Polish Power Plant Turbine Shut Down After Hackers Exploit Private Cellular Network

0
43

Key Takeaways

  • Attackers exploited a private cellular APN used by a Polish distribution system operator to pivot from a compromised wind‑farm network to a combined heat‑and‑power (CHP) plant, shutting down its turbine and process‑water treatment system.
  • The intrusion leveraged default credentials on a WAGO controller, permissive client‑to‑client traffic on the APN, and an exposed FortiGate VPN lacking multi‑factor authentication.
  • No known CVE was identified; the attack used legitimate device functions and protocols already in place (SSH, S7, DNP3.0).
  • CERT Polska recommends auditing APN configurations, enabling client isolation, treating the APN as untrusted from the OT side, segmenting traffic, removing unnecessary management services, and changing default credentials.
  • The incident highlights that private APNs, while often promoted as an isolation measure, can become a conduit for lateral movement if not properly hardened.

Incident Overview and Impact
In December 2025, cyber‑actors disrupted operations at a Polish combined heat‑and‑power plant that supplies heat to roughly 50 000 residents. By gaining access through the private cellular network managed by the local grid operator, the attackers were able to shut down the plant’s steam turbine and its process‑water treatment system. Recovery efforts began around 07:30 a.m. while the intruders remained active inside the network; fortunately, neither heat nor electricity service was lost to customers. CERT Polska disclosed the incident on 8 August 2025 after a three‑month investigation, noting that it was the second of two CHP plants targeted in a wider campaign mentioned by Poland’s prime minister in January.


Attack Vector: Private APN Exploitation
The attackers entered the OT environment via a private Access Point Name (APN)—a dedicated cellular data network operated by the distribution system operator. This APN allowed any device connected to it to communicate with any other device (client‑to‑client traffic), a configuration that CERT Polska identified as the first real‑world observation of this attack vector. The wind farm and the CHP plant are separate facilities, and neither runs the APN; the network merely linked them. Because the APN trusted all internal devices, once the attackers foothold was established on the wind‑farm side, they could pivot laterally to the CHP plant’s equipment.


Initial Compromise: Wind‑Farm FortiGate
The intrusion began at a wind farm where a FortiGate appliance served as both firewall and VPN concentrator. Its VPN was exposed to the public Internet and permitted accounts without multi‑factor authentication. Attackers obtained administrative privileges on the FortiGate, likely harvesting VPN credentials that granted them access to all network segments behind the device. From there, they used SSH tunneling through the farm’s cellular router to reach the private APN, setting the stage for further movement toward the CHP plant.


Cellular Router and WAGO Controller Weaknesses
The cellular link relied on a Teltonika RUTX50 router whose default password had been changed during deployment, yet investigators recovered repeated successful SSH logins without determining how the password was obtained. No publicly known vulnerability in the router’s firmware could give an unauthenticated attacker the password; the two CISA‑listed flaws (CVE‑2023‑32349, CVE‑2023‑32350) require existing privileges, and the router’s modem flaws only cause denial‑of‑service.

On the APN, a WAGO PFC200 controller was reachable and still used its factory‑default admin credentials. Because the APN permitted client‑to‑client traffic, the attacker could scan the network, discover the WAGO’s web interface, and likely enable SSH through that interface. The WAGO thus became a pivot point into the CHP plant’s OT network.


Reconnaissance and Destructive Actions
Starting on 18 December, the attacker scanned the APN and conducted reconnaissance inside the plant’s network, including a port scan that originated from the SCADA system’s address. By 25 December, they had established connections to three Siemens PLCs over the S7 protocol—activity CERT Polska assesses as reconnaissance for later destructive steps.

On 29 December, between 05:30 a.m. and 10:10 a.m., the attacker executed the disruptive actions: Siemens S7‑300, S7‑1200, and S7‑1500 controllers were switched to STOP mode and password‑protected, halting the turbine and the process‑water treatment system and interrupting cogeneration. Additionally, seven Moxa serial device servers and three switches were factory‑reset, assigned new passwords, and given unreachable IP addresses (e.g., 127.0.0.1). The timing and uniformity of these changes led CERT Polska to conclude they were automated. Notably, no malware was deployed; each step used legitimate device functions invoked over the protocols the plant already employed (SSH, S7, DNP3.0).


Cover‑Up and Evidence Preservation
After the destructive phase, the attacker attempted to erase traces. The WAGO controller’s partition table was corrupted, preventing it from booting and eliminating useful logs. Approximately thirty minutes later, the Teltonika router was factory‑reset, its administrator password changed, and it was assigned the unreachable address 127.0.0.1. The FortiGate was also factory‑reset, wiping its VPN logs. However, CERT Polska notes that RutOS versions earlier than 7.07 retain the event database after a factory reset, which is why the SSH login records survived and could be analyzed.

Initially, plant staff interpreted the outage as a contractor‑related issue during maintenance and logged it as such for information only. CERT Polska opened an incident because it already knew of similar events elsewhere in the campaign. No threat actor has been publicly attributed to this specific intrusion, although the broader December 2025 campaign received separate assessments from Poland’s government, CERT Polska, ESET, and Dragos, each focusing on different facets (preparation, infrastructure, wiper malware, overall scope).


Broader Implications and Recommendations
The incident underscores that private APNs, while often presented in guidance (including a July 2024 FBI/EPA advisory) as an isolated architecture for reaching OT over cellular links, can become a lateral‑movement conduit if not properly hardened. CERT Polska’s surveys found that many Polish organizations using private APNs allow any device on the network to reach any other, a configuration likely mirrored in other countries.

To mitigate similar risks, CERT Polska advises:

  1. Audit APN configurations and enable client isolation to prevent device‑to‑device communication.
  2. Treat the APN as untrusted from the OT perspective—segment and restrict traffic between the APN and OT networks.
  3. Remove unnecessary management services (e.g., SSH, HTTP/HTTPS) from interfaces reachable via the APN.
  4. Change default credentials on all devices accessible through the APN, enforce strong, unique passwords, and implement multi‑factor authentication where possible.
  5. Monitor and log VPN and remote‑access devices (such as FortiGate) for anomalous authentication attempts, and retain logs beyond factory‑reset capabilities.

By applying these measures, operators can reduce the likelihood that a compromised peripheral network (like a wind farm) will serve as a stepping stone to critical OT infrastructure.


Word count: approximately 945 words.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here