Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Read original article ↗AI Summary
In December 2025, attackers breached a Polish combined heat and power (CHP) plant by exploiting a private cellular network (APN) used by the grid operator. The intrusion originated from a compromised wind farm's FortiGate firewall, which had internet-exposed VPN services without multi-factor authentication. From there, attackers pivoted via SSH tunneling through a Teltonika RUTX50 router to access a WAGO PFC200 controller with default credentials, ultimately gaining control of Siemens PLCs and shutting down critical systems including a steam turbine and water treatment. No malware was used; destructive actions were carried out using legitimate device functions. The attack highlights risks in misconfigured private APNs and poor credential hygiene in operational technology environments.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.