Sandworm Pivots via Private APN to Brick Wago and Siemens PLCs at Polish CHP Plant
A second Sandworm-linked December 2025 attack on Polish energy infrastructure used an undocumented private APN pivot to reach and sabotage ICS at a CHP plant. Evidence shows exposed management interfaces on common industrial routers and PLCs enabled the chain from wind-farm VPN to bricked controllers. The pattern indicates systemic segmentation failures in energy OT networks that extend beyond Poland.
The parallel campaign hit roughly 30 sites including CHP plants and renewable dispatch centers. Attackers scanned the private APN after establishing the tunnel, identified the Wago controller via enabled SSH, moved laterally to Siemens, Moxa, ABB and Schneider devices, then corrupted the Wago partition table and bricked additional ICS units during cleanup. Heat and power output were restored within hours by factory resets and backup reloads, but the cogeneration process and water treatment halted temporarily during maintenance windows.
Technical evidence shows common Polish and European energy configurations: internet-exposed edge devices sharing networks with OT-adjacent cellular routers, private APNs lacking segmentation between DSO SCADA and substation PLCs, and exposed management interfaces on Wago and Teltonika hardware. These match procurement patterns where cost-driven deployments leave management ports open for remote vendors. No independent technical attribution beyond TTP reuse and target selection is public; Polish CERT links the activity to Sandworm based on prior campaign overlap rather than new infrastructure or code artifacts.
The operation reveals a repeatable path from internet edge to safety-critical ICS that bypasses perimeter firewalls once the APN is reached. Similar misconfigurations appear in regulatory filings and vendor case studies across EU distribution operators. Follow-on campaigns are likely to test the same vector against other national grids before operators complete APN hardening or disable unnecessary SSH services.
CERT.PL: At least five additional EU DSOs will disclose private APN exposures matching the Teltonika-Wago path within 90 days of public advisory release.
Sources (3)
- [1]CERT.PL December 2025 Energy Sector Report(https://cert.pl/en/2025/12/energy-sector-incidents/)
- [2]SecurityWeek Coverage of Polish APN Attack(https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/)
- [3]Dragos Year in Review 2025 Sandworm Activity(https://www.dragos.com/resources/industry-reports/)