Polish authorities have disclosed a previously unknown cyber-attack against a combined heat and power plant serving roughly 50,000 residents. CERT Polska revealed that the incident has been attributed to Russia's FSB and took place in a coordinated attempt to take down more than 30 renewable energy installations and a larger heat plant. Officials said these hack attempts came "very close" to causing a blackout for nearly 500,000 people during one of Europe's coldest winters. Operators initially blamed a contractor error for the December 29 shutdown of the steam turbine and water treatment systems; only a 3-month investigation revealed what seems to be the first known use of a private cellular data network as a pathway into an industrial control system, with attackers moving from compromised wind farm firewalls through a cellular router to a controller running default credentials.
According to reports, attackers were able to spend 11 days conducting reconnaissance without being detected before striking on Christmas Day. They then destroyed forensic evidence along their entire path — corrupting gateway devices, resetting firewalls and routers, and wiping configurations to slow recovery. Investigators were only able to reconstruct the attack because one router ran older software that preserved event logs through a factory reset. CERT Polska notes the underlying misconfiguration was common in Poland at the time and is believed to be widespread internationally.
Critical infrastructure operators must evolve to have forensic-grade evidence retention that survives attacker cleanup: had the plant maintained continuous, tamper-resistant capture of network and endpoint activity across its OT and adjacent IT paths, the December 29 shutdown would not have taken three months to identify as an intrusion, and the wind-farm-to-heat-plant lateral movement would have been visible in real time. Platforms like NIKSUN give energy operators the visibility to detect cross-facility lateral movement, catch reconnaissance activity before disruption occurs, and preserve the evidence needed for attribution even when attackers deliberately erase their tracks. Read more about this story on our LinkedIn page
We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.
Essential Cookies
Site Analytics
Essential Cookies
These cookies are necessary for certain areas of the site to function. They are used for access to secure areas of the website and to help us comply with legal requirements like GDPR.
Site Analytics
These cookies are used to collect information about how users use our site. We use these to improve how our website works.