Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-11 ยท updated: 2026-08-11 ยท tags: [incident, ot, ics, scada, critical-infrastructure, poland, energy, private-cellular, sector-energy] ยท confidence: high ยท affected_sectors: [energy, utilities, critical-infrastructure] ยท au_impact: true

Poland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months

CERT Polska revealed at DEF CON that an attack on a Polish combined heat and power plant supplying ~50,000 residents went unrecognised as malicious during last winter, initially blamed on a contractor error. The investigation traced the first known use of a private cellular data network as an ICS pathway.

Summary

Field Detail
Disclosed by CERT Polska (at DEF CON)
Target Polish combined heat and power plant supplying ~50,000 residents
Initial attribution Blamed on a contractor error during last winter
Pathway First known use of a private cellular data network as an ICS pathway
Kill chain Already-compromised wind farm firewalls โ†’ cellular router โ†’ private network โ†’ heat plant controller (factory-default credentials)
Dwell time 11 days
Impact Disabled Siemens controllers on 29 December; wiped network equipment to destroy forensic evidence
Reconstruction Only one legacy router's logs enabled reconstruction
Warning "Trusted" private cellular network misconfiguration believed widespread internationally
Date 2026-08-11

Key Details

  • Attackers moved from already-compromised wind farm firewalls to a cellular router, then across the private cellular network to a heat plant controller still running factory-default credentials.
  • The attackers dwelled 11 days and disabled Siemens controllers on 29 December before wiping network equipment to destroy forensic evidence.
  • Only one legacy router's logs enabled reconstruction of the attack.
  • CERT Polska warns the "trusted" private cellular network misconfiguration is believed widespread internationally.

Significance

The Polish private-cellular-network intrusion carries a direct lesson for Australian energy and OT operators, whose distributed renewable sites also rely on private cellular links โ€” ACSC guidance on OT security should be extended to treat these networks as hostile, not trusted, surfaces. It is the first documented private-cellular-network pivot into an industrial control system.

Source

Sources: raw/digests/Cyber-Digest-2026-08-11