside the network, the threat actors gained sufficient access to issue control commands affecting:
- Steam turbine — taken offline, requiring manual recovery procedures
- Process-water treatment system — disrupted, impacting the plant's ability to safely manage its heat generation cycle
The plant supplies district heating to approximately 50,000 residents in the surrounding area. While the shutdown did not result in a catastrophic failure, the disruption underscored the real-world consequences of OT network intrusions.
Recovery and Response
Recovery operations reportedly began around seven hours after the intrusion. The plant's operators activated incident response procedures, and investigators — including cybersecurity specialists — were brought in to assess the attack vector and prevent recurrence.
Polish authorities are believed to be involved in the investigation given the national critical infrastructure implications.
Why This Matters
This attack follows a pattern of escalating incidents targeting European energy infrastructure. Key takeaways for defenders:
- Private cellular ≠ secure — OT-connected cellular networks require the same segmentation, anomaly detection, and access controls as any other network path
- Remote access to control systems must be authenticated, logged, and monitored in real time
- OT-specific threat detection is essential — IT security tools often cannot interpret or detect anomalous commands in industrial control protocols (Modbus, DNP3, IEC 61850, etc.)
- Incident response plans for OT environments must account for recovery timelines measured in hours, not minutes
The Bigger Picture
Europe's energy infrastructure has been under heightened threat since the onset of regional geopolitical tensions. Nation-state actors and cybercriminal groups alike have demonstrated both the capability and willingness to target power generation and distribution facilities.
The Polish power plant incident serves as a reminder that critical infrastructure protection cannot rely solely on physical isolation. As remote management becomes operationally necessary, the attack surface grows — and adversaries will find the weakest link.
Source: The Hacker News