Russian APT Breached Polish Heat Plant via Cellular Network & Default Credentials
Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last winter's deep freeze. Speaking at the DEF CON cybersecurity conference in Las Vegas on Saturday, CERT Polska head Marcin Dudek revealed that the intrusion struck during routine Christmas-period maintenance and went unrecognized for months, with operators initially blaming a contractor error for the shutdown of the plant's steam turbine and water treatment system. Customer heating was never interrupted, but given the timing with simultaneous attacks on more than 30 renewable energy installations and a larger heat plant, CERT Polska launched a full investigation into what had originally been filed as a low-priority informational report. The three-month analysis uncovered the first known use of a private cellular data network as a pathway into an industrial control system (ICS).
The attack chain is notably novel. Wind farms and other distributed energy sites communicate with grid operators through dedicated private cellular networks that the industry treats as secure, walled-off infrastructure. According to CERT Polska's supplementary report, the attackers moved from firewalls already compromised at wind farm substations, reached a cellular router on one of these private networks, and used that router to hop across to a controller at the heat plant that was still running factory-default login credentials. From there the hackers tunneled into the plant's industrial control systems, eventually spending 11 days inside the network before the investigation traced them back. The entire chain spanned facilities with no direct operational relationship to one another besides their shared presence on the same private network — a finding that highlights how default credentials can turn isolated assets into pivot points, a recurring weakness that any administrator can audit with a password strength checker.
The broader campaign was formally attributed in July to Russia's Federal Security Service (FSB), although CERT Polska did not attribute the newly disclosed CHP incident in its latest report. A senior Polish minister previously said the coordinated attacks on 30-plus renewable energy installations came "very close" to triggering a blackout for nearly 500,000 people during one of the coldest European winters in more than a decade. Researchers are urging operators of operational technology environments to scan exposed controllers and routers with tools like the open port scanner to identify reachable management interfaces and segmentation gaps that allow lateral movement between facilities. Dudek emphasized that the case demonstrates the importance of reporting not only confirmed incidents but also unexplained failures and operational disruptions — a standard that sharply contrasts with the more limited reporting requirements set out by the European Union's NIS2 directive.