# Cyberattack on Polish Power Plant Reveals Vulnerabilities in Private Cellular Networks

*Published August 12, 2026*
*Source: [https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html](https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html)*

## Executive Summary

Attackers breached a Polish power plant via a private cellular network, disrupting operations without affecting customer services. The incident highlights vulnerabilities in network configurations and underscores the importance of stringent security measures for private APNs.

## Article

In a concerning development, attackers managed to disrupt operations at a Polish combined heat and power plant by exploiting a private cellular network used by the local grid operator. The breach allowed the attackers to shut down a steam turbine and interfere with the process-water treatment system, though fortunately, the plant's 50,000 customers did not experience any loss of heat or electricity. The incident, which took place in December 2025, was disclosed on August 8 after an extensive investigation by CERT Polska.

The attackers accessed the plant's network through a private access point name, a dedicated cellular data network, allowing them to move from a compromised wind-farm network to a controller at the power plant. This method of intrusion is notable as it is the first known real-world cyberattack using this vector. The investigation did not identify a specific software vulnerability as the cause, and no Common Vulnerabilities and Exposures were found related to the Teltonika router involved.

The attackers exploited weak points in network configuration, including default admin credentials on the WAGO controller and a lack of client isolation in the private APN, which allowed client-to-client traffic. CERT's recommendations include auditing and reconfiguring private APNs to enable client isolation and treating such networks as untrusted from the operational technology side.

The attackers initially gained access through a wind farm's FortiGate device, which served as both a firewall and VPN concentrator. This device's VPN was exposed to the internet without multi-factor authentication, providing a pathway for the attack. The attackers used SSH tunneling through the router to penetrate the private APN, ultimately reaching the plant's operational technology network. Their activities included reconnaissance and the deliberate disruption of plant operations, which were executed using the plant's own protocols and systems.

Despite the sophisticated nature of the attack, it did not rely on malware, and all actions were carried out using standard device functions. The attackers ensured their tracks were covered by corrupting the WAGO controller's partition table and resetting network devices, leading to a loss of logs and complicating the investigation.
