Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL
ID: e9cba463-8298-5cf4-ba54-13d5199cca15
STIX ID: report--e9cba463-8298-5cf4-ba54-13d5199cca15
Feed Name: Infosecurity Magazine (News)
CERT.PL reports that a Sandworm-linked campaign in December 2025 compromised a FortiGate device and a Teltonika router to reach a private APN and access a WAGO PFC200 PLC using default credentials; attackers then SSHed into the OT network, stopped Siemens PLCs, and forced shutdowns of a CHP plant's steam turbine and water treatment system, also sabotaging network devices and logs — CERT.PL urges isolating and treating private APNs as untrusted, auditing configurations, changing default credentials, and monitoring APN-OT traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
