Russia-linked hackers breached a Polish heat-and-power plant by exploiting a misconfigured private Access Point Name (APN) to sabotage the facility [1, 2].
The breach highlights a critical vulnerability in how industrial facilities isolate their Operational Technology (OT) networks using cellular connections. Because the hackers pivoted from an unrelated wind farm to the power plant, the incident proves that cellular isolation without strict client-level segregation can fail.
The compromised facility provides essential heat to approximately 50,000 residents [3]. According to reports, the attackers used a private APN, a gateway between a mobile network and another network, to bridge the gap between two unrelated energy sites [1, 2]. This method allowed the hackers to move laterally through the cellular provider's infrastructure to reach the plant's OT network [2].
The first breach occurred in 2026 [3]. This event was later publicly disclosed on Aug. 9, 2026, during the DEF CON 34 security conference [4]. Security analysts have since identified a second attack on the Polish power grid that took place in 2026 [2].
Experts said that this represents the first reported instance of a private APN being used as a primary attack vector to sabotage energy infrastructure [2]. While the method is novel, some reports suggest that the underlying APN misconfigurations may be common on an international scale [1].
The attack path began at a wind farm, which shared the same cellular network infrastructure as the heat-and-power plant [1]. By exploiting the lack of segregation between these clients, the hackers bypassed traditional perimeter defenses. Once inside the OT network, the attackers were able to carry out destructive sabotage [2].
This incident has drawn attention to security recommendations previously issued by U.S. federal agencies. The FBI had recommended the use of private APNs for OT security to isolate sensitive systems from the public internet [1]. However, this breach demonstrates that such a recommendation is insufficient if the service provider does not implement rigorous isolation between different customers on the same private network [1, 2].
“The compromised facility provides essential heat to approximately 50,000 residents.”
This breach exposes a systemic blind spot in industrial cybersecurity: the assumption that 'private' cellular networks are inherently secure. By pivoting from a wind farm to a power plant, the attackers proved that the trust placed in telecommunications providers can become a liability. If multiple critical infrastructure sites share the same APN without strict logical separation, a single weak point in one facility can grant an adversary access to an entire regional grid.



