Hackers disrupted operations at a Polish combined heat and power plant after finding an unexpected route into its network through a private cellular system used to connect remote energy equipment.
The December 2025 attack temporarily shut down a steam turbine and the plant’s water treatment system. The facility provides heat to approximately 50,000 residents, but customers did not lose heating or electricity during the incident.
CERT Polska revealed details of the attack on August 8 following an investigation lasting more than three months. According to investigators, the attackers did not initially enter through the power plant itself. Instead, the intrusion began at a separate wind farm.
After compromising systems there, the attackers discovered that equipment at the wind farm was connected to a private cellular network operated by the local electricity distribution company. The same network was also used to communicate with equipment elsewhere.
A security configuration allowed devices using this private network to communicate with each other. This gave the attackers an opportunity to move from the compromised wind farm toward equipment connected to the power plant.
CERT Polska said it was the first real-world cyberattack known to the agency where a private cellular network of this type was used as the route into an industrial control environment.
The attackers began exploring the network on December 18. During this activity, they discovered an industrial controller that could be reached through the cellular connection and was still protected by its default administrator credentials.
Investigators believe the compromised device then provided a route into the power plant’s operational network. Several days later, on December 25, the attackers connected to three industrial controllers inside the facility. CERT Polska believes this was reconnaissance conducted in preparation for the subsequent disruption.
The main attack occurred during the morning of December 29. Malicious activity was detected from approximately 5:30 a.m. until 10:10 a.m. Plant personnel started recovering affected systems at around 7:30 a.m., meaning the attackers were apparently still active while restoration efforts were already underway.
The intruders changed the operating state of several Siemens controllers and protected them with passwords. This caused the steam turbine and process-water treatment system to stop operating, interrupting the plant’s cogeneration process. Other networking equipment was deliberately reset and reconfigured so that operators could no longer reach it normally.
CERT Polska determined that at least some of these actions were probably automated because multiple changes occurred in a closely coordinated sequence. Investigators found no evidence that specialized malware was needed to cause the disruption. Instead, the attackers used functions already built into the affected industrial and networking equipment.
They also attempted to interfere with systems that had provided their route into the plant. Several devices were reset or damaged, resulting in the loss of potentially useful logs and other forensic evidence.
Initially, personnel did not realize they were dealing with a cyberattack. Maintenance was taking place at the facility at the time, so the disruption was first suspected to have resulted from contractor error.
Investigators have not publicly identified the attacker responsible for this particular incident.
