securityaffairs.com 8/10/2026, 5:32:00 PM · external

Polish Power Plant Breached via Wind Farm VPN and Fortinet Flaw

Polish Power Plant Breached via Wind Farm VPN and Fortinet Flaw
Developing story campaign 2 articles tracked
Polish power plant breached via Fortinet VPN and private APN
CyberSIXT Evidence Panel
Primary Source cert.pl

IN a significant cyber incident detailed by Poland's CERT, hackers penetrated a Polish combined heat and power (CHP) plant using a private APN (Access Point Name) linked to a previously exposed Fortinet firewall. The breach originated at a wind farm where attackers accessed the system via a VPN, then used SSH to connect through a Teltonika router to the plant's operational network.

This resulted in critical disruptions, including a shutdown of key systems like the steam turbine and water treatment facilities, though operators managed to restore functionality without severe outages. The report emphasizes the vulnerabilities of common network structures, the attackers' use of conventional entry points, and the critical need for robust defense measures for edge devices in operational technology environments.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline