In a sobering revelation that underscores the escalating volatility of global critical infrastructure, Poland’s Computer Emergency Response Team (CERT.PL) has published a comprehensive analysis detailing a sophisticated and "purely destructive" cyber-offensive against the nation’s power sector. The report sheds light on a secondary, previously undisclosed attack that occurred in late December 2025, operating in tandem with a broader campaign attributed to the Russian-linked threat actor known as Sandworm.
While the energy sector has long been a target for espionage, this incident marks a chilling shift toward kinetic disruption. The attackers did not merely seek to exfiltrate data; they aimed to dismantle the physical operational integrity of combined heat and power (CHP) plants and renewable energy dispatch centers. The investigation reveals a frightening reality: the hackers successfully infiltrated the Industrial Control Systems (ICS) that serve as the heartbeat of Poland’s energy grid.
The Anatomy of the Incursion: A Two-Pronged Offensive
The December 2025 campaign was characterized by its surgical precision and the breadth of its targeting. CERT.PL confirms that approximately 30 sites, including wind and solar energy hubs, were in the crosshairs. While the initial wave of the attack focused on grid stability monitoring systems, the second, more targeted incursion—the subject of the new report—focused on a critical CHP plant providing essential heating to 50,000 residents.
The attackers employed a multi-stage approach, leveraging legitimate but poorly secured edge devices to pivot into the heart of the Operational Technology (OT) network. What makes this incident particularly alarming to global security experts is the novel use of a private Access Point Name (APN) as a primary attack vector. This technique allowed the threat actors to traverse the secure, private networks typically reserved for communication between Distribution System Operators (DSO) and their remote substations.
Chronology of the Breach: From Edge Device to OT Heartbeat
The sophistication of the attack was matched only by the attackers’ patience. The breach did not happen in a vacuum; it began at the periphery of the network.
The Initial Foothold
The intrusion was initiated via a Fortinet VPN and firewall device located at a remote wind farm. Because the device was internet-facing, it served as the "front door" for the threat actors. Once inside, the hackers performed rapid reconnaissance, identifying a Teltonika cellular router residing on the same network. By compromising the administrator interface of this router, the attackers gained a foothold in the local network segment.
The Tunneling Phase
Using an active Secure Shell (SSH) service on the Teltonika device, the hackers established a tunnel that bypassed traditional network segmentation. This tunnel provided a direct line into a private APN network managed by the DSO. This network is the critical bridge that allows the DSO’s SCADA systems to communicate with the PLC infrastructure installed at substations. By exploiting this private conduit, the attackers effectively masqueraded as legitimate traffic.
The Lateral Movement and Sabotage
Once within the private APN network, the hackers scanned for vulnerabilities, eventually identifying a Wago programmable logic controller (PLC) at the targeted CHP plant. Through the controller’s SSH service, the attackers gained unfettered access to the plant’s internal OT network.
For one week, the attackers remained silent, conducting reconnaissance to understand the plant’s operational logic. The sabotage phase was swift:
- The Shutdown: The attackers established connections to Siemens PLCs and commanded them into "stop" mode.
- The Lockout: To ensure maximum disruption, they applied custom passwords to the controllers, effectively preventing plant operators from intervening or restoring the logic.
- The Kinetic Impact: The manipulation of these controllers caused the immediate shutdown of a steam turbine and a water treatment system, disrupting the cogeneration process.
The Final Attempt to Erase Evidence
As the attackers retreated, they engaged in a "scorched earth" policy. They attempted to brick various ICS devices—including Moxa serial device servers and network switches—by corrupting firmware and configuration files. In one instance, they corrupted the partition table of the primary Wago gateway controller. This rendered the device physically unbootable, even after a factory reset, effectively destroying the "black box" evidence that might have provided clues about the attack’s origin and methods.

Supporting Data and Technical Implications
The report by CERT.PL provides a chilling assessment of current industrial security standards. The use of private APNs as an attack vector is a significant development. Many operators rely on the perceived "privacy" of these networks, often assuming that because they are not traversing the public internet, they are inherently secure. This assumption is now proven to be a dangerous fallacy.
The targeting was broad, encompassing various vendors, including ABB, Schneider Electric, and Siemens. While the attackers were not successful in every interaction—some attempts to connect to variable frequency drives were stymied—the sheer variety of protocols and hardware targeted suggests an adversary with deep knowledge of industrial automation environments.
The recovery process, while successful, was labor-intensive. Plant staff were forced to manually reset PLCs to factory settings and reload control logic from cold backups. The fact that the plant was undergoing maintenance at the time of the attack masked the initial signs of the intrusion, with staff initially attributing the system anomalies to human error—a testament to the attackers’ ability to blend their activities with standard operational workflows.
Official Responses and Strategic Implications
The Polish government and CERT.PL have categorized this as a clear signal of intent by state-backed actors to normalize the use of cyber-sabotage against civilian infrastructure. The report serves as a stark warning to other nations: the "vulnerable configuration" used by the attackers is not unique to Poland. It is a common architecture in industrial deployments worldwide.
"The objective was purely destructive," the CERT.PL report states. The goal was not espionage, nor was it the extortion typical of ransomware gangs. It was a direct challenge to the energy security of a NATO member.
In response, international cybersecurity agencies are urging a total overhaul of how "private" network segments are managed. Recommendations include:
- Zero Trust Architecture: Moving away from the reliance on private APNs as a security boundary and implementing granular, identity-based access controls for every device within the OT network.
- Enhanced Logging: Ensuring that logs are mirrored to off-site, immutable storage. The fact that the attackers were able to destroy evidence by corrupting local controller partitions highlights the fragility of relying on local device logs.
- Hardware Hardening: Disabling unused services like SSH on industrial controllers and ensuring that management interfaces are physically or logically air-gapped from the broader corporate network.
A New Era of Industrial Conflict
The December 2025 attacks on the Polish power grid represent a dangerous evolution in state-sponsored cyber warfare. We are witnessing the transition from "cyber-espionage" to "cyber-kinetic warfare," where the digital domain is used as a lever to cause tangible, physical damage in the real world.
The resilience of the Polish power grid, which saw no major electrical outages despite the sophisticated nature of the attack, is a testament to the dedication of the engineers and the efficacy of their backup protocols. However, the reliance on the hope that "systems were quickly restored" is a precarious strategy for long-term national security.
As the geopolitical landscape remains fraught with tension, the targeting of CHP plants and renewable energy centers suggests that the adversaries are not just looking for weaknesses in the grid—they are mapping the physical dependencies of the society that relies on it. For critical infrastructure operators across the globe, the lessons from the Polish incident are clear: the perimeter is gone, the "private" network is a target, and the only remaining defense is a radical commitment to architectural security and forensic readiness.
The silent siege of 2025 is not just a chapter in a security report; it is the opening salvo of a new, high-stakes era of industrial competition, where the stability of a nation’s lights and heat depends entirely on the integrity of its code.
