logo

Hackers Cross From IT to OT Through a Private APN in Poland

ID: 0474294f-d634-5dfe-b67e-c70e19479ced

STIX ID: report--0474294f-d634-5dfe-b67e-c70e19479ced

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: Pierluigi Paganini

...
...

Attackers exploited an internet-exposed Fortinet VPN/firewall and a Teltonika RUTX50 cellular router to traverse a private APN and reach OT networks at a Polish CHP plant, where they accessed WAGO and Siemens PLCs, placed controllers in stop mode, set locking passwords, corrupted a WAGO controller partition, and disrupted turbine and water-treatment systems; ESET identified DynoWiper and linked the activity with medium confidence to the Sandworm APT. The incident highlights the risk of private APNs and edge devices as attack paths into industrial control systems and the need to protect router administration, segregation, and OT gateway discipline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.