Cyberattack on Polish CHP Plant Exploits Private APN in First-of-Its-Kind OT Breach
On December 29, 2023, a cyberattack targeted a Polish combined heat and power (CHP) plant, marking the first documented case of attackers infiltrating an operational technology (OT) network via a private APN (Access Point Name). The incident, analyzed by CERT Polska over three months, was part of a broader campaign against Poland’s energy sector that same day, affecting 30 renewable energy facilities and another CHP plant.
The attacked CHP plant supplies heat to approximately 50,000 residents. The breach disrupted a steam turbine and water treatment system, halting cogeneration processes. Plant operators initially attributed the outage to human error during ongoing maintenance but later confirmed it was a cyberattack. Despite the disruption, heat and electricity supplies to customers remained uninterrupted due to swift recovery efforts.
Investigators traced the attack to a WAGO PFC200 PLC with an integrated cellular modem, which the attacker used as an entry point. The device, however, was damaged, preventing forensic data recovery. The attack vector originated from a compromised FortiGate firewall/VPN concentrator at a wind farm substation, which lacked multi-factor authentication (MFA). From there, the attacker moved laterally through a Teltonika RUTX50 cellular router connected to both the substation’s internal network and the DSO’s private APN before tunneling into the CHP plant’s network.
Between December 18 and 25, the attacker conducted reconnaissance, scanning for VNC, HTTP, and industrial protocols (S7, Modbus). They exploited default credentials on the WAGO PLC, enabling SSH access and establishing a foothold in the plant’s SCADA system. On December 29 at 5:30 a.m., the attacker disabled three Siemens PLCs (S7-300, S7-1200, S7-1500) by switching them to STOP mode and locking them with passwords, halting critical operations. They also reset seven Moxa serial device servers and three network switches, assigning them unreachable IP addresses (e.g., 127.0.0.1).
The attack lasted nearly five hours, ending with the attacker corrupting the WAGO PLC’s partition table to prevent recovery. They also wiped logs from the FortiGate and Teltonika devices, obscuring their tracks. CERT Polska reconstructed the incident through remaining evidence, noting the attack was likely automated.
The breach exploited a misconfiguration in the private APN, which failed to isolate connected devices a vulnerability CERT Polska found to be common in Poland and other countries. The incident underscores the risks of unsecured remote access in OT environments, particularly when cellular connectivity bridges IT and industrial networks.
Clarke Energy - USA cybersecurity rating report: https://www.rankiteo.com/company/clarke-energy-usa
Energix - Renewable Energies cybersecurity rating report: https://www.rankiteo.com/company/energix---renewable-energies-ltd
CHP WORLD NIGERIA PVT LTD cybersecurity rating report: https://www.rankiteo.com/company/chp-world-nigeria-pvt-ltd
"id": "CLAENECHP1786425986",
"linkid": "clarke-energy-usa, energix---renewable-energies-ltd, chp-world-nigeria-pvt-ltd",
"type": "Cyber Attack",
"date": "12/2025",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': '50,000 residents',
'industry': 'Energy',
'location': 'Poland',
'name': 'Polish CHP Plant',
'type': 'Energy (Combined Heat and Power)'},
{'industry': 'Energy',
'location': 'Poland',
'name': '30 Renewable Energy Facilities',
'type': 'Energy (Renewable)'},
{'industry': 'Energy',
'location': 'Poland',
'name': 'Another CHP Plant',
'type': 'Energy (Combined Heat and Power)'}],
'attack_vector': ['Private APN misconfiguration',
'Compromised FortiGate firewall/VPN concentrator',
'Exploited default credentials on WAGO PLC'],
'date_detected': '2023-12-29',
'description': 'On December 29, 2023, a cyberattack targeted a Polish '
'combined heat and power (CHP) plant, marking the first '
'documented case of attackers infiltrating an operational '
'technology (OT) network via a private APN (Access Point '
'Name). The incident disrupted a steam turbine and water '
'treatment system, halting cogeneration processes. The attack '
'was part of a broader campaign against Poland’s energy '
'sector, affecting 30 renewable energy facilities and another '
'CHP plant.',
'impact': {'downtime': 'Nearly 5 hours',
'operational_impact': 'Halted cogeneration processes',
'systems_affected': ['Steam turbine',
'Water treatment system',
'Siemens PLCs (S7-300, S7-1200, S7-1500)',
'Moxa serial device servers',
'Network switches']},
'initial_access_broker': {'backdoors_established': 'SSH access via WAGO PLC',
'entry_point': 'Compromised FortiGate firewall/VPN '
'concentrator at a wind farm '
'substation',
'high_value_targets': ['Siemens PLCs',
'Moxa serial device servers'],
'reconnaissance_period': 'December 18-25, 2023'},
'investigation_status': 'Completed (reconstructed through remaining evidence)',
'lessons_learned': 'The incident underscores the risks of unsecured remote '
'access in OT environments, particularly when cellular '
'connectivity bridges IT and industrial networks. '
'Misconfigurations in private APNs and lack of MFA can '
'lead to severe breaches.',
'post_incident_analysis': {'root_causes': ['Misconfigured private APN',
'Lack of MFA on FortiGate '
'firewall/VPN concentrator',
'Default credentials on WAGO '
'PFC200 PLC',
'Unsecured cellular connectivity '
'bridging IT and OT networks']},
'recommendations': ['Implement multi-factor authentication (MFA) for all '
'remote access points',
'Secure default credentials on OT devices',
'Isolate private APN-connected devices',
'Enhance monitoring for lateral movement and unusual '
'activity',
'Regularly audit and update OT network configurations'],
'references': [{'source': 'CERT Polska'}],
'response': {'recovery_measures': 'Swift recovery efforts ensured '
'uninterrupted heat and electricity '
'supplies',
'third_party_assistance': 'CERT Polska'},
'title': 'Cyberattack on Polish CHP Plant Exploits Private APN in '
'First-of-Its-Kind OT Breach',
'type': 'OT Breach',
'vulnerability_exploited': ['Lack of multi-factor authentication (MFA)',
'Default credentials on WAGO PFC200 PLC',
'Misconfigured private APN']}