www.infosecurity-magazine.com 8/12/2026, 9:51:32 AM · external

Sandworm hits Polish power plant via private APN, brief outage

Sandworm hits Polish power plant via private APN, brief outage
CyberSIXT Evidence Panel
Threat Actor

RUSSIAN-LINKED hackers targeted a Polish power plant's operational technology (OT) network through a private Access Point Name (APN) during a cyber campaign in December 2025, as reported by Poland's Cybersecurity Incident Response Team (CERT.PL). This attack, traced back to the Sandworm group, involved sophisticated methods leading to the shutdown of crucial systems at a combined heat and power (CHP) plant that serves approximately 50,000 residents.

The attackers initially compromised a VPN firewall at a connected wind farm before accessing the CHP plant. Following the incident, CERT.PL recommended audits and enhanced security measures for organizations using private APNs, highlighting the importance of network segmentation and monitoring. Fortunately, the outage was brief and did not lead to power loss.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline