Polish Heat Plant Breached via Private Cellular OT Network
Attackers breached a Polish heat plant via private cellular APN, shutting down a steam turbine. The OT intrusion went undisclosed for months.
Polish authorities have disclosed a cyberattack on a combined heat-and-power plant supplying heat to roughly 50,000 residents. Attackers shut down a steam turbine and the facility’s process-water treatment system. Recovery was underway at around 7:30 a.m. while the intruders were still active inside the network. Source: The Hacker News, BleepingComputer.
The entry point was the plant’s private APN (Access Point Name) — a dedicated cellular connection the local grid operator used to reach remote OT equipment.
This is a disclosure of an attack that occurred last year. The breach went undisclosed for months.
What Happened
The attack was coordinated. According to The Record, the incident occurred the same day as cyberattacks on more than 30 other renewable energy installations and a larger heat plant — an attack wave Poland’s government partially disclosed in January 2026. This second plant’s breach was hidden until now.
Physical impact: steam turbine offline, process-water treatment disrupted. Customers lost neither heat nor hot water during the incident, but recovery operations were active while the attackers were still inside the network.
No CVE has been identified for this incident. Attack attribution has not been publicly named in disclosed reporting.
The Private APN Attack Surface
Private APNs are cellular connections scoped to a specific organization — separate from public internet traffic but not inherently isolated from whatever OT systems they’re configured to reach. They’re common in distributed energy environments: remote substations, pumping stations, distributed plant equipment that field operators need to monitor and control without physically traveling to each site.
The assumption that “it’s private cellular, so it’s isolated” is operationally wrong and, apparently, still common enough that attackers are finding it worth testing. If you can reach the APN’s network — through a compromised SIM, a misconfigured cellular gateway, or the carrier path itself — you can reach the OT equipment on the other end.
What to Check
If private cellular connectivity touches your OT environment:
- Inventory every private APN and cellular gateway. Know which devices connect through cellular, what OT segments they can reach, and whether any routing paths skip expected segmentation controls.
- Verify authentication on cellular gateway equipment. Default or shared credentials on cellular routers and RTUs are a standard problem in distributed OT. Confirm each gateway requires unique, non-default credentials and that management interfaces are not openly accessible.
- Pull traffic logs from cellular links. Look for unexpected connection volumes, non-standard source addresses, or sessions outside normal maintenance windows. Cellular-connected OT is frequently the last place anyone looks for logs — if you don’t have them, that’s the finding.
- Validate your OT network segmentation. A cellular gateway should not have unrestricted access to control system segments. If yours does, that segmentation gap is a higher priority than almost anything else on your patch list right now.
The same targeting pattern — internet-exposed and poorly-segmented OT in energy and water infrastructure — is showing up across geographies. Iran-linked actors are currently running active campaigns against water utility PLCs across more than a dozen U.S. states, also exploiting weak authentication and exposed network interfaces.
Track operational technology security coverage on our ICS/OT topic page.
Found this useful? Share it.


