Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Hackers Cross From IT to OT Through a Private APN in Poland Pierluigi Paganini
    Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking network design can turn into a route into OT. The target was a smaller combined heat and power plant feeding heat to around 50,000 residents, and the attackers used a private APN as the path in, som
     

Hackers Cross From IT to OT Through a Private APN in Poland

10 de Agosto de 2026, 13:17

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems.

Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking network design can turn into a route into OT. The target was a smaller combined heat and power plant feeding heat to around 50,000 residents, and the attackers used a private APN as the path in, something CERT says it saw for the first time in this incident.

The report says the intrusion began at a wind farm, where the attackers hit a Fortinet VPN and firewall device exposed to the internet.

Poland

From there they found a Teltonika cellular router, used SSH to build a tunnel, reached the private APN managed by the distribution system operator, and then moved toward the plant’s OT network.

“On 29 December 2025, coordinated attacks targeted the energy sector in Poland, including 30 renewable energy facilities and a large combined heat and power (CHP) plant. These attacks were described in detail in the report published on 30 January 2026*. At the same time, another incident occurred at a smaller CHP plant supplying heat to 50,000 residents.” reads the report published by Poland’s CERT. “The analysis of this incident took more than three months to complete, which is why it was not included in the initial report. To the best of our knowledge, the attack vector used in this case has not previously been observed in any known incidents.”

Once inside, the attackers found a Wago PLC at the CHP plant and used SSH access on that controller to reach the operational network. After roughly a week of reconnaissance, they connected to Siemens PLCs, switched them to stop mode, and set a password that blocked operators from changing the controllers’ state and control logic.

Poland

That is where the physical impact started. The steam turbine and water treatment system shut down, the cogeneration process broke, and the plant lost service continuity for a while, though staff restored the affected systems quickly enough to avoid a heat or electricity outage.

“The attacker then damaged the WAGO controller that had been used as a gateway into the network by corrupting its partition table, preventing it from being read by the device. In an attempt to restore the controller, the affected entity performed a factory reset; however, this did not repair the partition table and the device remained unable to boot.” continues the report. “No valuable logs could be recovered from the device during the investigation.”

The report also shows how messy real intrusions get once the attacker is inside the control environment. Moxa serial device servers and Moxa network switches were reconfigured to block legitimate access, ABB and Schneider Electric variable frequency drives were touched as well, and some connection attempts failed or were only partially successful.

“An important aspect of this architecture is that DSOs require all communication between the DSO’s ICT network and the RTU to take place over a serial protocol, in this case DNP3.0. At the compromised facility, a Teltonika RUTX50 router was used, and the DSO’s requirements were met. However, no requirements had been defined regarding the handling of the cellular router’s administrative interface.” continues the report. “As a result, the router was configured with two physical interfaces: a serial link connected to the RTU and a second interface, Ethernet, connected to a VLAN managed by the central firewall that had been compromised by the attacker.”

That is the uncomfortable part. The attackers did not need some exotic zero-day chain to do damage. They used a reachable edge device, a private APN that was already in the path, weak or exposed access points, and enough patience to move from reconnaissance to disruption.

CERT notes that the attackers damaged some devices while trying to cover their tracks, and in the WAGO case the controller could not be brought back by a simple reset. The agency also says this kind of private APN setup is not rare, which is exactly why the finding matters beyond Poland.

“As maintenance work was being carried out at the facility, the entity initially assumed that the process interruption had been caused by an error made by the contractor’s engineers and reported the event for informational purposes only.” continues the report. “However, due to its awareness of other similar events, CERT Polska initiated incident handling under the assumption that the event may have resulted from a cyberattack. Further analysis confirmed this hypothesis.”

The practical lesson is not subtle. Private APNs, edge routers and OT gateways need the same discipline as any other exposed infrastructure, because once an attacker can pivot from a field device into control systems, the difference between “maintenance” and “incident” gets very thin.

The original report is here: CERT Polska Energy Sector Incident Follow-up Report 2025.

In early 2026, ESET linked a late-2025 cyberattack on Poland’s energy system to the Russia-linked Sandworm APT.

“Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed,” said ESET researchers. “We’re not aware of any successful disruption occurring as a result of this attack,” ESET researchers said.

ESET researchers uncovered DynoWiper, a destructive wiper malware used in an attempted cyberattack against Poland’s energy sector on December 29, 2025. While no successful disruption has been confirmed, the malware’s architecture shows clear destructive intent. ESET attributes the operation with medium confidence to the Russia-aligned Sandworm APT group, citing strong overlaps in tactics, techniques, and behavior with previous Sandworm-linked wiper attacks analyzed by the team.

The attempted attack occurred during peak winter demand and coincided with the 10-year anniversary of Sandworm’s 2015 cyberattack on Ukraine’s power grid, the first malware-induced blackout that left around 230,000 people without electricity. ESET tracks the DynoWiper malware as Win32/KillFiles.NMO. Subscribers to ESET’s private Threat Intelligence APT reports have already received further technical details and indicators of compromise to aid rapid detection and incident response. The cybersecurity firm also shared an associated IoC hash for defensive use.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Poland)

  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇ASEC BLOG
  • June 2026 Dark Web Threat Actor Trend Report ATCP
    Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
     
  • ✇Firewall Daily – The Cyber Express
  • University of Warsaw Data Breach Exposes 200,000+ Sensitive Files on Darknet Ashish Khaitan
    Over 200,000 files containing sensitive personal information have been leaked following the University of Warsaw cyberattack that targeted the institution’s digital systems. The attack, which resulted in the publication of the stolen data on the darknet in mid-April 2026, has raised significant concerns about the university's cybersecurity protocols. In response to the breach, the University of Warsaw took immediate action, isolating affected systems and working closely with relevant authoritie
     

University of Warsaw Data Breach Exposes 200,000+ Sensitive Files on Darknet

University of Warsaw cyberattack

Over 200,000 files containing sensitive personal information have been leaked following the University of Warsaw cyberattack that targeted the institution’s digital systems. The attack, which resulted in the publication of the stolen data on the darknet in mid-April 2026, has raised significant concerns about the university's cybersecurity protocols.

In response to the breach, the University of Warsaw took immediate action, isolating affected systems and working closely with relevant authorities to assess the scope of the incident. Rector Alojzy Z. Nowak commented, “Immediately after detecting the incident, the University undertook a series of actions aimed at limiting its impact and securing the IT environment. These included isolating affected systems, terminating unauthorized access, enforcing password resets for all users, strengthening authentication mechanisms, and conducting a comprehensive security review of the infrastructure.”

How the University of Warsaw Cyberattack Unfolded 

The cyberattack unfolded over several months, with attackers gaining access to the university's systems using valid login credentials. These credentials were likely obtained through malware that infected a user’s device, allowing the attackers to quietly exfiltrate large amounts of data over time. The stolen data was eventually posted on the darknet on the night of April 15, 2026, in an 850-gigabyte data dump.

The breach was initially detected on February 9, 2026, during a routine security scan, triggered by global ransomware threats. At first, it was believed that the stolen data had not left the university’s infrastructure. However, subsequent investigation revealed that a significant portion had already been leaked online.

In response to our inquiry, the university clarified: “At this stage, the investigation is ongoing, and no definitive attribution has been publicly confirmed. The incident involved unauthorized access using valid credentials that had likely been previously compromised, most probably through malware on a user’s device.”

What Data Was Exposed? 

The leaked files, which total over 200,000 documents, include a broad range of sensitive information. A large portion of the data came from the Faculty of Applied Social Sciences and Resocialization, as well as the Faculty of Neophilology. The breach exposed approximately 650 GB of publicly accessible audiovisual materials, along with 200 GB of sensitive personal data.

Among the types of personal data exposed were:

  • Identification details: Full names, birthdates, gender, nationality, PESEL numbers, and identity document numbers (e.g., passport numbers).
  • Contact information: Home addresses, phone numbers, email addresses, and usernames.
  • Financial and tax information: Bank account numbers and tax records.
  • Employment data: Employment contracts and career histories.
  • Health records: Information from medical certificates, including sick leave records.

The university has acknowledged that it’s still too early to definitively determine which individuals' data has been impacted. In an official statement, they noted, “Given the nature of the incident, it is not yet possible to conclusively determine which specific individuals’ data may have been impacted; therefore, we encourage all members of the academic community to follow the recommended guidance and monitor further updates.”

Official Response and Security Measures 

Following the breach, the university has worked diligently to mitigate further damage. In addition to isolating the affected systems, the university has collaborated with Poland’s Central Bureau for Combating Cybercrime (CBZC) and CERT Polska to investigate the incident and fortify its cybersecurity defenses.

“We remain committed to fully clarifying the circumstances of this incident and to continuously improving the protection of personal data,” Rector Nowak stated. The university also emphasized its ongoing efforts to enhance security measures, including expanding advanced authentication methods, increasing network monitoring, and further segmenting IT infrastructure to reduce exposure to future risks.

Moreover, the university has published a detailed communication, following GDPR guidelines, to inform affected individuals about the breach and provide recommendations on how they can protect themselves. “Affected individuals are being informed through an official public communication available on the University’s website,” the statement said. “These include, among others, monitoring financial activity, securing personal data (e.g., PESEL number), changing passwords, enabling multi-factor authentication, and remaining vigilant against phishing or fraud attempts.”

Consequences of the Warsaw University Data Leak 

The leaked data presents a serious risk to those affected. The exposure of personal identification details, financial information, and health records could lead to a range of harmful outcomes, including: 
  • Identity theft: Cybercriminals could use the stolen data to impersonate individuals, open accounts in their names, or conduct fraudulent transactions.  
  • Financial fraud: With access to sensitive financial information, attackers may attempt to take out loans, make unauthorized purchases, or commit tax fraud.  
  • Health and privacy violations: Unauthorized access to medical records could lead to misuse of health-related information for fraud or exploitation.  
Moreover, the data leak also carries legal and operational risks, such as wrongful use of personal data in official systems or academic environments. University applicants could face fraudulent claims or be targeted by scams related to university admissions or scholarship offers. 

Preventive Actions and Recommendations 

While the university has taken immediate steps to isolate the affected systems and enhance its security infrastructure, there are additional measures individuals can take to protect themselves from potential fallout: 
  • Monitor financial and credit activity: Individuals should check their credit reports for any suspicious activity and set up alerts for new credit inquiries.  
  • Change passwords and use multi-factor authentication: Affected individuals should update their passwords for email, bank accounts, and university systems, ensuring they use strong, unique passwords for each service.  
  • Be cautious of phishing attempts: The exposure of personal data may lead to targeted phishing attacks. Individuals should remain vigilant when receiving unsolicited messages, particularly those related to banking or health services.
❌
❌