Ethical Hacking News
A recent cyberattack on a Polish power plant highlights the growing threat of vulnerabilities in industrial control systems, particularly those related to private access points networks (APNs). The attackers exploited a Teltonika router to gain access to the plant's operational technology (OT) network, demonstrating the need for robust cybersecurity measures and vulnerability assessments to prevent similar breaches. This incident underscores the critical importance of securing private APNs and industrial control systems to safeguard critical infrastructure.
The recent breach of a Polish power plant's controls through a private cellular network highlights the growing threat of vulnerabilities in industrial control systems. The attackers exploited a Teltonika router to gain access to the plant's operational technology (OT) network, initially gaining access via a compromised FortiGate device. The hackers gained control of the plant's Siemens PLCs over the S7 protocol and were able to shut down critical systems by switching them to STOP mode and password-protecting them. The breach was made possible by a configuration that allowed arbitrary devices on the private APN to communicate with one another, highlighting the importance of securing private access points networks (APNs). The incident underscores the need for robust cybersecurity measures in critical infrastructure and highlights the vulnerabilities of industrial control systems.
The recent breach of a Polish power plant's controls through a private cellular network has sent shockwaves throughout the cybersecurity community, highlighting the growing threat of vulnerabilities in industrial control systems. The incident, which occurred in December 2025 and was recently disclosed by CERT Polska, involved hackers exploiting a Teltonika router to gain access to the plant's operational technology (OT) network.
According to the investigation conducted by CERT Polska, the attackers initially gained access to the wind farm's system, where they exploited a compromised FortiGate device that had an exposed VPN and lacked multi-factor authentication. This allowed them to obtain VPN credentials that could reach all network segments, providing a pivot point for further exploitation. The hackers then utilized SSH tunneling through the router to connect to the private APN, which led them to the WAGO PFC200 controller exposing its web administration interface with default admin credentials.
The attackers subsequently gained control of the plant's Siemens PLCs over the S7 protocol, which they believed was part of reconnaissance for later destructive actions. On December 29, the hackers successfully shut down the turbine and process-water treatment system by switching it to STOP mode and password-protecting it, as well as factory-resetting seven Moxa serial device servers and three switches.
The breach was made possible by a configuration that allowed arbitrary devices on the private APN to communicate with one another. CERT Polska advises treating the APN as untrusted from an OT perspective, segmenting and restricting traffic, removing unnecessary management services from APN-reachable interfaces, and changing default credentials.
The investigation also revealed that the Teltonika router's SSH service, controller's web interface, and permissive APN were all working as configured. The attackers took advantage of this by exploiting a possible unpublished flaw in the router's firmware, which is not yet documented or disclosed by CISA.
This incident highlights the critical importance of securing private access points networks (APNs) to prevent similar breaches. According to CERT Polska's surveys, many organizations running private APNs allow any device on the network to reach any other device, which is a common configuration that can be exploited by attackers.
The Polish power plant breach underscores the need for robust cybersecurity measures in critical infrastructure. The incident has been assessed as part of a wider December campaign that targeted several other organizations and systems, including government agencies, industrial control networks, and energy sectors.
In response to this growing threat landscape, it is essential for organizations to prioritize cybersecurity awareness, implement robust security protocols, and conduct regular vulnerability assessments to prevent similar breaches in the future. As the importance of securing private APNs grows, it is crucial that policymakers, industry leaders, and cybersecurity experts work together to develop and disseminate best practices for safeguarding these critical systems.
The attack on the Polish power plant also sheds light on the vulnerabilities of industrial control systems and the need for manufacturers to prioritize security in their products. The Teltonika router's vulnerabilities, which are not yet fully disclosed or patched by CISA, demonstrate the need for ongoing monitoring and vigilance by both end-users and cybersecurity professionals.
In conclusion, the breach of the Polish power plant highlights the growing threat landscape of industrial control system breaches and the importance of securing private APNs. By prioritizing cybersecurity awareness, implementing robust security protocols, and conducting regular vulnerability assessments, organizations can reduce their risk of similar breaches and safeguard critical infrastructure.
Related Information:
https://www.ethicalhackingnews.com/articles/Hacking-the-Grid-A-Closer-Look-at-the-Polish-Power-Plant-Breach-via-Private-Cellular-Network-ehn.shtml
https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html
Published: Tue Aug 11 03:38:46 2026 by llama3.2 3B Q4_K_M