INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers Shut Polish Power Plant Turbine via Private Cellular Network
| 2026-08-11 06:55 HIGH HIGH DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
In December 2025, attackers successfully breached the control systems of a Polish combined heat and power plant via its private cellular network, which is used to reach remote equipment. The attack was attributed to CERT Polska, ESET, Dragos, and Poland's government in January 2026 assessments. The targeted sector was industrial control networks, specifically affecting an organization involved in energy production. Four thousand fifty residents rely on the plant for heat supply. The attackers exploited a configuration that allowed arbitrary devices on the private APN to communicate with one another, pivoting from a compromised wind-farm network to the CHP controller. The attack worked by using exposed VPN credentials and default admin credentials on the WAGO controller reachable through the APN. As of August 11, 2026, recovery efforts were underway while the intruders remained active inside the network.
Technical Mitigations AI-generated
• Audit the private APN configuration and switch on client isolation.
• Treat the private APN as untrusted from the operational technology (OT) side, segmenting and restricting traffic.
• Remove unnecessary management services from APN-reachable interfaces and change default credentials for the WAGO controller reachable through the APN.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-32349CVE-2023-32349
CVE-2023-32350CVE-2023-32350
Target & Sectors
PL
energyenergy
manufacturingmanufacturing
telecommunicationstelecommunications
Incident Timeline
December 2025
Threat actors used SSH tunneling through a router to reach the private APN, which was likely configured without client isolation and allowed any device on the network to access other devices.
Click on any entity below to view its context and source!
infrastructure
7.07
CERT says
RutOS versions earlier than 7.07
retained their event database after a factory reset, which is why the SSH login records survived.
infrastructure
Fortigate
The
attack path
began at a wind farm, where a FortiGate device served as both firewall and VPN concentrator.
2026/08/11
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by exploiting vulnerabilities in Teltonika routers over their private cellular network.
Click on any entity below to view its context and source!
infrastructure
Fortigate
…after the last observed activity at the CHP plant, the attacker factory-reset the Teltonika router, changed its administrator password and assigned it the unreachable address 127.0.0.1, then factory-reset the FortiGate, causing its logs to be lost.
Tactical Metrics
Metrics
infrastructure
Fortigate
Affected Product
Click for context!
The
attack path
began at a wind farm, where a FortiGate device served as both firewall and VPN concentrator.
…after the last observed activity at the CHP plant, the attacker factory-reset the Teltonika router, changed its administrator password and assigned it the unreachable address 127.0.0.1, then factory-reset the FortiGate, causing its logs to be lost.
Metrics
infrastructure
7.07
Software Version
CERT says
RutOS versions earlier than 7.07
retained their event database after a factory reset, which is why the SSH login records survived.
Intelligence Sources
The Hacker News
2026-08-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:45
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
CHP
entity
11x
timeline
Temporal Reference
December 25
date
8x
attribution
Attributing Entity
CERT Polska
authority
2x
industry
Targeted Sector
Government
sector
2x
tactic
Cyber Operation Type
Reconnaissance
tactic
2x
vulnerability
Exploited CVE
CVE-2023-32349
cve
Contextual Telemetry
Context Block
10 METRICS
target region
Target Country
Poland
country
infrastructure
Affected Product
Fortigate
software
general metric
Teltonika Advisory
32,350
teltonika advisory
general metric
Minutes
30
minutes
infrastructure
Software Version
7.07
version
general metric
Versions
7
versions
source region
Origin Country
Poland
country
general metric
S7
300
s7
general metric
Controllers
1,500
controllers
general metric
Residents
50,000
residents
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.