Russian Hackers Used an Obscure Telecom Back Door to Shut Down a Polish Heating Plant

A second cyberattack on Poland's energy sector, running in parallel with a previously disclosed assault, exploited a rarely scrutinised type of private mobile network to reach deep inside a plant supplying heat to 50,000 people.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal overhead view of a fuel storage tank farm at dusk, large white cylindrical tanks with catwalks and piping, faint cool blue ind
Share

Key points

  • Poland's national computer security team, CERT.PL, confirmed a second attack on the country's energy sector in December 2025, separate from but simultaneous with a previously reported assault.
  • Hackers linked to the Russian government group known as Sandworm broke into a combined heat and power plant serving roughly 50,000 residents.
  • The attackers locked industrial controllers, causing a steam turbine and water treatment system to shut down, though engineers restored heat and electricity supply within hours.
  • CERT.PL says this is the first recorded case of attackers using a private APN (a private mobile data channel used by utilities to connect remote equipment) as a route into an industrial network.
  • No electrical or heating outages reached residents, but several pieces of industrial hardware were permanently destroyed.

Polish authorities thought it was an engineering mistake. It was not.

When systems at a combined heat and power plant, which is a facility that produces both electricity and hot water for homes from a single fuel source, suddenly failed during routine maintenance in December 2025, staff initially blamed human error. Poland's national computer emergency response team, CERT.PL, soon established the real cause: hackers connected to the Russian government had remotely switched off the plant's industrial controllers.

CERT.PL published its findings over the weekend. The attack ran in parallel with a larger, already-reported assault on roughly 30 Polish energy sites that has been attributed to Sandworm, a hacking group operated by Russian military intelligence. That first attack damaged monitoring equipment but caused no power cuts. This second attack went further.

How did the hackers get in?

They entered through a wind farm, not the plant itself. The route took several steps and roughly a week of quiet reconnaissance before anything broke.

The attackers first found a Fortinet VPN and firewall device, the kind of equipment organisations use to allow remote workers to connect securely, at a wind farm connected to the internet. From there they reached a Teltonika cellular router on the same network and accessed its administration panel. They then used SSH, a standard remote-access protocol that lets a computer be controlled over a network, to open a tunnel into a private APN.

A private APN, or Access Point Name, is a dedicated mobile data channel, similar to a private lane on a motorway, that Polish grid operators use to let their central control software talk to equipment at remote substations. CERT.PL says this type of channel has rarely been considered an attack route, and that the same poorly secured configuration is common across Poland and internationally.

Through that channel the attackers found a Wago programmable logic controller (PLC), a small computer that physically operates industrial machinery, running at the heat and power plant. An SSH service left enabled on that controller gave them full access to the plant's operational network.

What exactly did they do once inside?

They switched machines off and locked the doors behind them. After a week of silent reconnaissance, the attackers connected to Siemens PLCs, set them to stop mode, and applied password protection so plant engineers could not override the commands or reload the control software. That triggered the shutdown of the steam turbine and a water treatment system.

Engineers recovered by resetting the affected controllers to factory settings and reloading software from backups. Moxa network switches and serial device servers were also tampered with to block legitimate access. The attackers also targeted ABB and Schneider Electric variable frequency drives, though the full effect on those devices remains unclear.

Before leaving, the attackers destroyed evidence. They corrupted the storage partition of the Wago controller they had used as their entry point into the plant network, making the device unbootable and wiping the logs investigators needed.

Event Detail
Attack period December 2025
Entry point Fortinet VPN device at a wind farm
Pivot route Private APN mobile data channel
Target facility CHP plant serving 50,000 residents
Effect on residents No heat or electricity interruption
Permanently damaged devices Multiple ICS units, including one Wago PLC

Should residents be worried?

No outage reached homes this time. Heat and electricity supply was not interrupted, and CERT.PL says engineers restored systems quickly.

The broader concern is what the attack reveals about how utilities connect remote equipment. Private mobile data channels were not widely seen as an entry point before this incident. CERT.PL is now urging energy operators in Poland and elsewhere to audit these connections and restrict SSH access on industrial controllers.

If you receive heat or electricity from a district network, there is nothing specific to do right now. The practical action sits with the utilities and their regulators.

© 2026 Threat Vectr