Attackers Exploit Private APN to Breach Polish CHP Plant OT Network, Shutting Steam Turbine
What Happened — On 29 December 2026 a combined heat‑and‑power (CHP) plant in Poland was infiltrated via a private APN used by the local Distribution System Operator. The attacker accessed a WAGO PFC200 PLC with an integrated cellular modem, causing the steam turbine and water‑treatment system to stop. Operators restored service before heat or electricity supplies were impacted.
Why It Matters for Compliance & Audit Readiness
- The incident shows how undocumented or mis‑segmented remote‑access channels can bypass traditional OT isolation, a gap SOC 2 controls (CC6.1 Logical Access, CC7.1 System Operations) are designed to close.
- Continuous evidence of network‑segmentation mappings and remote‑device inventories is essential to prove due diligence during an audit.
- Verisq’s Control Mapping capability can automatically correlate private‑APN configurations to SOC 2 control requirements, providing real‑time audit evidence.
Who Is Affected – Energy & utilities operators that rely on private cellular networks for remote device management; vendors of industrial PLCs with cellular modems.
Recommended Actions
- Inventory every private APN and any cellular‑enabled PLC; document business justification and access controls.
- Enforce strict network segmentation: keep APN traffic separate from OT control networks and enforce firewall rules.
- Deploy continuous monitoring of remote‑access devices and log all APN traffic for audit‑ready evidence.
Technical Notes – Attack vector: misuse of a private APN (cellular) to reach a PLC; no CVE disclosed. Impacted device: WAGO PFC200 PLC with integrated modem; disruption limited to steam turbine and water‑treatment system, no customer‑facing outage. Source: Help Net Security