How Hackers Used a Wind Farm to Breach a Power Plant Grid
Warsaw, Saturday, 15 August 2026.
Investigators revealed hackers breached a heating plant by pivoting through a wind farm’s private cellular network, marking the first real-world cyberattack to exploit this novel connectivity path.
Unprecedented Attack Vector Revealed
A comprehensive post-mortem analysis of the December 2025 cyberattack on Poland’s energy sector has exposed a novel vulnerability in critical national infrastructure, marking the first confirmed real-world instance of attackers pivoting through a private cellular network to breach operational technology [1][8]. On 29 December 2025, coordinated cyber-physical attacks targeted over 30 wind and solar farms, alongside a combined heat and power (CHP) plant supplying heat to approximately 500,000 customers [1]. While the initial incidents disrupted remote control and communication with Distribution System Operators, a follow-up report published by CERT Polska on 8 August 2026 revealed a secondary, more intricate breach affecting a second CHP plant serving 50,000 residents [1][8].
Operational Impact and Timing
The attacks occurred during extreme winter weather conditions, exploiting vulnerabilities in remote access and identity management shortly before New Year’s Eve [1]. CERT Polska characterized the incidents as purely destructive sabotage comparable to deliberate acts of arson, affecting both information systems and physical industrial equipment [1]. In the second facility, attackers successfully interrupted the cogeneration process, stopping a steam turbine and water treatment processes after placing industrial controllers into STOP mode [1][8]. This disruption highlighted how distributed generation assets can become scalable cyber-physical risks when sharing common remote access patterns and weakly governed operational technology components [1].
Technical Execution via Private APN
Investigators identified that the attackers compromised a wind farm’s FortiGate appliance and Teltonika cellular router to establish an SSH tunnel into a Distribution System Operator-managed private Access Point Name (APN) [1]. Once inside the private network, the threat actors exploited a WAGO PFC200 controller with default administrative credentials to access the operational technology network at the CHP plant [1]. This lateral movement path, which utilized the private APN as a transport network rather than a security boundary, allowed the attackers to scan for industrial services and establish connections to Siemens PLCs between 18 December 2025 and 25 December 2025 [1][5]. Security experts note that this demonstrates how private APNs are often mistakenly treated as secure zones when they lack proper segmentation and monitoring [3][5].
Regulatory Response and Future Resilience
The incident underscores the urgency of complying with the European Union’s NIS2 Directive and the Cyber Resilience Act, which mandate stricter cybersecurity risk-management measures for essential entities [1]. While the Cyber Resilience Act entered into force on 10 December 2024, specific reporting obligations for actively exploited vulnerabilities are scheduled to begin on 11 September 2026 [1]. As of July 2026, the European Commission had referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify complete transposition of the NIS2 Directive, highlighting inconsistent implementation across the bloc [1]. The Polish campaign serves as a critical reference event, demonstrating that coordinated sabotage of distributed generation assets relies on exploiting existing operational weaknesses rather than novel zero-day exploits [1].