Hackers Cross From IT to OT Through a Private APN in Poland
ID: 0474294f-d634-5dfe-b67e-c70e19479ced
STIX ID: report--0474294f-d634-5dfe-b67e-c70e19479ced
Feed Name: Security Affairs
Attackers exploited an internet-exposed Fortinet VPN/firewall and a Teltonika RUTX50 cellular router to traverse a private APN and reach OT networks at a Polish CHP plant, where they accessed WAGO and Siemens PLCs, placed controllers in stop mode, set locking passwords, corrupted a WAGO controller partition, and disrupted turbine and water-treatment systems; ESET identified DynoWiper and linked the activity with medium confidence to the Sandworm APT. The incident highlights the risk of private APNs and edge devices as attack paths into industrial control systems and the need to protect router administration, segregation, and OT gateway discipline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
