Urgent.News

What's breaking now, across thousands of outlets.

Tech

Hackers breach Polish plant through private mobile network

Hackers penetrated a Polish combined heat and power plant through a private cellular network, manipulating industrial controllers and temporarily halting cogeneration at a facility supplying heat to about 50,000 residents. The attack has exposed a previously undocumented route into critical operational technology systems. The intrusion occurred on December 29, 2025, during a broader campaign…

Hackers breached a Polish combined heat and power plant through a private cellular network, according to a report on December 29, 2025. The attack manipulated industrial controllers, temporarily halting cogeneration and affecting heat supply to approximately 50,000 residents. Investigators discovered that the intrusion resulted from a previously unknown route into critical operational technology systems.

The breach occurred after attackers compromised a FortiGate device at a wind farm, then accessed a Teltonika RUTX50 cellular router connected to the distribution operator’s private APN network. They created an SSH tunnel into this network and discovered an unsecured WAGO PFC200 controller's web administration interface. The controller, still using default credentials, allowed attackers to enable SSH access and tunnel into the plant's internal industrial network, connecting to SCADA systems and equipment responsible for critical processes.

The intrusion lasted about a week, during which attackers accessed three Siemens programmable logic controllers, putting the plant into STOP mode and hindering operators from reversing the changes. Other industrial devices were also targeted, including Moxa serial device servers and network switches. Despite the attackers' efforts to erase evidence and damage gateway devices, operators restored operations before consumers lost heating services, limiting the incident to a short operational outage.

The breach highlights the dangers of treating private APNs as trusted communication environments. The attack is part of a coordinated campaign against Poland’s energy infrastructure, involving more than 30 wind and photovoltaic installations and other facilities, linked to a sophisticated threat cluster known as Static Tundra, Berserk Bear, or Ghost Blizzard, potentially associated with the Sandworm ecosystem.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

U.S. Congress Presses TSMC Loophole Crackdown

The United States Congress has urged the Trump administration to strengthen customer verification for foundry companies, including TSMC, to prevent the indirect supply of advanced semiconductors to…

  • U.S. Congress demands tighter TSMC verification procedures to curb semiconductor supply to China.
  • Heightened scrutiny of TSMC's verification methods due to concerns over Chinese orders.

More from Tuesday 11 August →