Warsaw, Poland — August 10, 2026 — Polish cybersecurity authorities have disclosed a previously unknown cyberattack that disrupted a combined heat and power plant supplying approximately 50,000 residents during the winter of 2025.
The December 29 attack disabled a steam turbine and the facility’s water-treatment system, interrupting the cogeneration process used to produce electricity and heat. Plant operators restored the affected systems before heat deliveries to residents were interrupted.
CERT Polska said the incident occurred alongside coordinated destructive attacks against more than 30 wind and solar installations and a larger combined heat and power plant.
Those attacks were publicly disclosed in January and formally attributed in July to Russia’s Federal Security Service. CERT Polska did not separately attribute the newly disclosed heat-plant intrusion to the FSB or another state, criminal group or identified threat actor.
The second incident was initially treated as an operational failure rather than a cyberattack. The disruption occurred during maintenance over the Christmas period, leading plant personnel to suspect that a contractor error had caused the steam turbine and water-treatment systems to shut down.
Operators restored service quickly and reported the event for informational purposes. Its timing, combined with the attacks against other Polish energy facilities, led CERT Polska to open a broader technical investigation.
The investigation continued for more than three months and uncovered an attack path that crossed several industrial facilities through a private cellular data network.
CERT Polska described the case as the first known real-world cyberattack in which a private Access Point Name network was used to reach an operational technology environment.
Private APN networks provide dedicated mobile-data connections for industrial devices, remote facilities and distributed infrastructure. Energy operators use them to connect substations, renewable-energy installations and control equipment located outside traditional corporate networks.
These networks are frequently treated as isolated infrastructure because they are not directly exposed through ordinary public internet connections. The Polish investigation found that the private network lacked sufficient internal separation, allowing connected devices to communicate across facilities that otherwise had no direct operational relationship.
The attackers began their movement from firewalls compromised at wind-farm substations. From those systems, they reached a cellular router connected to the private APN and used the router to move toward the smaller heat plant.
A controller at the plant was still protected by factory-default login credentials. That weakness allowed the attackers to continue from the private cellular network into equipment connected to the plant’s industrial control environment.
The access path connected wind-energy substations, a cellular router and the heat plant even though the facilities were not part of the same operating site. Their shared position inside the private APN created the route used to cross between them.
CERT Polska determined that the attackers remained inside the environment for 11 days before disrupting operations. During that period, they examined industrial equipment, tested credentials against the plant’s firewall and mapped the systems supporting the facility.
The attackers connected to three Siemens controllers on Christmas Day. CERT Polska could not determine the exact purpose of the activity but assessed that the most likely explanation was reconnaissance in preparation for the destructive actions carried out four days later.
Before dawn on December 29, the attackers disabled Siemens controllers operating the steam turbine and water-treatment equipment. They changed controller passwords, preventing plant personnel from immediately regaining administrative access.
CERT Polska concluded with a high degree of confidence that the attackers automated the erasure of network-equipment configurations and assignment of unreachable addresses to affected devices. Those actions were intended to disrupt communications, delay recovery and force operators to rebuild portions of the environment.
Plant personnel began restoration work approximately two hours after attacker activity started while the attackers were still active inside parts of the infrastructure. Their response limited the incident to a short-term installation outage and prevented any interruption to customers’ heat or electricity supplies.
The attackers attempted to destroy evidence across the access path after the operational disruption. Firewalls and routers were reset, and the device used as the final gateway into the plant was damaged so extensively that it could not be returned to service.
Investigators reconstructed the intrusion because one router was running older software that retained its event records after a factory reset. Those surviving records helped identify the route through the private cellular network and connect activity across the affected systems.
CERT Polska said the private APN configuration that allowed devices to communicate freely was not limited to the compromised environment. Surveys of organizations using comparable cellular systems found that the same configuration was common in Poland and may also exist in industrial networks internationally.
The findings challenge the assumption that a privately operated cellular connection should automatically be considered trusted. A private APN can restrict access from the public internet while still exposing connected organizations to lateral movement if internal traffic is not segmented and authenticated.
A compromised device at one remote installation may provide access to other devices using the same mobile-data environment. The risk becomes more severe when industrial controllers, firewalls and cellular routers retain default credentials or expose administrative services across the shared network.
CERT Polska is urging energy companies and other industrial operators to audit every private APN connection, identify all connected equipment and determine which devices can communicate with one another.
Operators should remove default passwords, restrict administrative access, segment unrelated facilities and apply filtering rules between devices. Private cellular connections should also be included in penetration testing, asset inventories, logging programs and incident-response planning.
Security teams should examine cellular routers, industrial gateways, remote-access systems and connected controllers for outdated software, unsupported configurations and weak authentication. Logs from cellular providers and network equipment should be retained long enough to support investigations that may begin months after the original activity.
The case also demonstrates the importance of reporting unexplained equipment failures and operational disruptions, even when personnel initially believe the cause is accidental. A report that appears minor may reveal a broader attack when compared with activity affecting other facilities.
CERT Polska said the December campaign represented the first cyberattack against Poland’s energy sector in which the objective was purely destructive. The newly disclosed intrusion shows that the operation was more extensive than originally established and that the attackers were capable of moving between unrelated industrial sites through shared communications infrastructure.
The failure to interrupt residential heating was the result of the plant’s rapid operational response, not the absence of destructive activity. The attackers reached critical controllers, disabled production systems, obstructed administrative access and attempted to erase the technical evidence needed to reconstruct their actions.
The incident establishes private cellular infrastructure as a potential route into operational technology networks. Energy operators must treat every connection to an industrial environment as an external access path requiring authentication, segmentation, monitoring and continuous security review.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



