What CERT Polska disclosed on August 8
CERT Polska, Poland's national computer emergency response team, publicly disclosed on August 8, 2026 that attackers had sabotaged a combined-heat-and-power (CHP) plant serving roughly 50,000 residents. The intrusion began with a reconnaissance phase CERT Polska traces to December 18-25, 2025, followed by a destructive phase that ran from 5:30 a.m. to 10:10 a.m. on December 29, 2025.
During those hours the attackers forced a shutdown of the plant's steam turbine and its process-water treatment system, switched Siemens S7-300, S7-1200 and S7-1500 controllers into STOP mode, and factory-reset seven Moxa serial device servers plus three network switches. Plant operators began recovery around 7:30 a.m., while the attackers were still active inside the network, and restored operations without any customer losing heat or power.
The pivot: a wind farm's APN into an unrelated plant
The entry point was not the heat plant itself. According to the reporting, a FortiGate device functioning as both firewall and VPN concentrator sat on a private cellular access point name, or APN, used to monitor a wind farm's substation. A configuration flaw let any device reachable on that APN communicate with any other device on it, including a Teltonika RUTX50 cellular router and a WAGO PFC200 controller further along the chain, giving the attackers a route out of the wind farm's monitoring segment and into a controller at the CHP plant.
CERT Polska describes this as the first documented case of a private APN being used as a pivot path between two operational-technology networks with no obvious relationship to each other. Researchers have linked the intrusion to the Russia-affiliated group Sandworm, citing overlap with the group's earlier wiper activity, with the attribution offered at medium confidence; the disclosure followed an investigation CERT Polska says ran for more than three months.
Why 'private' does not mean 'isolated'
Utilities and industrial operators across the EU generally treat private cellular APNs as a safer category of network than the public internet, and many skip the segmentation controls they would insist on for an internet-facing link on the assumption that a private APN is already isolated by design. That assumption is usually a decision made once, at the time a remote-monitoring contract for a wind farm or a substation is signed, and rarely revisited afterward.
This incident shows the assumption does not hold. A private APN built to monitor a wind farm became the route into a heat plant's turbine and water-treatment controls, two systems with no operational reason to share a network path. For any EU district-heating operator, energy utility or industrial company running SCADA or OT monitoring over a private cellular link, this is now a documented, board-relevant reason to test whether that link is segmented from OT.
What to check before the next audit cycle
Start with an inventory: list every private APN or cellular link that reaches an OT network, name the vendor equipment on it, such as Fortinet firewalls, Teltonika routers, WAGO controllers, Siemens PLCs or Moxa serial gateways, and confirm through a configuration review whether devices on that APN can reach devices belonging to a different site or a different operator. Where a single APN serves multiple remote assets, as it did here, that shared reachability is the vulnerability.
Then check the parts of the chain this attack actually used: default or factory credentials on serial device servers and switches, VPN concentrator rules broader than the monitoring traffic they were built for, and whether a PLC can be forced into STOP mode from any device reachable on the APN, as opposed to only an engineering workstation on the plant's own network. District heating and energy are essential entities under NIS2, so this is now a live example a supervisory authority can point to, not a hypothetical one.
Read next: A Bricked Building Costs More Than a Ransom | An 18-Year-Old Cisco Bug Now Has a 3-Day Deadline



