Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”.

In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities.

In that attack, the hackers gained access to ICS, but mainly targeted grid safety and stability monitoring systems rather than active power generation systems. While some ICS devices were permanently damaged, the attack did not cause any electrical outages.

In a report published over the weekend, CERT.PL revealed that the country’s energy sector was targeted in a second attack in December 2025. An investigation revealed that this attack, conducted in parallel with the previously disclosed hack, was aimed at a smaller CHP plant supplying heat to 50,000 residents.

The Polish CERT’s report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world.

The cyberattack caused the shutdown of a steam turbine and a water treatment system, which resulted in a disruption of the cogeneration process. However, the systems were quickly restored, and heat and electricity supply were not interrupted.

The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption, but the CERT soon determined that it was the result of hacker activity.

From an edge device to an energy facility’s OT network

The intrusion started on a Fortinet VPN and firewall device located at a wind farm and connected to the internet. The hackers then identified a Teltonika cellular router on the same network and accessed its admin interface.

An SSH service running on the device was then used to establish a tunnel that enabled communication to a private APN network managed by the distribution system operator (DSO). These private APN networks enable communication between the DSO’s SCADA system and ICS installed at the substation.

The attacker scanned the private APN network and identified a Wago programmable logic controller (PLC) running at a CHP plant. An SSH service enabled on this controller gave the attacker access to the plant’s operational technology (OT) networks.

After conducting reconnaissance over the course of one week, the threat actor connected to Siemens PLCs, switched them to ‘stop’ mode, and set a password to prevent operators from changing the controllers’ operating state and control logic. These actions caused the shutdown of the steam turbine and water treatment systems.

Staff managed to limit the downtime by resetting the affected PLCs to their factory settings and reloading logic from backups.

Moxa serial device servers and Moxa network switches were also targeted by the attackers and configured to prevent the legitimate operators from accessing them. ABB and Schneider Electric variable frequency drives were also targeted by the attackers, but it’s unclear what actions they carried out on these devices, and some attempts to connect to them were unsuccessful.

Similar to the attack on the first energy facility, the hackers bricked some of the compromised ICS devices.

According to the Polish CERT, some devices were permanently damaged as part of the attackers’ attempts to cover their tracks.

“The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot. No valuable logs could be recovered from the device during the investigation.”

Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Related: Water Sector Cyberattacks Reportedly Hit at Least 12 States