CERT Polska said its follow-up investigation into the destructive December 2025 cyberattacks on Poland’s energy sector uncovered a previously undisclosed parallel attack on a smaller combined heat and power (CHP) plant. Attackers reached the plant’s OT environment, shut down a steam turbine and the water treatment system used for process water, and briefly interrupted cogeneration operations. Operators restored service quickly enough to avoid disrupting heat supplies for about 50,000 residents.
Investigators spent more than three months reconstructing the intrusion path and concluded that the attackers accessed the OT network through a private APN, describing it as a previously unobserved real-world attack vector. CERT Polska said the compromise was enabled in part by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another, and warned that similar deployments are common in Poland and likely used in other countries. The agency issued recommendations for organizations that rely on private APN-based connectivity.

See the actors and campaigns active against you right now.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-08, CERT Polska disclosed that the December 2025 campaign included a second combined heat and power plant incident reached through a misconfigured private APN. The disclosure followed an investigation lasting more than three months and included defensive recommendations for organizations using private APNs.
A Truesec report published on 2026-02-09 said Polish CERT attributed the 29 December 2025 destructive attacks on Poland's energy infrastructure to Ghost Blizzard, also known as DragonFly and assessed as part of Russia's FSB Center 16. The report described the campaign as involving at least three attack events, including grid connection points and a combined heat-and-power plant.
On 29 December 2025, coordinated cyberattacks targeted Poland's energy infrastructure. CERT Polska said the campaign struck 30 wind and solar installations and a large combined heat and power plant, and described it as the first attack on Poland's energy sector with a purely destructive objective.
During the late December 2025 attacks on Polish energy companies, defenders identified DynoWiper malware. ESET Research and CERT Polska linked the activity and supporting malware to Russian state-aligned infrastructure and tradecraft, with ESET assessing the campaign as consistent with Sandworm operations.
During the same December 2025 campaign, attackers also hit a smaller CHP plant in Poland that supplied heat to 50,000 residents. The attack shut down a steam turbine and the water treatment system, briefly interrupting cogeneration, but operators restored service quickly enough to avoid disruption of heat supplies.
In December 2025, attackers compromised a FortiGate device at a wind farm, pivoted through a Teltonika router into a private APN lacking client isolation, and used default credentials on an exposed WAGO PLC to bridge into a smaller CHP plant's OT network. By December 25 they had accessed Siemens PLCs, and at about 05:30 on December 29 they put controllers into STOP mode, enabled password protection, shut down the steam turbine and water treatment system, and reset devices to hinder recovery.
Beginning on 18 December 2025, the attacker used access through a private APN to scan for services and expand access toward the smaller CHP plant. On 21 December, the attacker scanned the plant’s internal network for industrial automation and remote access services including S7, Modbus, CODESYS, RDP, VNC, HTTP, and HTTPS.
The NSA, CISA, FBI, DOE, and EPA issued a joint advisory, “Defending Against an Active Threat to Siemens S7 Series PLCs,” recommending organizations verify network segmentation and monitor traffic for anomalous or malicious activity.
ESET released additional technical details on DynoWiper used against a Polish energy company, describing three deployed samples, their wiping workflow, and related tooling such as attempted Rubeus use, LSASS dumping, and rsocx. The report also reiterated medium-confidence attribution of DynoWiper to Sandworm and noted ESET PROTECT blocked execution, limiting impact.
CERT Polska published a follow-up report disclosing that the December 2025 campaign was more complex than previously understood because it included a previously undisclosed parallel attack on a second CHP plant. The report also included recommendations for organizations using private APN-based solutions.
After more than three months of investigation, CERT Polska identified the device used by the attacker and reconstructed the intrusion path into the smaller CHP plant. Investigators concluded the attackers reached the OT network through a private APN, enabled in part by a misconfiguration allowing arbitrary devices within that APN to communicate with one another.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
23 references tracked. Mallory keeps watching after this page renders.
netresec.com
Open sourcexakep.ru
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcegov.pl
Open sourcewelivesecurity.com
Open sourcewelivesecurity.com
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.