Duke u ngarkuar…
  • August 11, 2026
  • Nga aOneITForce

Private Mobile Network Became a Hidden Bridge Into Poland's Energy Systems

Private Mobile Network Became a Hidden Bridge Into Poland's Energy Systems

<p><strong>News Date: 2026-08-10</strong></p><p>A cyberattack against a small Polish combined heat-and-power plant has exposed a dangerous assumption in operational technology security: a private network is not automatically a trusted network. According to details reported from Poland's national incident response investigation, attackers used a private Access Point Name, or APN, as a route between separate energy facilities.</p><h2>From a Wind Farm to a Heating Plant</h2><p>The intrusion occurred during the destructive attacks against Poland's energy sector on December 29, 2025, but the second affected plant and its unusual access path have only now been publicly detailed. The facility provides heat to approximately 50,000 residents.</p><p>Investigators determined that the attackers first compromised a FortiGate device at a wind farm. They then used a cellular router to enter a private APN operated for energy-sector communications. Because devices connected to the APN were not adequately isolated, the intruders could scan for systems belonging to other facilities.</p><p>They discovered a WAGO industrial controller at the heating plant with an exposed management interface and default administrator credentials. After taking control of the device, the attackers enabled SSH and used it as a bridge into the operational network. They subsequently accessed SCADA resources and Siemens programmable logic controllers, placed equipment into a stopped state and applied password protection.</p><p>The steam turbine and process-water treatment system were shut down, interrupting cogeneration. Staff restored operations quickly, and the incident reportedly caused no impact to the surrounding population. Attackers also damaged logs and reconfigured network devices, complicating the forensic investigation.</p><h2>What Infrastructure Operators Should Change</h2><ul><li>Treat private APNs and carrier networks as untrusted external connections.</li><li>Enable strict isolation between every device connected to a mobile gateway.</li><li>Replace default credentials and disable unnecessary remote administration services.</li><li>Allow only specifically approved traffic between APN gateways and OT assets.</li><li>Monitor industrial devices for configuration changes, new services and unexpected stop commands.</li></ul><p>I believe this incident deserves attention well beyond the energy sector. Utilities, transport operators and manufacturers increasingly use cellular connectivity for remote equipment, but these connections are often omitted from conventional network diagrams and security assessments. Private addressing may reduce internet exposure, yet it does not provide authentication, segmentation or trustworthy device identity. Every mobile pathway into an industrial environment should therefore be reviewed as carefully as an internet-facing VPN.</p>

Kthehu lart