bleeping-computer · Crawled Aug 11, 2026

Hackers breached a small Polish energy plant via private APN last year

3 IoCs 1 Actors
Read original article ↗

AI Summary

In December 2025, a threat actor linked to the Russian Electrum group breached a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers gained initial access through a compromised FortiGate firewall and Teltonika cellular router at a wind farm, then moved laterally through the private APN to reach the CHP plant's operational technology (OT) network. They exploited default credentials on a WAGO PFC200 PLC, used it as a bridge to access Siemens PLCs, and ultimately shut down critical systems including the steam turbine and water treatment system.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain apn Details →
Filename PFC200 Details →
Filename SCADA Details →

MITRE ATT&CK TTPs 23 techniques