Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Polish Power Utility
Incident: Attackers accessed a combined heat and power plant via a private cellular network and shut down a steam turbine.
Impact: Temporary disruption of plant process-water treatment and turbine operations.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged a lack of multi-factor authentication on a wind farm’s VPN to gain an initial foothold. They then exploited a misconfigured private Access Point Name (APN) that permitted client-to-client communication, allowing a pivot into a separate power plant’s network. The breach culminated in the takeover of a WAGO controller using default administrative credentials.
Recommendations: Enable client isolation on all private APNs to prevent lateral movement between remote sites.; Enforce multi-factor authentication (MFA) on all internet-facing VPN concentrators and firewalls.; Audit OT controllers to ensure all default administrative credentials have been changed.
Source: The Hacker News / CERT Polska
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source