A three-month forensic investigation by CERT Polska and IOActive into the December 2025 cyberattack on the Polish energy sector has confirmed a multi-target campaign impacting at least two Combined Heat and Power (CHP) plants. The investigation identified a novel exploitation of private Access Point Names (APNs) used for cellular-based industrial connectivity. By leveraging these cellular-to-OT bridges, threat actors successfully bypassed traditional network perimeter defenses to access critical ICS/OT control systems. The incident involved the deployment of specialized ICS/OT malware, highlighting a sophisticated pivot from mobile telecommunications infrastructure directly into critical national infrastructure environments.
-
Incident Overview: Multi-Target Campaign
- Forensic evidence confirms the December 2025 attack was not an isolated breach but a broader, coordinated campaign.
- The scope of impact has expanded to include at least two distinct Combined Heat and Power (CHP) plants.
- The formal investigation concluded in August 2026 following over three months of deep-dive forensic analysis.
-
Attack Vector: Private APN Exploitation
- Threat actors utilized a highly novel methodology involving the exploitation of private Access Point Names (APNs).
- The campaign leveraged cellular-based industrial connectivity to establish a bridge between mobile networks and OT environments.
- This specific vector allowed attackers to circumvent traditional network perimeter security and air-gapped assumptions.
-
Technical Artifacts: ICS/OT Impact
- Identification of specialized ICS/OT-specific malware through intensive binary triage.
- Successful compromise of control system architectures specifically within the affected CHP facilities.
- Documentation of a successful pivot from mobile telecommunications infrastructure into the core industrial control layer.
-
Industry Implications and Defense Response
- The incident underscores the critical risks inherent in the convergence of mobile telecommunications and ICS/OT environments.
- Critical infrastructure providers must implement enhanced monitoring for cellular-to-OT bridge vulnerabilities.
- Hardening private APN configurations and securing all mobile connectivity endpoints is now a high-priority defensive requirement.
-
Conclusion
- The Polish energy sector incident serves as a high-signal warning regarding the security of cellular-connected critical infrastructure.
- Future remediation and architectural strategies must account for non-traditional network entry points beyond standard IT/OT boundaries.
Related posts
- Malware News — Follow-Up Report of the December 2025 Energy Sector Incident
- Cert
- Thehackernews
- Cisa
- Industrialcyber
- Ioactive
- Ceenergynews
- 4m4