Polish Power Plant Hack: How Hackers Shut Down a Turbine via Private Cellular Network (2026)

In today's digital age, where our lives are increasingly intertwined with technology, the recent cyberattack on a Polish power plant serves as a stark reminder of the vulnerabilities that exist within our critical infrastructure. This incident, which saw hackers breach the plant's controls via a private cellular network, highlights the evolving nature of cyber threats and the urgent need for enhanced security measures.

The Breach and Its Impact

The attack, which occurred in December 2025, resulted in the shutdown of a steam turbine and the process-water treatment system at a combined heat and power plant in Poland. Approximately 50,000 residents rely on this plant for their heating needs, yet despite the intrusion, recovery efforts began swiftly, and customers were fortunate to experience no disruption in heat or electricity supply.

What makes this incident particularly fascinating is the route the attackers took to gain access. By exploiting a configuration error within the private cellular network used by the local grid operator to communicate with remote equipment, the hackers were able to pivot from a compromised wind farm network to a controller at the power plant. This attack vector, according to CERT Polska, is believed to be the first of its kind observed in a real-world cyberattack.

Unraveling the Attack Path

The attack path began at a wind farm, where a FortiGate device, serving as both a firewall and VPN concentrator, was exposed to the internet and allowed accounts without multi-factor authentication. This vulnerability provided the attackers with administrative privileges, enabling them to obtain VPN credentials that granted access to all network segments.

From there, the distribution operator's requirement for communications to the substation's remote terminal unit to run over the serial DNP3.0 protocol was met, but there were no equivalent requirements for the cellular router's management interface. This oversight allowed the attackers to exploit the permissive private APN, which permitted client-to-client traffic, and gain access to a WAGO controller with default admin credentials.

Reconnaissance and Destruction

Once inside the network, the attackers spent time conducting reconnaissance, scanning the APN and finding a WAGO PFC200 controller exposing its web administration interface. They likely enabled the SSH service through this interface, allowing them to tunnel into the plant's operational technology (OT) network. On December 25, the attackers connected to Siemens PLCs over the S7 protocol, likely as part of their reconnaissance for the destructive actions that followed.

On December 29, the attackers initiated their destructive activities, switching Siemens controllers to STOP mode and password-protecting them, which shut down the turbine and process-water treatment system. They also factory-reset and reassigned unreachable IP addresses to seven Moxa serial device servers and three switches, ensuring that these devices were rendered useless. All of these steps were taken without the need for malware, and the attackers carefully avoided leaving any traces of their actions.

Covering Their Tracks

After completing their destructive mission, the attackers focused on damaging the way in, ensuring that their entry point was compromised and difficult to trace. They corrupted the WAGO controller's partition table, preventing it from booting and leaving no useful logs. Then, they factory-reset the Teltonika router, changed its administrator password, and assigned it an unreachable IP address. Finally, they factory-reset the FortiGate device, causing its logs to be lost.

Implications and Future Considerations

This incident serves as a wake-up call for the critical infrastructure sector. The use of private APNs, which are still recommended in federal guidance as an isolation option, has been shown to be vulnerable to attack. The attackers' ability to exploit default credentials, permissive network configurations, and lack of multi-factor authentication highlights the importance of basic cybersecurity hygiene.

As we move forward, it is crucial to recognize that cyber threats are constantly evolving, and our defenses must adapt accordingly. The incident in Poland should serve as a catalyst for a comprehensive review of security measures, especially within critical infrastructure sectors. By learning from this attack, we can work towards building a more resilient and secure digital future.

Polish Power Plant Hack: How Hackers Shut Down a Turbine via Private Cellular Network (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Duncan Muller

Last Updated:

Views: 5686

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.