In a newly detailed follow-up report, CERT Polska disclosed that hackers linked to the Russian threat group Electrum compromised a combined heat-and-power (CHP) plant in Poland by exploiting a misconfigured private Access Point Name (APN) on a cellular network. The incident, which occurred alongside a broader series of cyberattacks targeting Polish renewable energy installations, highlights a novel real-world attack vector: moving laterally across private cellular infrastructure to bridge air-gapped operational technology (OT) environments.
While the plant’s staff moved quickly to restore affected systems—preventing heating disruptions for the 50,000 residents served by the facility—the attack successfully forced a steam turbine and process-water treatment system offline. Security researchers believe this is the first documented case of a threat actor using a private cellular APN as a lateral movement pathway into an industrial SCADA network.
The Anatomy of the Private APN Breach
The intrusion began on December 18, when the attacker gained an initial foothold by compromising a FortiGate VPN/firewall device located at a wind farm. From there, the threat actor pivoted to an onboard Teltonika cellular router. This router was connected to a private APN managed by the regional distribution system operator (DSO) to connect dispersed energy resources across the grid.
Private APNs are widely used in critical infrastructure to provide remote cellular connectivity to distributed assets like wind turbines, solar fields, and substations. However, the DSO’s private APN lacked client isolation. Because arbitrary devices connected to the APN were allowed to communicate directly with one another, the private network essentially functioned as a flat, unsegmented local network spanning multiple geographically separated energy facilities.
Using the Teltonika router as a proxy, the attacker scanned the private APN subnet and identified a WAGO PFC200 programmable logic controller (PLC) operating at the targeted CHP plant. The WAGO controller’s web interface was directly exposed on the APN and configured with default administrator credentials. Once logged in, the threat actor enabled SSH on the controller, establishing a persistent bridge directly into the plant’s internal OT network.
Disruption of OT Infrastructure and Anti-Forensics
Over the week following the initial bridgehead, the threat actor conducted internal reconnaissance, mapping the target’s SCADA environment and identifying key industrial controllers. By December 25, the attacker had established connections to three Siemens PLCs controlling core facility operations.
Early on the morning of December 29 at approximately 5:30 a.m., the attacker executed the main phase of the operation:
- PLC Control Disruption: The threat actor accessed the SCADA interface and issued commands to the Siemens PLCs, switching them into “STOP” mode.
- Access Denial: To prevent operators from easily reversing the change, the attacker enabled password protection on the controllers.
- Process Interruption: The forced shutdown of the PLCs deactivated the plant’s steam turbine and process-water treatment system, halting cogeneration operations.
- Anti-Forensics and Cover-Up: The attacker reconfigured and reset several Moxa industrial serial-to-Ethernet gateways to obstruct local recovery efforts. Finally, the attacker destroyed system logs and reset or corrupted the WAGO controller, Teltonika router, and FortiGate firewall used throughout the intrusion to cover their tracks and impede post-incident forensic analysis.
This event occurred concurrently with a coordinated campaign on December 29 targeting 30 wind and solar power installations and another major CHP plant across Poland, where attackers wiped Windows systems, corrupted OT devices, and destroyed equipment beyond repair.
The Danger of Implicit Trust in Private Cellular Networks
Electrum—a threat group associated with Russia’s Sandworm actor and known for historical OT-destructive attacks such as CrashOverride/Industroyer—capitalized on a dangerous architectural assumption: that traffic inside a private APN is inherently trusted and secure.
Many utilities and industrial operators deploy private cellular APNs under the assumption that they act as isolated point-to-point tunnels. In reality, unless client-to-client isolation is explicitly enabled by the telecommunications provider or enforced via strict firewall policy, every remote terminal unit (RTU), cellular gateway, and controller on that APN shares a broadcast domain. A single compromised edge device—such as a remote solar inverter or wind turbine router—becomes a springboard to every other asset connected to the operator’s APN.
When combined with standard OT security oversights like exposed web management interfaces and default credentials, an unisolated APN transforms distributed remote assets into a broad, target-rich lateral movement domain.
Hardening Cellular OT Topologies
Investigations by CERT Polska indicate that flat private APN architectures are common throughout Poland and highly prevalent internationally across energy, water, and industrial sectors. To mitigate this attack path, critical infrastructure operators and telecom partners should implement the following architectural controls:
- Enforce Client Isolation on APNs: Require telecommunication providers to enable client-to-client isolation on all private APNs, ensuring individual cellular gateways cannot route traffic to or discover other endpoints on the same APN.
- Treat Private APNs as Untrusted Networks: Terminate cellular APN connections at a central security gateway or firewall. Apply strict microsegmentation and allowlist-only traffic rules between APN gateways and OT networks.
- Eliminate Default Credentials and Unused Services: Audit all deployed PLCs, RTUs, and industrial cellular gateways to ensure default passwords are changed. Disable unencrypted management protocols, exposed administrative web consoles, and remote management services like SSH or Telnet unless explicitly required and protected by strong authentication.
- Implement Centralized OT Monitoring: Log and analyze traffic passing between cellular gateways and control systems to detect unauthorized scanning, unexpected protocol usage, or unauthorized state-change commands issued to PLCs.
Related content
Polish CHP Plant Turbine Shut Down via Private Cellular Network Breach
Security NewsSandworm Hackers Pivot via Private APN to Sabotage Second Polish Energy Facility
Security NewsCISA Urges Water Sector to Secure Exposed PLCs Following Minnesota Cyberattacks
Security News18% of Data Center Physical Infrastructure Assets Sit One Hop From Public Internet
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call