CERT Polska has published a follow-up to its report on the December 2025 attacks against Poland's energy sector, and it adds two things the original did not have: a second victim, and a full account of how the attackers reached an industrial control network. The route ran through a private mobile network, an APN run by the local distribution system operator. The agency says that is, to the best of its knowledge, the first time this vector has been seen in a real-world attack.
The newly disclosed victim is a small combined heat and power plant serving around 50,000 residents. It was attacked on 29 December 2025 from about 07:00, at the same time as more than 30 renewable energy sites and the larger plant covered in the January report. The attackers shut down its steam turbine and its process water treatment system. Staff response kept the outage short, and no customer lost heat or electricity.
The case took more than three months to analyse, which is why it was missing from the first report. Plant staff initially assumed a contractor had made a mistake and filed the event for information only. CERT Polska opened an incident anyway, because it already knew about the parallel attacks that day. The agency draws the lesson explicitly: report unexplained failures, not only confirmed incidents.
How the attackers got in
The entry point was a FortiGate device at a wind farm substation, exposed to the internet, acting as both firewall and VPN concentrator, with local accounts and no multi-factor authentication. From there the attackers reached a Teltonika RUTX50 cellular router inside the wind farm network. That router was dual homed: a serial link carrying the telecontrol protocol the operator mandates, and an Ethernet leg into a VLAN behind the compromised firewall. The operator had set requirements for the serial side and none for the router's administration interface.
The integrator had changed the router's default password, and CERT Polska says plainly that it could not determine how the attackers obtained the new one, or whether any vulnerability was involved. Investigators recovered the attackers' logins only because the router's operating system kept its event database through a factory reset on versions before 7.07.
From the router the attackers tunnelled into the private APN and, from 18 December, scanned it for remote access and industrial protocols. They found a WAGO PFC200 controller with a built-in cellular modem exposing its web administration interface, still on default credentials. They used that interface to switch on remote shell access, then tunnelled from the controller into the plant's operational network.
Reconnaissance, then destruction
One internal scan on Sunday 21 December began at the SCADA system's own address, which suggests the attackers already knew what they were looking for. On Christmas Day they connected successfully to three Siemens controllers.
The destruction ran from 05:30 to 10:10 on 29 December. Siemens S7-300, S7-1200 and S7-1500 controllers were put into STOP mode and password protected against changes, halting the turbine and the water treatment. Ten Moxa devices were factory reset, given new passwords and assigned unreachable addresses to slow recovery, and the timing of the requests shows this was automated. Recovery began around 07:30, while the attackers were still inside. Resetting and reloading the controllers shortened the outage but destroyed their logs, which Siemens confirmed were unrecoverable. On the way out the attackers corrupted the WAGO controller's partition table so it would not boot, reset the Teltonika router, and factory reset the FortiGate, erasing the logs at the entry point.
Why this matters beyond Poland
The enabling weakness was not a product flaw. It was an APN configured to let any device inside it connect to any other, combined with default credentials and administration interfaces left reachable. CERT Polska surveyed several Polish operators and found that configuration commonly deployed, and says similar setups are widespread internationally. Its advice is to enable client isolation, treat the private APN as untrusted and equivalent to the internet, keep administration interfaces off APN-facing ports, change default credentials, and bring private APNs into the scope of penetration tests.
The follow-up names no threat actor. The full account is in CERT Polska's report. It echoes a pattern we have covered before, from water utilities locked out of internet-facing controllers to fuel terminal equipment shipping with open debug access, and more Polish cyber activity is on our Poland profile.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.