Hackers Breached a Small Polish CHP Plant via Misconfigured Private APN, Shutting Down Steam Turbine
What Happened — In December 2025 a threat actor linked to the Russian Electrum group compromised a FortiGate VPN at a wind farm, then leveraged a Teltonika cellular router to tunnel into a private Access Point Name (APN) used by the distribution system operator. The APN lacked client isolation, allowing the attacker to reach a WAGO PFC200 PLC at a combined‑heat‑and‑power (CHP) plant, use default credentials to enable SSH, and ultimately stop the plant’s steam turbine and water‑treatment system.
Why It Matters for Compliance & Audit Readiness
- Misconfigured network segmentation is a classic control‑gap scenario that SOC 2 continuous‑compliance programs are built to detect, monitor, and evidence.
- Demonstrates the need for documented configuration‑management and change‑control processes (CC6.1 Logical Access, CC7.1 System Operations) that can be audited in real time.
- Highlights the value of continuous control‑mapping and evidence collection to prove that isolation controls are enforced across all network segments, including private APNs.
Who Is Affected – Energy & utilities (combined‑heat‑and‑power, wind, solar), OT device vendors, telecom providers managing private APNs.
Recommended Actions –
- Map the APN client‑isolation requirement to SOC 2 control CC6.1 and implement automated checks.
- Conduct a configuration‑audit of all VPN/firewall and cellular‑router settings; remediate default credentials.
- Capture continuous evidence of network‑segmentation controls in a centralized Trust Center for audit readiness.
Source: BleepingComputer
Technical Notes – Attack vector: private‑APN misconfiguration; exploited default PLC admin credentials; leveraged FortiGate VPN, Teltonika router, WAGO PFC200 PLC, Siemens PLCs. No permanent service disruption reported. Source: same article