Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Sandworm APT used private APN to sabotage Polish energy facility.
Summary
Russian state-sponsored threat actors, identified as Sandworm APT, have conducted a second destructive cyberattack on Poland's energy sector. This attack, which targeted a smaller CHP plant, notably utilized a private APN as a novel attack vector for the first time. The hackers disrupted operations by shutting down a steam turbine and water treatment system, causing damage to ICS devices, though power supply remained uninterrupted.
Full text
Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”. In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities. In that attack, the hackers gained access to ICS, but mainly targeted grid safety and stability monitoring systems rather than active power generation systems. While some ICS devices were permanently damaged, the attack did not cause any electrical outages. In a report published over the weekend, CERT.PL revealed that the country’s energy sector was targeted in a second attack in December 2025. An investigation revealed that this attack, conducted in parallel with the previously disclosed hack, was aimed at a smaller CHP plant supplying heat to 50,000 residents. The Polish CERT’s report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world. The cyberattack caused the shutdown of a steam turbine and a water treatment system, which resulted in a disruption of the cogeneration process. However, the systems were quickly restored, and heat and electricity supply were not interrupted. The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption, but the CERT soon determined that it was the result of hacker activity. Advertisement. Scroll to continue reading. From an edge device to an energy facility’s OT network The intrusion started on a Fortinet VPN and firewall device located at a wind farm and connected to the internet. The hackers then identified a Teltonika cellular router on the same network and accessed its admin interface. An SSH service running on the device was then used to establish a tunnel that enabled communication to a private APN network managed by the distribution system operator (DSO). These private APN networks enable communication between the DSO’s SCADA system and ICS installed at the substation. The attacker scanned the private APN network and identified a Wago programmable logic controller (PLC) running at a CHP plant. An SSH service enabled on this controller gave the attacker access to the plant’s operational technology (OT) networks. SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity After conducting reconnaissance over the course of one week, the threat actor connected to Siemens PLCs, switched them to ‘stop’ mode, and set a password to prevent operators from changing the controllers’ operating state and control logic. These actions caused the shutdown of the steam turbine and water treatment systems. Staff managed to limit the downtime by resetting the affected PLCs to their factory settings and reloading logic from backups. Moxa serial device servers and Moxa network switches were also targeted by the attackers and configured to prevent the legitimate operators from accessing them. ABB and Schneider Electric variable frequency drives were also targeted by the attackers, but it’s unclear what actions they carried out on these devices, and some attempts to connect to them were unsuccessful. Similar to the attack on the first energy facility, the hackers bricked some of the compromised ICS devices. According to the Polish CERT, some devices were permanently damaged as part of the attackers’ attempts to cover their tracks. “The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot. No valuable logs could be recovered from the device during the investigation.” Related: Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Related: Water Sector Cyberattacks Reportedly Hit at Least 12 States Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Truck Brake Controller’s Safety Recall Doubled as Hidden Security FixSnowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsMeta AI Hacked External Systems During Cybersecurity TestingHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 States Latest News New Jersey, Alabama Join States Targeted in Water CyberattacksMetabase Patches Vulnerability Exploited as Zero-DayCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityCorporate Data Stolen in Levi Strauss CyberattackCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetVishing Extortion Group UNC6671 Rebrands After Making Millions Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously a
Indicators of Compromise
- malware — Sandworm