What's Happening?
Poland's computer emergency response team (CERT) has reported a second cyberattack on the country's power grid, targeting industrial control systems (ICS) with a destructive intent. The attack, linked to the Russian government-backed APT group Sandworm,
occurred in December 2025 and focused on communication and control systems at various sites, including combined heat and power (CHP) plants. The hackers used a private APN as an attack vector, a method not previously documented. The attack led to the shutdown of a steam turbine and water treatment system, disrupting the cogeneration process. However, the systems were quickly restored, and there was no interruption in heat and electricity supply.
Why It's Important?
This cyberattack highlights the growing sophistication of state-sponsored cyber threats targeting critical infrastructure. The use of a private APN as an attack vector represents a new challenge for cybersecurity professionals, emphasizing the need for robust security measures in industrial control systems. The incident underscores the vulnerability of energy sectors worldwide to cyberattacks, which can have significant economic and societal impacts. The attack also raises concerns about the security of legacy systems and the need for continuous monitoring and updating of cybersecurity protocols to protect against evolving threats.
What's Next?
In response to this attack, there may be increased efforts to secure private APN networks and other vulnerable configurations in industrial control systems. Governments and organizations might invest in advanced cybersecurity technologies and training to prevent similar incidents. There could be international collaboration to address state-sponsored cyber threats and develop strategies to protect critical infrastructure. Additionally, the incident may prompt regulatory bodies to enforce stricter cybersecurity standards and guidelines for the energy sector.











