Poland uncovers second heat plant cyberattack that went hidden for months
ID: 34cf9e7d-a920-5877-9199-3345f9b99576
STIX ID: report--34cf9e7d-a920-5877-9199-3345f9b99576
Feed Name: The Record from Recorded Future News
Poland’s CERT disclosed that a previously undetected cyberattack targeted a combined heat and power plant during a severe winter cold snap, using a compromised wind-farm firewall and a private cellular data network to reach controllers (which had factory-default credentials). Attackers spent 11 days mapping systems, then disabled Siemens controllers and wiped network equipment configurations, narrowly avoiding widespread heating outages; CERT Polska warns that allowing unrestricted communication across private cellular networks and leaving default passwords enabled is a widespread, high-risk misconfiguration that must be audited and remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
