Report an incident
Report an incident

Follow-Up Report of the December 2025 Energy Sector Incident
08 August 2026 | CERT Polska | #report, #incident, #energy

cover Download report (PDF, 5.6MB)

This was a first cyberattack against Poland's energy sector in which the objective was purely destructive. It also proved to be considerably more complex than initially believed, involving an additional event that had not previously been disclosed publicly and that likewise took place in December 2025. The analysis of what occurred at the second CHP plant targeted during that campaign is presented in the report published today. The investigation, which lasted more than three months, led to the discovery of a previously unobserved attack vector involving a private APN. During DEF CON in Las Vegas, the world's largest cybersecurity conference currently taking place, Marcin Dudek, Head of CERT Polska, is presenting the details of the incident.

On 29 December 2025, coordinated attacks targeted Poland's energy infrastructure, including 30 wind and solar power installations and a large combined heat and power (CHP) plant. We described these attacks in detail in our initial report. However, another incident took place in parallel: an attack on a smaller CHP plant supplying heat to 50,000 residents.

As a result of the attack described in this report, a steam turbine and the water treatment system used to produce process water were shut down, interrupting the cogeneration process, in which electricity and heat are generated simultaneously. Thanks to the prompt response of the CHP plant's operators, the incident resulted only in a short-term outage and did not disrupt heat supplies to consumers. It did, however, leave one key question unanswered: how had the attackers managed to achieve this?

Based on the analysis of the collected evidence, we identified the device from which the attacker conducted their operations and reconstructed the attack path. To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack. The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another. Surveys conducted among organizations using similar solutions indicated that this configuration was commonly encountered in Poland. To the best of our knowledge, it is also widely used in other countries around the world. For this reason, the report concludes with CERT Polska's recommendations for organizations using private APN-based solutions. We encourage readers to read the follow-up report.

Share: