Security1 publisher3 min readPublished
CERT.PL says attackers reached a plant's OT network through a carrier private APN
A wind-farm FortiGate and a Teltonika router put intruders onto a DSO-managed APN, where a WAGO controller with default credentials was waiting. A steam turbine stopped.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CERT.PL published details of an attack on Polish energy infrastructure that took place during a suspected Russian cyber campaign in December 2025.
- The post mortem on the attack took three months to complete and was therefore not included in the initial report published in January 2026.
- The January 2026 report detailed a late 2025 cyber-attack on Poland's energy infrastructure involving wiper malware and attributed to Sandworm, a Russian state-backed APT group.
- The attackers forced the shutdown of a steam turbine and water treatment system at a large combined heat and power plant serving 50,000 residents.
- CERT.PL claimed it is the first known documented attack in which threat actors have accessed an OT network through a private Access Point Name (APN).
Compiled by The WatchSomething wrong?How this is made
Why it matters
CERT.PL has published a post mortem showing that attackers reached the operational technology network of a Polish combined heat and power plant through a private Access Point Name managed by a distribution system operator, forcing the shutdown of a steam turbine and the water treatment system that produces process water at a site serving 50,000 residents [1][4][11]. The Polish CERT says this is the first documented case of an OT network being reached through a private APN [5], which matters because private APNs are widely treated as trusted carrier transport rather than as a routable network with hostile neighbours.
The chain is unglamorous and worth reading closely. It started with a compromised FortiGate VPN and firewall at a wind farm [6]. From there the attackers used a Teltonika cellular router on the same network to reach the DSO-managed private APN over an SSH tunnel [7]. They scanned the APN repeatedly and found a WAGO PFC200 programmable logic controller at the CHP plant whose web interface was reachable from the APN and protected only by default administrative credentials [8]. Having taken that controller, they used SSH to move into the plant's OT network and found three Siemens PLCs [9].
According to statements from plant personnel quoted in the report, those PLCs were switched to STOP mode and then locked with a password that prevented changes to their operating state or control logic [10]. The cogeneration process was interrupted [11]. The attackers then worked on the recovery timeline as well as the process: CERT.PL says they sabotaged several Moxa network devices, destroyed logs, damaged the WAGO controller, reset the Teltonika router, and restored the FortiGate to factory settings [12]. That is five different vendors' devices touched across the intrusion and the clean-up [1], across three separate environments: a wind farm network, a DSO's APN, and a plant's OT network [2].
CERT.PL's recommendations read as a list of assumptions that turned out to be wrong. Audit the private APN configuration and turn on client isolation between connected devices [13]. Treat the APN as untrusted and segment it from OT [14]. Strictly limit traffic between OT and the device acting as the APN gateway, monitor that traffic, and centrally log events from those gateway devices [15]. Minimise open ports reachable from the APN, change default credentials on everything attached to it, and put the APN and its gateway devices inside the scope of penetration tests, red teaming and architecture reviews [16].
The physical outcome was contained: the outage was short and no customers lost power [17]. The context is less comforting. The attacks took place on 29 and 30 December 2025 [19] during a campaign linked to Sandworm that hit 30 Polish renewable energy facilities and another large CHP plant [18]. An earlier January 2026 report covered a late-2025 attack involving wiper malware and attributed it to Sandworm [3]; this analysis took three months and missed that publication [2], so the APN vector went undocumented for at least a quarter after the intrusion [3].
Two things to watch. First, whether asset owners can actually produce an inventory of vendor-managed cellular routers sitting inside their networks, because the Teltonika device was the pivot and the FortiGate was only the entry [6][7]. Second, whether DSOs running private APNs can show client isolation is enabled [13], since without it every subscriber on the APN is a peer of every PLC on it.