Polish cybersecurity authorities have disclosed a previously unacknowledged cyberattack that impacted a combined heat and power plant last winter, coinciding with a period of severe cold. This incident occurred on the same day in December as a series of coordinated cyberattacks that targeted over 30 other renewable energy installations and a larger heat plant, which Poland publicly acknowledged in January. The earlier attacks were described by a senior minister as having nearly caused a blackout for approximately 500,000 people.
While the broader wave of attacks was formally attributed to Russia’s Federal Security Service in July, CERT Polska, the national computer emergency response team, did not attribute the newly revealed attack. This incident affected a smaller combined heat and power plant that supplies heat to about 50,000 residents. According to Marcin Dudek, head of CERT Polska, the attack went unrecognized as a cyberattack at the time.
Dudek, speaking at the DEF CON cybersecurity conference in Las Vegas, explained that the incident took place during routine maintenance over the Christmas period. Plant operators initially attributed the shutdown of the steam turbine and water treatment system to a contractor error, rather than malicious activity. The disruption was contained quickly, preventing any interruption to customer heating, and was initially reported only for informational purposes. However, due to its timing relative to the other attacks, CERT Polska initiated a comprehensive investigation into the low-priority report.
The investigation, which spanned over three months, uncovered what CERT Polska described as the first known instance of a private cellular data network being used as an ingress point into an industrial control system. The agency highlighted the importance of reporting not only confirmed incidents but also unexplained failures and operational disruptions, contrasting this with the more limited reporting requirements under the European Union’s NIS2 law.
In the newly revealed incident, attackers leveraged firewalls that had already been compromised at wind farm substations. From there, they accessed a cellular router connected to one of these private networks. They then used this router to pivot to a controller at the heat plant that was still configured with factory-default login credentials. This allowed the hackers to establish a tunnel into the plant’s industrial control systems. The attack chain involved movement across facilities—from a wind farm to the cellular network and then to the heat plant—that had no direct operational relationship beyond their shared presence on the same private network.
Once inside the heat plant, the attackers conducted reconnaissance for 11 days. They probed industrial equipment, tested credentials against the plant’s firewall, and connected to controllers on Christmas Day to map their targets. Before dawn on December 29, they disabled the Siemens controllers managing the steam turbine and water treatment system. They then locked operators out of these controllers by setting new passwords. The hackers subsequently used automated scripts to wipe the configurations of network equipment and set device addresses to unreachable values to impede recovery efforts.
Plant staff began restoring systems approximately two hours later, even while the attackers were still active, successfully limiting the disruption to a brief outage. The attackers then attempted to destroy forensic evidence along their entire path, corrupting the device used as a gateway into the plant beyond repair and resetting the firewalls and routers behind them. Investigators were only able to reconstruct the attack because one router was running older software that preserved its event logs through a factory reset.
CERT Polska issued a warning that the network misconfiguration enabling the attack—allowing any device on a private cellular network to communicate freely with any other—was prevalent across Poland at the time and is believed to be widespread internationally. The agency is urging energy operators to cease treating private cellular networks as inherently trusted infrastructure and instead apply the same security controls used for internet-facing connections. It called for immediate audits of network configurations, the removal of default passwords from connected devices, and the inclusion of these networks in security testing programs.






