Polish power plant compromised via private mobile APN exploit
Attackers successfully compromised the operational technology (OT) of a Polish combined heat and power (CHP) plant by exploiting a private Access Point Name (APN) within a mobile telecommunications network. This incident marks the first documented case of using a private APN as a primary attack vector to pivot into industrial control systems (ICS) and SCADA networks.
The breach resulted in the shutdown of a steam turbine and process water treatment systems at a facility that provides heat to approximately 50,000 residents. While the plant was being restored, investigators noted that the intruders remained active within the network. CERT Polska reported that the attack bypassed traditional internet-based defenses by leveraging the perceived isolation of carrier-provisioned private networks.
Security experts highlight that this exploit challenges the long-held assumption that private APNs provide air-gapped security. Instead, attackers can use compromised IoT or telemetry devices on the APN to abuse DNS or DHCP services, allowing them to move laterally into critical industrial environments. This follows a previous incident involving a second energy facility, suggesting a targeted campaign against Polish energy infrastructure.