logo

Poland uncovers second heat plant cyberattack that went hidden for months

ID: 34cf9e7d-a920-5877-9199-3345f9b99576

STIX ID: report--34cf9e7d-a920-5877-9199-3345f9b99576

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

...
...

Poland’s CERT disclosed that a previously undetected cyberattack targeted a combined heat and power plant during a severe winter cold snap, using a compromised wind-farm firewall and a private cellular data network to reach controllers (which had factory-default credentials). Attackers spent 11 days mapping systems, then disabled Siemens controllers and wiped network equipment configurations, narrowly avoiding widespread heating outages; CERT Polska warns that allowing unrestricted communication across private cellular networks and leaving default passwords enabled is a widespread, high-risk misconfiguration that must be audited and remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.