Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Private Mobile Network Became a Hidden Bridge Into Poland's Energy Systems

Private Mobile Network Became a Hidden Bridge Into Poland's Energy Systems
Photo by Miguel Á. Padriñán on Pexels

A newly disclosed investigation found that attackers reached a Polish combined heat-and-power plant by moving laterally through a private mobile network. Weak client isolation and default industrial-controller credentials allowed the intruders to stop operational equipment, although plant personnel restored service before residents were affected.

News Date: 2026-08-10

A cyberattack against a small Polish combined heat-and-power plant has exposed a dangerous assumption in operational technology security: a private network is not automatically a trusted network. According to details reported from Poland's national incident response investigation, attackers used a private Access Point Name, or APN, as a route between separate energy facilities.

From a Wind Farm to a Heating Plant

The intrusion occurred during the destructive attacks against Poland's energy sector on December 29, 2025, but the second affected plant and its unusual access path have only now been publicly detailed. The facility provides heat to approximately 50,000 residents.

Investigators determined that the attackers first compromised a FortiGate device at a wind farm. They then used a cellular router to enter a private APN operated for energy-sector communications. Because devices connected to the APN were not adequately isolated, the intruders could scan for systems belonging to other facilities.

They discovered a WAGO industrial controller at the heating plant with an exposed management interface and default administrator credentials. After taking control of the device, the attackers enabled SSH and used it as a bridge into the operational network. They subsequently accessed SCADA resources and Siemens programmable logic controllers, placed equipment into a stopped state and applied password protection.

The steam turbine and process-water treatment system were shut down, interrupting cogeneration. Staff restored operations quickly, and the incident reportedly caused no impact to the surrounding population. Attackers also damaged logs and reconfigured network devices, complicating the forensic investigation.

What Infrastructure Operators Should Change

  • Treat private APNs and carrier networks as untrusted external connections.
  • Enable strict isolation between every device connected to a mobile gateway.
  • Replace default credentials and disable unnecessary remote administration services.
  • Allow only specifically approved traffic between APN gateways and OT assets.
  • Monitor industrial devices for configuration changes, new services and unexpected stop commands.

I believe this incident deserves attention well beyond the energy sector. Utilities, transport operators and manufacturers increasingly use cellular connectivity for remote equipment, but these connections are often omitted from conventional network diagrams and security assessments. Private addressing may reduce internet exposure, yet it does not provide authentication, segmentation or trustworthy device identity. Every mobile pathway into an industrial environment should therefore be reviewed as carefully as an internet-facing VPN.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path