CERT Polska, Poland's national computer emergency response team, has disclosed a sophisticated cyberattack from December 2025 that targeted a combined heat and power (CHP) plant. The report details a novel attack vector where threat actors, believed to be linked to Russia's FSB, leveraged a misconfigured private Access Point Name (APN) — a private cellular data network — to pivot from a compromised wind farm into the power plant's Operational Technology (OT) network. This is reportedly the first documented real-world attack of its kind. The attackers used default credentials to access a PLC and disrupt operations by shutting down a steam turbine.
The attack demonstrates a multi-stage, indirect approach to compromising a critical infrastructure target.
The plant operators initially mistook the disruption for a contractor error during maintenance, highlighting the challenge of identifying malicious activity in complex OT environments. The event was only later identified as a deliberate attack when CERT Polska connected it to a wider campaign against Poland's energy sector.
This attack highlights the convergence of IT, telecommunications, and OT networks and the new risks this creates.
Although operators were able to restore the systems before any customers lost heat or power, the incident is highly significant. It proves that private cellular networks, often considered more secure than the public internet, can become a viable attack vector if not properly configured and segmented. This attack serves as a blueprint for other threat actors targeting critical infrastructure. The potential for causing widespread power outages or physical damage is substantial. The incident forces asset owners and telecom providers to re-evaluate the security architecture of private APNs used for M2M and IoT communications in critical sectors.
No specific digital IOCs were provided in the source articles.
Defenders of OT environments using private cellular networks should look for:
Cyberattack on the Polish CHP plant occurs.
CERT Polska releases its report detailing the attack.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.