Polish Power Plant Hack Turns Private Cell Networks Into a New Critical Infrastructure Weak Point
Hackers shut down a turbine at a Polish combined heat and power plant by tunneling through a private cellular network from a compromised wind farm, then stopping Siemens industrial controllers. It’s the first documented real-world use of this APN route, raising fresh alarms for grid operators that thought their operational networks were safely isolated.
A cyberattack that forced a turbine shutdown at a Polish power plant has exposed an unexpected weak point in Europe’s critical infrastructure defenses: the private cellular networks many operators use to link remote assets they believe are insulated from the public internet. It is the first documented case in which attackers pivoted through a grid operator’s private APN—an ostensibly closed mobile data service—into an operational technology network to disrupt power generation.
According to Poland’s national computer emergency response team, the hackers began by compromising a wind farm connected to the same grid operator. From there, they leveraged the operator’s private cellular access point name (APN) to move laterally into the control systems of a combined heat and power (CHP) plant. Once inside the plant’s operational technology environment, the attackers placed Siemens programmable logic controllers into STOP mode, shutting down at least one turbine and halting power production from that unit.
For plant workers and local residents, the event was experienced as a sudden loss of generating capacity, with engineers forced to scramble to confirm the cause and restore operations. There is no public indication of a prolonged outage, but the fact that a digital intrusion could so directly translate into a physical stoppage shows how thin the line can be between cyber incidents and real-world disruption. Operators who once assumed that their industrial networks were effectively air‑gapped now face evidence that their own connectivity choices—private mobile links meant to increase efficiency—can serve as attack corridors.
Operationally, the use of a private APN as a bridge is a worrying development for utilities and grid managers across Europe and beyond. Private cellular networks have been marketed as secure, isolated channels ideal for connecting wind farms, substations and distributed sensors. This incident suggests that if an attacker gains a foothold in any asset connected to that private network, they may be able to reach far more critical systems than previously assumed. Security teams will have to rethink trust boundaries, segmentation and monitoring for infrastructure that historically sat outside mainstream IT threat models.
Strategically, the attack lands in a geopolitical environment where energy systems are already under strain from war‑related disruptions and the push to integrate large volumes of renewable power. European authorities have warned repeatedly that state and state‑linked actors view energy infrastructure as a prime target for espionage and sabotage. While officials have not publicly attributed this particular incident, the choice of a grid‑connected CHP plant and the sophistication of the lateral movement will sharpen concerns that adversaries are testing methods that could be scaled up in a crisis.
The Polish case also underscores a larger truth: cyber defense for critical infrastructure can no longer be built on assumptions about physical separation or obscurity. When a private mobile network becomes a highway into turbine controllers, the perimeter is no longer the plant fence but every device and site sharing that connectivity. For governments and regulators, the takeaway is that oversight of industrial cybersecurity must extend into telecom arrangements and vendor architectures that used to be treated as purely commercial matters.
Key indicators to watch in the coming weeks will include whether Poland or its allies offer any public attribution or link the incident to known threat groups, and whether regulators issue new guidance on the use of private APNs and segmentation between renewable assets and conventional plants. Grid operators across Europe will be assessing similar configurations in their own systems; how quickly they move from audit to concrete network redesign will help determine whether this attack remains a warning shot or a template.
Sources
- OSINT