What's Happening?
Hackers breached a Polish power plant's controls via a private cellular network, shutting down a steam turbine and process-water treatment system. The attack, disclosed by CERT Polska, involved pivoting from a compromised wind-farm network to the power plant's controller
through a private APN. The breach exploited default admin credentials and permissive network configurations, allowing the attacker to disrupt operations without malware. The incident highlights vulnerabilities in private APN configurations and the need for improved security measures. CERT recommends auditing APN configurations, enabling client isolation, and treating APNs as untrusted from the operational technology side.
Why It's Important?
The breach of the Polish power plant underscores the vulnerabilities associated with private cellular networks used in industrial control systems. The attack demonstrates how permissive network configurations and default credentials can be exploited to disrupt critical infrastructure. As private APNs are commonly used in various countries, the incident serves as a warning to operators to review and strengthen their network security measures. The attack's reliance on supported device functions rather than malware highlights the need for comprehensive security practices that go beyond traditional defenses. The incident may prompt regulatory bodies to issue updated guidelines for securing industrial networks.











