← Back to Daily Briefing

A three-month forensic investigation by CERT Polska and IOActive into the December 2025 cyberattack on the Polish energy sector has confirmed a multi-target campaign impacting at least two Combined Heat and Power (CHP) plants. The investigation identified a novel exploitation of private Access Point Names (APNs) used for cellular-based industrial connectivity. By leveraging these cellular-to-OT bridges, threat actors successfully bypassed traditional network perimeter defenses to access critical ICS/OT control systems. The incident involved the deployment of specialized ICS/OT malware, highlighting a sophisticated pivot from mobile telecommunications infrastructure directly into critical national infrastructure environments.

  • Incident Overview: Multi-Target Campaign

    • Forensic evidence confirms the December 2025 attack was not an isolated breach but a broader, coordinated campaign.
    • The scope of impact has expanded to include at least two distinct Combined Heat and Power (CHP) plants.
    • The formal investigation concluded in August 2026 following over three months of deep-dive forensic analysis.
  • Attack Vector: Private APN Exploitation

    • Threat actors utilized a highly novel methodology involving the exploitation of private Access Point Names (APNs).
    • The campaign leveraged cellular-based industrial connectivity to establish a bridge between mobile networks and OT environments.
    • This specific vector allowed attackers to circumvent traditional network perimeter security and air-gapped assumptions.
  • Technical Artifacts: ICS/OT Impact

    • Identification of specialized ICS/OT-specific malware through intensive binary triage.
    • Successful compromise of control system architectures specifically within the affected CHP facilities.
    • Documentation of a successful pivot from mobile telecommunications infrastructure into the core industrial control layer.
  • Industry Implications and Defense Response

    • The incident underscores the critical risks inherent in the convergence of mobile telecommunications and ICS/OT environments.
    • Critical infrastructure providers must implement enhanced monitoring for cellular-to-OT bridge vulnerabilities.
    • Hardening private APN configurations and securing all mobile connectivity endpoints is now a high-priority defensive requirement.
  • Conclusion

    • The Polish energy sector incident serves as a high-signal warning regarding the security of cellular-connected critical infrastructure.
    • Future remediation and architectural strategies must account for non-traditional network entry points beyond standard IT/OT boundaries.

Related posts

  1. Malware News — Follow-Up Report of the December 2025 Energy Sector Incident
  2. Cert
  3. Thehackernews
  4. Cisa
  5. Industrialcyber
  6. Reddit
  7. Ioactive
  8. Ceenergynews
  9. 4m4

LINK COPIED TO CLIPBOARD