Desk live·
ForensicPost
Nation-state/Infrastructure/File 26-0808

Polish Heat Plant Attackers Reached the PLCs Through a Private APN

Attackers reached a Polish heat and power plant’s controllers over the private cellular network its grid operator uses for remote equipment — the isolation mechanism itself. They set the PLCs to STOP and password-protected them.

Constructed geometry · not a chart of case data
JurisdictionPolandWarsawthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPolish combined heat and power plant
ActorUnattributed
S. Rosler13 min readConfidence: high3 sources reviewed

On 8 August 2026 CERT Polska disclosed an intrusion at a small combined heat and power plant supplying around 50,000 residents, following an investigation of more than three months. At approximately 05:30 on 29 December 2025 the attacker reached the SCADA interface and Siemens programmable logic controllers, switched them into STOP mode, activated password protection and shut down the steam turbine and the process-water treatment system.

The route was a private Access Point Name — the private cellular network the local grid operator uses to reach remote equipment. CERT.PL attributes the pivot in part to a misconfiguration that allowed arbitrary devices inside that private network to communicate with one another, and describes this as the first instance it has seen of a private APN used as an attack vector. Customer heating was not interrupted. This is the second Polish energy facility incident disclosed in this sequence.

The Isolation Was The Route

A private APN exists to keep operational technology off the public internet. It is the recommended answer to exactly the exposure this corpus filed at 26-0729, where federal agencies warned water utilities about internet-facing controllers, and at 26-0727.

Here it was the way in. Not because the concept failed but because a private network is still a network: once the segmentation inside it permitted any device to talk to any other, the remote-access path the operator relied on became a flat route to the plant floor. We have recorded the same shape at 23-0818b, where a migration merged backup networks into the environment they protected — a control that works only while somebody keeps enforcing the property that makes it a control.

STOP, With A Password On It

The controllers were not wiped, corrupted or ransomed. They were halted and locked, which is a specific and deliberate outcome.

Destruction announces itself and invites replacement. A PLC sitting in STOP with password protection enabled looks like equipment that has stopped, and the operator’s first question is what broke rather than who did this. We have recorded manipulation rather than destruction at 26-0727 and at 22-0627, where a plant was driven into a damaging state; this is the quieter version of the same capability.

For Months, It Was Assumed To Be A Contractor’s Mistake

The plant’s operators initially attributed the shutdown to contractor error rather than to an intrusion. The investigation took more than three months to establish otherwise, and disclosure came more than seven months after the event.

This desk does not read that as negligence, and says so plainly: an unexplained turbine trip in an industrial plant has many ordinary causes and exactly one exotic one. It is the strongest evidence in this corpus for the argument at 26-0802 that the file set is built from incidents that announced themselves. This one very nearly did not, and the honest inference is that others do not.

Fifty Thousand People, Zero Recorded Harm

Heating was never interrupted, and the incident was reported for information rather than as a service failure. By every measure this database usually applies, nothing happened.

What happened was that somebody demonstrated they could stop the heat for a town in December. We have argued at 24-1231 that availability harm goes uncounted; this file is the case where the harm was averted and the capability is the finding. There is no field for that anywhere.

How we reported this

Compiled from CERT Polska’s published account and contemporaneous reporting of it, listed below. Reporting also refers to a Fortinet device in the chain; this desk has not established its role and does not assert one. No actor is named — none was publicly identified — and this desk attributes nothing to any state despite the section this file sits in. No indicators are reproduced. Graded high on the sequence as published by the national CERT. Corrections: corrections@forensicpost.com.

Sources
  1. Poland uncovers second heat plant cyberattack that went hidden for monthsThe Record
  2. Hackers breached a small Polish energy plant via private APN last yearBleepingComputer
  3. Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy FacilitySecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary