Actor Profile

No specific threat actor has been publicly attributed to this campaign. The December 2025 attacks targeted Poland's energy infrastructure with purely destructive intent, representing a coordinated operation against multiple facilities including wind farms, solar installations, and combined heat and power (CHP) plants. The campaign demonstrated advanced operational planning and knowledge of industrial control systems, with attackers exploiting a previously unobserved attack vector involving private Access Point Name (APN) networks to access operational technology (OT) environments.

TTPs (Tactics, Techniques, Procedures)

The campaign leveraged a novel initial access vector exploiting misconfigured private APN networks used for cellular connectivity to OT systems. Attackers gained unauthorized access through arbitrary device-to-device communication enabled by APN misconfigurations, allowing lateral movement within the private cellular network. Once inside the OT environment, operators conducted destructive actions targeting industrial control systems, specifically shutting down a steam turbine and water treatment system at a CHP plant. The attack demonstrated knowledge of SCADA/ICS operations and the ability to disrupt cogeneration processes. The use of private APN as an attack vector represents a significant evolution in OT-targeting techniques, exploiting trust relationships within cellular network segments that are often assumed to be isolated.

Targets & Patterns

The campaign specifically targeted Poland's energy sector, focusing on critical infrastructure providing electricity and heating to civilian populations. Victims included 30 wind and solar power installations and two combined heat and power plants—one large facility and a smaller plant serving 50,000 residents. The selection of CHP plants during winter months (December) suggests intent to maximize impact on heating supplies during peak demand periods. The targeting pattern indicates the adversary possessed detailed knowledge of Poland's energy infrastructure topology and operational dependencies. The purely destructive objective—rather than espionage or financial gain—suggests nation-state motivation or ideologically driven sabotage. The coordinated nature of simultaneous attacks across multiple facilities demonstrates sophisticated planning and reconnaissance capabilities.

Historical Context

This campaign represents the first cyberattack against Poland's energy sector with purely destructive objectives, marking an escalation from previous reconnaissance or espionage-focused intrusions. The December 29, 2025 attacks were initially disclosed by CERT Polska in an earlier report covering the larger CHP plant and renewable energy installations. The August 2026 follow-up report revealed a parallel, previously undisclosed attack on a second CHP plant that occurred during the same timeframe. The three-month investigation uncovered the private APN attack vector, which CERT Polska assesses had not been observed in real-world cyberattacks prior to this incident. Surveys following the incident revealed that the exploited APN misconfiguration was widespread in Poland and likely common internationally, suggesting potential for similar attacks elsewhere.

Defensive Recommendations

  • Audit private APN configurations to ensure device-to-device communication is restricted and segmented; implement strict access control lists preventing arbitrary connectivity between devices within the APN network
  • Deploy network monitoring and anomaly detection within private APN segments to identify unauthorized device connections or unusual lateral movement patterns between cellular-connected OT assets
  • Implement defense-in-depth for OT environments by ensuring private APN connectivity does not bypass network segmentation controls; treat cellular connections as untrusted network boundaries requiring authentication and inspection
  • Conduct regular security assessments of cellular-connected industrial control systems, including penetration testing scenarios that assume compromise of the private APN infrastructure
  • Establish out-of-band monitoring and emergency shutdown procedures for critical OT systems that do not rely on potentially compromised cellular network paths

---

# Geopolitical Context

Geopolitical Context

The December 2025 coordinated attacks on Poland's energy infrastructure—targeting wind, solar, and combined heat and power (CHP) facilities—represent the first purely destructive cyber operation against the country's energy sector. The timing and scope of the campaign, which affected critical heating infrastructure serving tens of thousands of residents during winter, suggest strategic intent to disrupt civilian services and test resilience of NATO's eastern flank energy systems. The disclosure of a second, previously unreported CHP plant compromise underscores the breadth of reconnaissance and operational planning involved. The use of a novel attack vector—exploitation of misconfigured private Access Point Name (APN) networks commonly deployed in industrial control environments—indicates adversary adaptation to operational technology (OT) security architectures. CERT Polska's assessment that this configuration is widespread both domestically and internationally elevates the incident from a national security concern to a systemic vulnerability with implications for critical infrastructure globally.

State Actor Alignment

No formal attribution has been published by Polish authorities or CERT Polska as of this report. However, the sophistication, coordination, and destructive intent of the campaign are consistent with state-sponsored advanced persistent threat (APT) activity. Poland's geographic position, NATO membership, and role as a logistics hub for support to Ukraine make its critical infrastructure a strategic target for adversaries seeking to undermine alliance cohesion or signal capability. The timing—late December, during peak heating demand—aligns with tactics observed in previous operations attributed to actors linked to states with adversarial postures toward NATO and EU member states. Any formal attribution or sanctions response would likely be coordinated through EU or NATO frameworks, given the cross-border implications of the attack vector identified.

Business Impacty pro region

The incident has significant implications for European energy security and critical infrastructure defense. Poland's energy sector is integrated into the EU grid and plays a key role in regional energy transit, particularly as Europe diversifies away from Russian energy dependence. A successful destructive attack on heating infrastructure during winter months could serve as a template for operations targeting other Central and Eastern European states with similar OT architectures. The identification of widespread private APN misconfigurations suggests that energy operators across Europe—and globally—may be vulnerable to the same attack vector. This is likely to prompt urgent reviews of mobile network segmentation practices in OT environments by national CERTs, regulators, and the European Union Agency for Cybersecurity (ENISA). The public disclosure at DEF CON signals Poland's intent to share threat intelligence broadly, reinforcing transatlantic cybersecurity cooperation and raising awareness among critical infrastructure operators worldwide.

Forecast

If the identified private APN misconfiguration remains widespread and unaddressed, additional attacks exploiting this vector are likely in the near to medium term, particularly against energy and utilities sectors in Europe and other regions with similar OT connectivity models. Should formal attribution emerge linking the December 2025 campaign to a state actor, coordinated EU or NATO-level sanctions and diplomatic responses may follow, potentially escalating cyber tensions. In the coming months, expect increased regulatory scrutiny of mobile network segmentation in critical infrastructure, with national authorities likely mandating configuration audits and hardening measures. If geopolitical tensions in Eastern Europe persist or escalate, Poland's energy infrastructure may remain a high-priority target, prompting further investment in OT security, threat hunting, and public-private information sharing. The incident may also accelerate adoption of zero-trust architectures and network segmentation best practices in industrial environments globally.