GBHackers

Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant


Threat actors used a private cellular access-point-name (APN) network to pivot from a compromised wind farm into the operational technology environment.

A Polish combined heat and power plant, where they disrupted Siemens programmable logic controllers and briefly interrupted cogeneration operations.

The December 29, 2025 intrusion affected a CHP facility serving approximately 50,000 residents, forcing a steam turbine and the process-water treatment system offline.

Operators restored the installation before heat or electricity deliveries to customers were affected.

The attack chain began at a wind farm, where the adversary had access to a FortiGate appliance serving as both a firewall and a VPN concentrator.

The internet-facing VPN accepted locally configured accounts without multi-factor authentication, creating a high-value foothold in a distributed-energy environment.

From that network, the attackers identified a Teltonika RUTX50 cellular router connected to a distribution system operator’s private APN.

Although the APN was intended to carry communications between the DSO’s SCADA infrastructure and remote terminal units, its design enabled peer-to-peer reachability between connected devices.

The adversary accessed the router’s administrative functions and used SSH to build a tunnel into the APN.

CERT Polska Researchers said that, follow-up investigation describes the incident as the first known real-world attack in which a private APN was used as a lateral-movement path into an OT network.

The router model deployed at the affected facility exposes a web admin‑istration interface and an SSH service on its LAN interface by default.

Beginning December 18, the operators scanned the private network for VNC, HTTP, Modbus, and Siemens S7 services. They eventually identified a WAGO PFC200 controller at the CHP plant.

Placement of the Cellular Router Within a Segment of the Wind Farm Network (Source : CERT).

Its WAN-facing management interface was reachable from the APN and protected by default credentials for the admin account.

Siemens PLC Network

After authenticating to the device, the attackers appear to have enabled SSH and created another tunnel this time into the plant’s internal OT environment.

Inside the CHP network, the actors conducted reconnaissance from December 18 through December 25.

Illustrative diagram of the attack against the CHP plant leveraging a private APN (Source : CERT).
Illustrative diagram of the attack against the CHP plant leveraging a private APN (Source : CERT).

They probed firewall administration interfaces, remote-access services, and industrial systems, including TCP/102 for Siemens S7, TCP/502 for Modbus, and TCP/11740 for CODESYS.

The scanning sequence suggests an operator who understood that the SCADA host and controllers represented the fastest route to process disruption.

On the morning of December 29, the attackers accessed the SCADA web interface and connected over S7 to Siemens S7-300, S7-1200, and S7-1500 PLCs.

Plant personnel determined that the controllers had been placed into STOP mode and protected with passwords that prevented changes to their operating state or control logic.

The result was operational rather than merely administrative impact: the steam turbine halted, the water-treatment system stopped producing process water, and cogeneration was interrupted. Recovery required operators to factory-reset affected PLCs and reload logic from backups.

While that response contained downtime, it also erased controller-resident evidence; Siemens ProductCERT confirmed the logs could not be recovered.

The sabotage extended beyond Siemens equipment. The attackers altered configuration on seven Moxa serial-device servers and three Moxa switches, changing credentials and assigning unreachable addresses such as 127.0.0.1.

They also reached web interfaces on ABB drives and unsuccessfully attempted to access Schneider Electric variable-frequency drives.

Before exiting, the actors corrupted the WAGO controller’s partition table, leaving it unbootable even after a factory reset.

They also reset the Teltonika router and the original FortiGate device, actions that impeded recovery and eliminated forensic records.

The case reinforces that a private APN is not automatically a trusted OT transport.

CERT Polska recommends client isolation, strict allowlisting between APN gateways and OT assets, centralized logging, removal of externally reachable administrative services, credential hygiene, and explicit APN coverage in penetration tests.

The incident is linked to a wider destructive campaign against Polish energy infrastructure that targeted more than 30 renewable facilities and other organizations on the same day.

Why use the 2026 Agentic SOC Buyer’s Guide? 8 Best Platforms Compared – Download the 2026 Buyer’s Guide



Source link