Poland Grid Attack: How a Shared APN Took Down a Power Plant
A hacker didn't need a zero day exploit to knock two Polish power facilities offline. He needed one open door and a network with no walls between machines.
-
Liron
VP system, OneLayer
About this webinar
CERT Polska just disclosed a second attack on Polish energy infrastructure, and it’s the first confirmed real world case of attackers using a private cellular APN to reach into an OT network. The attackers broke into a wind farm substation, then moved sideways across a shared APN into an unrelated combined heat and power plant serving 50,000 residents, putting PLCs into stop mode along the way. No custom malware. No advanced exploit. Just an internet exposed VPN with no MFA, default credentials, an open SSH port on a cellular router, and an APN that let every device on it talk to every other device.
What you'll learn
In this session, our team breaks down exactly how this attack unfolded and what it means for anyone running a private cellular network in a critical infrastructure environment. You’ll walk away understanding:
- How a single unpatched VPN and a set of default credentials turned into a breach of two separate facilities
- Why sharing an APN without isolation between devices is the real story here, not the initial entry point
- What device level segmentation and Zero Trust policies would have contained this attack at the first substation
- The specific configuration checks utilities, oil and gas, mining, ports, and rail operators should be running on their own private LTE and 5G networks this week