Sandworm hackers hit second Polish power plant via private APN network

Sandworm hackers hit second Polish power plant via private APN network

Poland's computer emergency response team CERT.PL has revealed details of a second cyberattack on the country's energy sector in December 2025. Unlike the previously disclosed incident, the target was a small combined heat and power plant supplying heat to 50,000 residents. The investigation found that the operation ran in parallel with the earlier hack and was "purely destructive" in nature.

The cyberattack, attributed to the Russia-linked Sandworm group, caused a steam turbine and a water treatment system to shut down, disrupting the cogeneration process. However, power and heat supply were not interrupted, as the systems were quickly restored. Initially, the disruption was blamed on an engineering error during maintenance work, but CERT specialists soon determined that hackers were behind it.

The intrusion began with a Fortinet VPN and firewall device at a wind farm connected to the internet. The attackers found a Teltonika cellular router on the same network and accessed its admin interface. Using an SSH service, they established a tunnel to a private APN network managed by the distribution system operator. Such networks enable communication between the operator's SCADA system and industrial controllers at substations.

Scanning the private APN network, the hackers identified a Wago programmable logic controller running at the CHP plant. According to CERT.PL, this is the first documented case of a private APN being used as an attack vector. The report warns that similar vulnerable configurations are common not only in Poland but also worldwide, making this technique a potential threat to many energy facilities.

In the previously disclosed attack, Sandworm targeted communication and control systems at roughly 30 sites, including CHP plants and dispatch centers for wind and solar energy. The hackers breached industrial networks but focused on grid stability monitoring rather than active generation. Despite permanent damage to some devices, no power outages occurred — just as in the second attack.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate