
CERT Polska Traces Undetected Heat Plant Breach to Private Cellular Network Pivot from Wind Farm Substations
Poland's CERT uncovered a stealth ICS intrusion at a heat plant via a shared private cellular network used by wind farms. The attack evaded detection for months due to misattribution to maintenance error and was only reconstructed from partial logs. This exposes gaps in NIS2 reporting and the assumption that cellular infrastructure is isolated from critical control systems.
Energy operators must now treat private cellular links as untrusted transit rather than segmented infrastructure. Expect mandatory logging retention on cellular routers and removal of factory defaults within six months as Polish regulators respond. Unreported low-severity events on similar networks will likely surface once mandatory disclosure rules tighten.
CERT Polska: At least three additional unreported private cellular pivots into Polish ICS sites will be disclosed by March 2025 once mandatory logging audits complete.
Sources (3)
- [1]CERT Polska Supplementary Report(https://cert.pl/en/2024/heat-plant-incident-analysis)
- [2]The Record Coverage(https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden)
- [3]NIS2 Directive Text(https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)