Skip to content
Beveiligingsnieuws

Private APN Attack Vector in Poland’s Power Grid

Private APN pivot

Poland’s CERT.PL has published findings about a second cyberattack against the country’s energy sector in December 2025. While the earlier disclosure described destructive intent against industrial control systems (ICS), this new report adds a key technical twist: attackers used a private APN attack vector to reach operational technology (OT) networks tied to substations.

According to the report, threat activity aligned with Sandworm—an APT associated in public reporting with the Russian government—targeted communication and control environments across multiple energy sites. In this case, investigators concluded the objective was sabotage rather than intelligence gathering.

A second strike aimed at a smaller heat-and-power site

CERT.PL states that the December 2025 assault occurred in parallel with a previously disclosed intrusion. This time, the target was a smaller combined heat and power (CHP) facility responsible for heat delivery to roughly 50,000 residents.

The investigation concluded the attackers focused on systems that affect industrial operations, not on directly forcing power generation output to fail. Even so, the incident still had tangible operational impact.

What the attackers managed to disrupt

The reported sabotage resulted in the shutdown of two critical functions: a steam turbine and a water treatment system. Together, these disruptions interrupted the cogeneration process—meaning the plant could not produce the expected combined heat and electricity service.

Importantly, CERT.PL also notes that the outage window was limited. Plant staff restored affected systems quickly, and the heat and electricity supply was not interrupted for customers.

How the intrusion started: from edge devices to OT

The pathway into the OT environment followed a pattern that begins at the edge and climbs toward industrial networks. The intrusion started on internet-connected perimeter equipment at a wind farm, specifically a Fortinet VPN and firewall device.

From there, the attackers moved laterally within the same network and identified a Teltonika cellular router. They then accessed its administrative interface and leveraged an SSH service to establish a tunnel onward to the operator-managed private APN environment.

This is where the private APN attack vector became central. Private APN networks are designed to enable communications between a distribution system operator’s SCADA systems and ICS deployed at substations. In other words, they are a bridge between enterprise-like monitoring and real-world industrial control.

Scanning the private APN network for PLC access

Once the tunnel was established, the attackers performed reconnaissance inside the private APN network and identified a Wago programmable logic controller (PLC) at the CHP plant.

With SSH enabled on the controller, the threat actor gained access to the facility’s OT networks. This step matters because PLCs are often treated as sensitive control points, and direct access can enable changes to operating modes, logic, or safety-related behavior.

Sabotage steps: stopping controls and locking operators out

CERT.PL reports that after about a week of reconnaissance, the attacker connected to Siemens PLCs and switched them to a ‘stop’ mode. They also set a password intended to prevent operators from changing controller operating states and control logic.

These actions directly contributed to the shutdown of the steam turbine and water treatment systems. The attackers’ approach suggests they aimed to halt key processes and reduce the ability of onsite staff to recover quickly.

Device targeting beyond PLCs

The report also indicates the attackers did not limit themselves to the PLCs. Moxa serial device servers and Moxa network switches were targeted, with configuration changes intended to prevent legitimate operators from accessing them.

In addition, CERT.PL notes that ABB and Schneider Electric variable frequency drives were targeted. However, the report says it is unclear what the attackers actually did to those devices, and some connection attempts were unsuccessful.

In line with the broader “destructive” intent described by CERT.PL, the attackers also bricked some compromised ICS devices. In certain cases, they permanently damaged devices while trying to cover their tracks.

Why the private APN configuration mattered

CERT.PL emphasizes that this appears to be the first time threat actors used a private APN attack vector as an approach for reaching OT systems in this manner. The warning is practical: the same or similar vulnerable configuration has been commonly observed not only in Poland, but also internationally.

For energy operators, this highlights that “private” does not automatically mean “unreachable.” If authentication controls, exposure management, and segmentation are insufficient, a private APN can still become an avenue for unauthorized access—especially when the attacker can reach an internet-facing starting point and then pivot into operator-managed connectivity.

Recovery under time pressure

At the targeted facility, the disruption occurred during maintenance work. Initially, responders believed an engineering error might have caused the downtime. CERT.PL later determined the cause was hacker activity.

To limit downtime, staff reset affected PLCs to factory settings and reloaded logic from backups. That operational discipline appears to have reduced the duration of the incident and helped restore services without prolonged customer impact.

When recovery still fails: corrupted partitions and lost data

One especially damaging element described in the report involves the Wago controller that served as a gateway into the OT network. The attackers damaged it by corrupting its partition table, which prevented the device from being read by the controller.

Afterward, an attempt to restore the controller through a factory reset did not fix the partition table. The device remained unable to boot.

CERT.PL adds that no valuable logs could be recovered from the compromised device during the investigation—an outcome consistent with sabotage and anti-forensics goals.

Takeaways for OT and energy security teams

This incident reinforces several themes that security leaders in energy and industrial environments are increasingly focused on.

  • Edge-to-OT pathways are real: Even a targeted intrusion that begins at VPN/firewall infrastructure can quickly escalate toward PLCs and control networks.
  • Connectivity between SCADA and ICS must be tightly controlled: Private APN links can enable legitimate operations, but they can also become an attack route if configuration and access controls are weak.
  • Recovery plans matter: The ability to restore PLC logic from backups limited impact, even when the attackers tried to stop controllers and lock out operator changes.
  • Destruction and anti-forensics may coexist: Bricking devices and corrupting partitions reduced forensic value, making detection and response harder.

Conclusion

CERT.PL’s report outlines a second December 2025 attack on Poland’s energy sector that used a private APN attack vector to reach OT networks and carry out sabotage. Although the disruption shut down key processes, the plant recovered quickly enough that heat and electricity supply were not interrupted for residents.

At the same time, the case shows how challenging it can be to investigate and recover when devices are permanently damaged and logs cannot be retrieved. For operators, the lesson is clear: protecting industrial systems requires scrutiny of every layer that supports communications, including private connectivity components.

Source: https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/