Security1 distinct publisher3 min readUpdated
A wind-farm FortiGate and a Teltonika router put intruders onto a DSO-managed APN, where a WAGO controller with default credentials was waiting. A steam turbine stopped.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CERT.PL has published a post mortem showing that attackers reached the operational technology network of a Polish combined heat and power plant through a private Access Point Name managed by a distribution system operator, forcing the shutdown of a steam turbine and the water treatment system that produces process water at a site serving 50,000 residents [1][4][11]. The Polish CERT says this is the first documented case of an OT network being reached through a private APN [5], which matters because private APNs are widely treated as trusted carrier transport rather than as a routable network with hostile neighbours.
The chain is unglamorous and worth reading closely. It started with a compromised FortiGate VPN and firewall at a wind farm [6]. From there the attackers used a Teltonika cellular router on the same network to reach the DSO-managed private APN over an SSH tunnel [7]. They scanned the APN repeatedly and found a WAGO PFC200 programmable logic controller at the CHP plant whose web interface was reachable from the APN and protected only by default administrative credentials [8]. Having taken that controller, they used SSH to move into the plant's OT network and found three Siemens PLCs [9].
According to statements from plant personnel quoted in the report, those PLCs were switched to STOP mode and then locked with a password that prevented changes to their operating state or control logic [10]. The cogeneration process was interrupted [11]. The attackers then worked on the recovery timeline as well as the process: CERT.PL says they sabotaged several Moxa network devices, destroyed logs, damaged the WAGO controller, reset the Teltonika router, and restored the FortiGate to factory settings [12]. That is five different vendors' devices touched across the intrusion and the clean-up [1], across three separate environments: a wind farm network, a DSO's APN, and a plant's OT network [2].
CERT.PL's recommendations read as a list of assumptions that turned out to be wrong. Audit the private APN configuration and turn on client isolation between connected devices [13]. Treat the APN as untrusted and segment it from OT [14]. Strictly limit traffic between OT and the device acting as the APN gateway, monitor that traffic, and centrally log events from those gateway devices [15]. Minimise open ports reachable from the APN, change default credentials on everything attached to it, and put the APN and its gateway devices inside the scope of penetration tests, red teaming and architecture reviews [16].
The physical outcome was contained: the outage was short and no customers lost power [17]. The context is less comforting. The attacks took place on 29 and 30 December 2025 [19] during a campaign linked to Sandworm that hit 30 Polish renewable energy facilities and another large CHP plant [18]. An earlier January 2026 report covered a late-2025 attack involving wiper malware and attributed it to Sandworm [3]; this analysis took three months and missed that publication [2], so the APN vector went undocumented for at least a quarter after the intrusion [3].
Two things to watch. First, whether asset owners can actually produce an inventory of vendor-managed cellular routers sitting inside their networks, because the Teltonika device was the pivot and the FortiGate was only the entry [6][7]. Second, whether DSOs running private APNs can show client isolation is enabled [13], since without it every subscriber on the APN is a peer of every PLC on it.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The attackers forced the shutdown of a steam turbine and water treatment system at a large combined heat and power plant serving 50,000 residents.
The report states that, according to statements provided by CHP plant personnel, the PLCs were switched to STOP mode and protected with a password that prevented changes to their operating state and modification of the control logic.
As a result the steam turbine and the water treatment system used to produce process water were shut down, leading to an interruption of the cogeneration process.
CERT.PL claimed it is the first known documented attack in which threat actors have accessed an OT network through a private Access Point Name (APN).
The attack began after adversaries compromised a FortiGate VPN and firewall at a wind farm in Poland.
The attackers used a Teltonika cellular router on the same network to target a private APN network managed by a distribution system operator (DSO) via an SSH tunnel.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-sourced CERT relay
The account is unusually specific for an OT incident - named devices at each hop, the default-credential failure, quoted report language on PLC STOP mode, and an itemised sabotage list - and originates with a national CERT's post mortem. It is nonetheless carried by one publisher summarising that report, with no primary document link, no vendor or DSO response, and the physical-effect detail resting on plant personnel statements. That caps evidence well short of corroborated.
One confirmed intrusion inside a broad campaign
Real-world occurrence is established rather than hypothetical: a single documented private-APN-to-OT intrusion with a measurable physical effect, situated within a campaign against 30 renewable facilities and a second CHP plant. But the APN technique itself is evidenced at exactly one site, and there is no indication of the vector recurring elsewhere or of defenders having implemented CERT.PL's guidance.
Novelty framing slightly ahead of a mundane root cause
The 'first known documented' private-APN framing is the loudest element, yet the decisive failures described are ordinary: unchanged default admin credentials, an administrative web interface reachable from a supposedly closed carrier network, and no client isolation or OT segmentation. The article does discipline itself by reporting the short outage and absence of customer power loss, so the overstatement is modest rather than severe.
Institutional and traffic incentives, no vendor promotion
CERT.PL has an institutional interest in foregrounding novelty and in driving uptake of its own hardening recommendations, and the trade publication benefits from a dramatic critical-infrastructure narrative. Offsetting this, no product or vendor is being sold: Fortinet, Teltonika, WAGO, Siemens and Moxa equipment is named descriptively, and the guidance is configuration and process advice rather than a purchase recommendation.
Credible mechanics, unverified novelty, single publisher
Confidence is moderate: the technical chain is internally coherent, plausible and traceable to a national CERT post mortem, and the mitigation guidance stands on its own regardless of attribution. It is held down by having exactly one publisher, no primary report in evidence, an uncorroborated 'first documented' claim, and reliance on operator statements for the physical outcome.
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
security
A volunteer SOC for 45,000 water systems: what the Water Watch Center asks of operators1 distinct publisher
security
Siemens patches Parasolid: a crafted X_T file is the whole attack chain1 distinct publisher
security
Siemens patches a CAE overflow that lands in the sectors that patch workstations last1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.