← Back to Daily Briefing (#Pentesting)

A three-month forensic investigation by CERT Polska and IOActive into the December 2025 cyberattack on the Polish energy sector has confirmed a multi-target campaign impacting at least two Combined Heat and Power (CHP) plants. The investigation identified a novel exploitation of private Access Point Names (APNs) used for cellular-based industrial connectivity. By leveraging these cellular-to-OT bridges, threat actors successfully bypassed traditional network perimeter defenses to access critical ICS/OT control systems. The incident involved the deployment of specialized ICS/OT malware, highlighting a sophisticated pivot from mobile telecommunications infrastructure directly into critical national infrastructure environments.

  • Incident Overview: Multi-Target Campaign

    • Forensic evidence confirms the December 2025 attack was not an isolated breach but a broader, coordinated campaign.
    • The scope of impact has expanded to include at least two distinct Combined Heat and Power (CHP) plants.
    • The formal investigation concluded in August 2026 following over three months of deep-dive forensic analysis.
  • Attack Vector: Private APN Exploitation

    • Threat actors utilized a highly novel methodology involving the exploitation of private Access Point Names (APNs).
    • The campaign leveraged cellular-based industrial connectivity to establish a bridge between mobile networks and OT environments.
    • This specific vector allowed attackers to circumvent traditional network perimeter security and air-gapped assumptions.
  • Technical Artifacts: ICS/OT Impact

    • Identification of specialized ICS/OT-specific malware through intensive binary triage.
    • Successful compromise of control system architectures specifically within the affected CHP facilities.
    • Documentation of a successful pivot from mobile telecommunications infrastructure into the core industrial control layer.
  • Industry Implications and Defense Response

    • The incident underscores the critical risks inherent in the convergence of mobile telecommunications and ICS/OT environments.
    • Critical infrastructure providers must implement enhanced monitoring for cellular-to-OT bridge vulnerabilities.
    • Hardening private APN configurations and securing all mobile connectivity endpoints is now a high-priority defensive requirement.
  • Conclusion

    • The Polish energy sector incident serves as a high-signal warning regarding the security of cellular-connected critical infrastructure.
    • Future remediation and architectural strategies must account for non-traditional network entry points beyond standard IT/OT boundaries.

Related posts

  1. Malware News — Follow-Up Report of the December 2025 Energy Sector Incident
  2. Security Affairs — Hackers Cross From IT to OT Through a Private APN in Poland
  3. feeds.feedburner.com — Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
  4. Industrial Cyber — CERT Polska exposes multi-stage cyberattack on energy infrastructure involving VPN, private APN, OT network tunneling
  5. Cert
  6. Thehackernews
  7. Cisa
  8. Industrialcyber
  9. Reddit
  10. Ioactive
  11. Ceenergynews
  12. 4m4
  13. The Record by Recorded Future — Poland uncovers second heat plant cyberattack that went hidden for months
  14. Helpnetsecurity
  15. Daily
  16. Indurex
  17. Dev
  18. Omicroncybersecurity
  19. Industrialcyber
  20. bleepingcomputer.com — Hackers breached a small Polish energy plant via private APN last year
  21. helpnetsecurity.com — Previously unseen entry vector used to breach Polish energy plant
  22. gbhackers.com — Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant
  23. Securityweek
  24. Infosecurity-magazine
  25. Daily
  26. Cyberpress
  27. SecurityWeek — Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

LINK COPIED TO CLIPBOARD