Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

August 11, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Polish Power Utility
Incident: Attackers accessed a combined heat and power plant via a private cellular network and shut down a steam turbine.
Impact: Temporary disruption of plant process-water treatment and turbine operations.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged a lack of multi-factor authentication on a wind farm’s VPN to gain an initial foothold. They then exploited a misconfigured private Access Point Name (APN) that permitted client-to-client communication, allowing a pivot into a separate power plant’s network. The breach culminated in the takeover of a WAGO controller using default administrative credentials.
Recommendations: Enable client isolation on all private APNs to prevent lateral movement between remote sites.; Enforce multi-factor authentication (MFA) on all internet-facing VPN concentrators and firewalls.; Audit OT controllers to ensure all default administrative credentials have been changed.
Source: The Hacker News / CERT Polska

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *