Russian Hackers Used an Obscure Telecom Back Door to Shut Down a Polish Heating Plant

A second cyberattack on Poland's energy sector, running alongside a previously disclosed assault, exploited a rarely scrutinised type of private mobile network to reach deep inside a plant supplying heat to 50,000 people.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A district heating plant's control room with large industrial gauges showing pressure and temperature readings, technicians monitoring SCADA screens showing the
Share

Key points

  • Poland's national computer security team, CERT.PL, confirmed a second attack on the country's energy sector in December 2025, separate from but simultaneous with a previously reported assault.
  • Hackers linked to the Russian government group known as Sandworm broke into a combined heat and power plant serving roughly 50,000 residents.
  • The attackers locked industrial controllers, causing a steam turbine and water treatment system to shut down, though engineers restored heat and electricity supply within hours.
  • CERT.PL says this is the first recorded case of attackers using a private APN (a private mobile data channel used by utilities to connect remote equipment) as a route into an industrial network.
  • No electrical or heating outages reached residents, but several pieces of industrial hardware were permanently destroyed.

Polish authorities thought it was an engineering mistake. It wasn't.

When systems at a combined heat and power plant, a facility that produces both electricity and hot water for homes from a single fuel source, suddenly failed during routine maintenance in December 2025, staff initially blamed human error. Poland's national computer emergency response team, CERT.PL, soon established the real cause: hackers connected to the Russian government had remotely switched off the plant's industrial controllers.

CERT.PL published its findings over the weekend. The attack ran in parallel with a larger, already-reported assault on roughly 30 Polish energy sites attributed to Sandworm, a hacking group operated by Russian military intelligence. That first attack damaged monitoring equipment but caused no power cuts. This second attack went further. The wider campaign sits in the context we reported on 15 July 2026, when EU, UK and French governments sanctioned Russia over coordinated infrastructure attacks across more than a dozen countries.

How did the hackers get in?

They entered through a wind farm, not the plant itself. Several steps and about a week of quiet reconnaissance preceded any visible damage.

First, the attackers found a Fortinet VPN and firewall device, the kind organisations use to let remote workers connect securely, at a wind farm connected to the internet. From there they reached a Teltonika cellular router on the same network and accessed its administration panel. An SSH service on that router, SSH being a standard remote-access protocol that lets a computer be controlled over a network, was used to open a tunnel into a private APN.

A private APN, or Access Point Name, is a dedicated mobile data channel, similar to a private lane on a motorway, that Polish grid operators use to let their central control software talk to equipment at remote substations. CERT.PL says this type of channel has rarely been considered an attack route, and that the same poorly secured configuration is common across Poland and internationally.

Through that channel the attackers found a Wago programmable logic controller (PLC), a small computer that physically operates industrial machinery, running at the heat and power plant. An SSH service left enabled on that controller gave them full access to the plant's operational network.

What exactly did they do once inside?

They switched machines off and locked the doors behind them. After a week of silent reconnaissance, the attackers connected to Siemens PLCs, set them to stop mode, and applied password protection so plant engineers couldn't override the commands or reload the control software. That triggered the shutdown of the steam turbine and a water treatment system.

Engineers recovered by resetting the affected controllers to factory settings and reloading software from backups. Moxa network switches and serial device servers were also tampered with to block legitimate access. ABB and Schneider Electric variable frequency drives were targeted too, though what the attackers did on those devices isn't fully clear.

Before leaving, the attackers destroyed evidence. They corrupted the storage partition of the Wago controller used as the entry point into the plant network, making it unbootable and wiping the logs investigators needed.

Event Detail
Attack period December 2025
Entry point Fortinet VPN device at a wind farm
Pivot route Private APN mobile data channel
Target facility CHP plant serving 50,000 residents
Effect on residents No heat or electricity interruption
Permanently damaged devices Multiple ICS units, including one Wago PLC

Should residents be worried?

No outage reached homes this time. Heat and electricity supply wasn't interrupted, and CERT.PL says engineers restored systems quickly.

The real concern is structural. Private mobile data channels weren't widely treated as an attack surface before this incident, and CERT.PL is now urging energy operators in Poland and elsewhere to audit these connections and restrict SSH access on industrial controllers. Worth watching: whether regulators follow with mandatory configuration standards, or whether this stays a voluntary advisory.

If you receive heat or electricity from a district network, there's nothing specific to do right now. The practical action sits with the utilities and their regulators.

© 2026 Threat Vectr