ics-ottrade-pressNewsThe Broadside2 min read

Private cellular network used to breach Polish heat plant ICS

The industry treats private cellular networks as secure, walled-off infrastructure; the attackers used one to pivot from wind farm firewalls to a heat plant controller still running factory default credentials.


TL;DR

CERT Polska has disclosed a previously unknown cyberattack on a combined heat and power plant serving roughly 50,000 residents, occurring the same day as the coordinated grid strikes Poland attributed to Russia's FSB. The incident went unrecognized for months; operators blamed a contractor error for the shutdown. Investigators found the attackers pivoted through a private cellular data network to reach a controller running factory default credentials, the first known use of this pathway against industrial control systems.

The newly disclosed attack on the combined heat and power plant is the more instructive of the two, precisely because it was initially dismissed. When the steam turbine and water treatment system shut down during routine maintenance over the Christmas period, plant operators logged it as a contractor error. It wasn't. CERT Polska's investigation, which took more than three months, reconstructed an attack chain that is now the first documented case of attackers using a private cellular data network as a pathway into industrial control systems.

The route was lateral in a way that defeats standard assumptions about segmentation. Attackers started at firewalls already compromised at wind farm substations, moved to a cellular router connected to a private mobile data network the energy sector treats as walled-off infrastructure, and from there hopped to a controller at the heat plant still running factory default credentials. The wind farm and the heat plant had no direct operational relationship. Their only connection was shared presence on the same private network, which the attackers used as a bridge.

Once inside, they spent 11 days on reconnaissance, probing industrial equipment, testing credentials, and mapping targets on Christmas Day. Before dawn on December 29, they disabled the Siemens controllers running the steam turbine and water treatment system, locked operators out with new passwords, and wiped network equipment configurations with automated scripts. Plant staff began restoring systems roughly two hours later while the attackers were still active, limiting the disruption. The hackers then destroyed forensic evidence along their entire path, corrupting the gateway device beyond repair and resetting firewalls and routers behind them.

CERT Polska's report draws a pointed contrast with the EU's NIS2 directive, which mandates reporting of confirmed incidents. The agency argues that unexplained operational failures deserve the same scrutiny. When a heat plant serving 50,000 people goes down during a winter cold snap, the default assumption cannot be "contractor error" just because no alarm identified a breach. The attackers counted on that assumption, and for three months, it worked.


Published ·Deep Fathom