Breaking
Cyber CrimeConfirmed

APN Pivot Lets Sandworm Sabotage Second Polish Plant

CERT.PL details how a private APN pivot enabled destructive attacks on a second energy facility.

··8 hours ago·4 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

Late last month, Poland’s computer emergency response team published a report detailing a second attack on the country’s power grid. This time, the attackers, linked to the Russian government and known as Sandworm, may have used a private APN as an attack vector for the first time, according to CERT.PL.

Parallel Attack on a Smaller Plant

In late December 2025, the same threat actors targeted roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities. While that attack focused on grid safety and stability monitoring systems rather than active power generation, this second incident, conducted in parallel, was aimed at a smaller CHP plant supplying heat to 50,000 residents.

The Polish CERT’s report says that the cyberattack caused the shutdown of a steam turbine and a water treatment system, disrupting the cogeneration process. However, systems were quickly restored, and heat and electricity supply were not interrupted.

Initial Confusion: Engineering Error or Attack?

The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption. But CERT soon determined it was the result of hacker activity.

This second incident highlights a concerning trend: the attackers didn’t stick to the same playbook. They adapted and found a new way in, using a private APN network—a communication channel typically trusted by industrial operators.

From Wind Farm Edge to OT Network

The intrusion started on a Fortinet VPN and firewall device at a wind farm, connected to the internet. The hackers then identified a Teltonika cellular router on the same network and accessed its admin interface.

An SSH service running on the device was used to establish a tunnel that enabled communication to a private APN network managed by the distribution system operator (DSO). These private APN networks enable communication between the DSO’s SCADA system and ICS installed at substations.

The attacker scanned the private APN network and identified a Wago programmable logic controller (PLC) running at a CHP plant. An SSH service enabled on this controller gave the attacker access to the plant’s operational technology (OT) networks.

Week-Long Reconnaissance, then Sabotage

After conducting reconnaissance over the course of one week, the threat actor connected to Siemens PLCs, switched them to ‘stop’ mode, and set a password to prevent operators from changing the controllers’ operating state and control logic. These actions caused the shutdown of the steam turbine and water treatment systems.

Staff managed to limit downtime by resetting the affected PLCs to their factory settings and reloading logic from backups.

Moxa serial device servers and Moxa network switches were also targeted, configured to prevent legitimate operators from accessing them. ABB and Schneider Electric variable frequency drives were targeted too, but it’s unclear what actions were carried out, and some connection attempts were unsuccessful.

Bricked Devices and Covering Tracks

Similar to the first attack, the hackers bricked some compromised ICS devices. According to the Polish CERT, some devices were permanently damaged as part of the attackers’ attempts to cover their tracks.

“The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot. No valuable logs could be recovered from the device during the investigation.”

— From the CERT.PL report, as cited by SecurityWeek

First Known Use of Private APN as Vector

The Polish CERT highlights that this appears to be the first time threat actors used a private APN as an attack vector. They warn that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world.

In the first attack, the hackers targeted communication and control systems at about 30 sites. While some ICS devices were permanently damaged, that attack did not cause electrical outages. This second incident, though smaller in scale, underscores a broader concern about the security of industrial networks.

Key Facts at a Glance

  • Roughly 30 sites targeted in the first December attack
  • Smaller CHP plant in second attack supplies heat to 50,000 residents
  • Attack caused shutdown of a steam turbine and a water treatment system
  • Reconnaissance conducted over one week before sabotage

Why This Matters for Industrial Operators

The use of a private APN as a pivot point is a worrying development for energy providers and other critical infrastructure operators. Private APNs are often assumed to be secure because they are isolated from the public internet, but this attack shows that if an attacker compromises an edge device—like a wind farm’s firewall—they can tunnel into what was thought to be a protected network.

For organizations running similar configurations, this report suggests that the assumption of trust in private APNs may need to be revisited. The fact that the same vulnerable configuration has been commonly encountered in Poland and elsewhere means that other facilities could be exposed to similar attacks.

While no outages occurred in this incident, the damage to ICS devices and the attackers’ method of covering their tracks—by bricking the gateway device—point to a persistent and adaptive threat. This could mean that other energy facilities, especially those with similar OT setups, need to shore up their edge security and monitor for unusual tunneling activity.

#sandworm#poland#energy-sector#private-apn#ot-security#ics

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories