Ethical Hacking News
A recent cyberattack on Poland's energy sector highlights the vulnerabilities of private APNs and their potential risks to critical infrastructure. The attackers breached the facility's network through a Fortinet VPN and firewall device exposed to the internet, using weak or exposed access points and enough patience to move from reconnaissance to disruption.
The recent cyberattack on Poland's energy sector highlights vulnerabilities of private Access Points (APNs) in critical infrastructure. The attackers breached the facility's network through a Fortinet VPN and firewall device exposed to the internet, using a Teltonika cellular router as an entry point. The attackers successfully breached the WAGO PLC at the CHP plant and connected to Siemens PLCs, switching them to stop mode and setting a password that blocked operators from changing the controllers' state and control logic. Securing private APNs and edge routers in critical infrastructure environments is crucial to prevent similar attacks. The attackers used a reachable edge device, weak or exposed access points, and patience to breach the facility's network, highlighting the importance of robust security measures.
The recent cyberattack on Poland's energy sector has shed light on the vulnerabilities of private Access Points (APNs) and their potential risks to critical infrastructure. According to a report by Poland's CERT, a coordinated attack targeted 30 renewable energy facilities and a large combined heat and power plant in December 2025. The attackers managed to breach the facility's network through a Fortinet VPN and firewall device exposed to the internet.
The attackers then found a Teltonika cellular router, used SSH to build a tunnel, reached the private APN managed by the distribution system operator, and then moved toward the plant's operational network (OT) network. The attackers successfully breached the WAGO PLC at the CHP plant and connected to Siemens PLCs, switching them to stop mode and setting a password that blocked operators from changing the controllers' state and control logic.
This attack highlights the importance of securing private APNs and edge routers in critical infrastructure environments. The attackers did not need an exotic zero-day chain to do damage; instead, they used a reachable edge device, weak or exposed access points, and enough patience to move from reconnaissance to disruption. The report notes that this kind of attack vector is not rare, which is why the finding matters beyond Poland.
The incident was first reported by ESET researchers, who attributed the attack to the Russia-linked Sandworm APT group with medium confidence due to a strong overlap with previous Sandworm wiper activity. While no successful disruption has been confirmed, the malware's architecture shows clear destructive intent. The incident is also linked to a previous Sandworm cyberattack on Ukraine's power grid in 2015.
The attack demonstrates how an ordinary-looking network design can turn into a route into OT. Poland's CERT notes that the entity initially assumed that the process interruption had been caused by an error made by the contractor's engineers and reported the event for informational purposes only. However, due to its awareness of other similar events, CERT Polska initiated incident handling under the assumption that the event may have resulted from a cyberattack.
The practical lesson is not subtle. Private APNs, edge routers, and OT gateways need the same discipline as any other exposed infrastructure, because once an attacker can pivot from a field device into control systems, the difference between "maintenance" and "incident" gets very thin.
Related Information:
https://www.ethicalhackingnews.com/articles/Hackers-Unprecedented-Attack-on-Polands-Energy-Sector-Highlights-Vulnerabilities-of-Private-APNs-ehn.shtml
https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html
Published: Mon Aug 10 12:26:51 2026 by llama3.2 3B Q4_K_M