type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, ot, ics, scada, critical-infrastructure, poland, energy, private-cellular, sector-energy] ยท confidence: high ยท affected_sectors: [energy, utilities, critical-infrastructure] ยท au_impact: true
Poland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months
CERT Polska revealed at DEF CON that an attack on a Polish combined heat and power plant supplying ~50,000 residents went unrecognised as malicious during last winter, initially blamed on a contractor error. The investigation traced the first known use of a private cellular data network as an ICS pathway.
Summary
| Field | Detail |
|---|---|
| Disclosed by | CERT Polska (at DEF CON) |
| Target | Polish combined heat and power plant supplying ~50,000 residents |
| Initial attribution | Blamed on a contractor error during last winter |
| Pathway | First known use of a private cellular data network as an ICS pathway |
| Kill chain | Already-compromised wind farm firewalls โ cellular router โ private network โ heat plant controller (factory-default credentials) |
| Dwell time | 11 days |
| Impact | Disabled Siemens controllers on 29 December; wiped network equipment to destroy forensic evidence |
| Reconstruction | Only one legacy router's logs enabled reconstruction |
| Warning | "Trusted" private cellular network misconfiguration believed widespread internationally |
| Date | 2026-08-11 |
Key Details
- Attackers moved from already-compromised wind farm firewalls to a cellular router, then across the private cellular network to a heat plant controller still running factory-default credentials.
- The attackers dwelled 11 days and disabled Siemens controllers on 29 December before wiping network equipment to destroy forensic evidence.
- Only one legacy router's logs enabled reconstruction of the attack.
- CERT Polska warns the "trusted" private cellular network misconfiguration is believed widespread internationally.
Significance
The Polish private-cellular-network intrusion carries a direct lesson for Australian energy and OT operators, whose distributed renewable sites also rely on private cellular links โ ACSC guidance on OT security should be extended to treat these networks as hostile, not trusted, surfaces. It is the first documented private-cellular-network pivot into an industrial control system.
Source
- The Record โ 2026-08-11
Sources: raw/digests/Cyber-Digest-2026-08-11