Early on the morning of December 29, 2025, a steam turbine at a combined heat and power plant in Poland stopped. So did the system that treats the plant’s process water. The facility served heat and electricity to roughly 50,000 residents, and for a few hours its cogeneration process was interrupted. Staff scrambled and got everything back before any customer lost heat or power. But when investigators pieced together what had happened — an effort that took more than three months — they found something that had never been documented before in a real-world attack, and a lesson that applies to far more businesses than just power plants.
The attackers didn’t break into the power plant directly. They broke into a wind farm — a completely separate company, miles away — and then walked from one to the other through a connection that neither facility even controlled. It’s one of the most instructive intrusion stories we’ve covered, so let’s follow the whole path, because the trail these attackers walked has a small-business equivalent that almost nobody thinks about. This is the third story we’ve covered recently about attacks on the systems that run physical infrastructure, and it may be the most revealing of the set.
A quick note on why this is here
Before we trace the attack: this happened in Poland, at an energy facility, and we cover it the way we cover any infrastructure story — factually, apolitically, and with no interest in who to blame. The investigating agency, CERT Polska, did not publicly attribute the attack to any particular group, and we take no view on that question. What earns this story a place on a small business blog is not the geopolitics. It’s the method — a method that quietly exists inside a huge number of ordinary businesses, waiting to be understood.
The path: from a wind farm to a turbine
Here is the journey the attackers took, step by step. Follow the shape of it rather than the technical names — the shape is the lesson.
- The foothold: a wind farm’s security appliance. The attackers first got into a wind farm’s network through an internet-facing security device — the box meant to be its firewall and secure remote-access gateway. According to investigators, that device accepted local accounts without multi-factor authentication, which turned the guard at the gate into an open door.
- The bridge: a cellular router and a hidden tunnel. On that wind farm network sat a small cellular router. The attackers logged into it and used it to open a secret tunnel onto something called a private APN — a dedicated, private cellular network run by the regional grid operator to let its scattered energy sites talk to its central systems.
- The crossing: one private network, many companies. Here’s the crucial part. That private cellular network was configured so that any device on it could talk to any other device on it. The wind farm was on it. The power plant was on it. So once the attackers were on the shared network via the wind farm, they had an unobstructed path straight to the power plant’s industrial controls — despite the two being entirely separate businesses.
- The reconnaissance: patient and quiet. They didn’t rush. Over about a week and a half, they scanned the private network, found an industrial controller at the plant with its admin interface exposed and protected only by default credentials, and used it as a stepping stone deeper into the plant’s operational network. They connected to the plant’s main control systems days before doing anything destructive — looking around, learning the layout.
- The sabotage. On the morning of December 29, they reached the plant’s core industrial controllers — the computers that directly run the physical machinery — and switched them into “stop” mode, then locked them with a password so operators couldn’t easily reverse it. The turbine halted. The water treatment stopped. The plant’s normal operation broke.
- The cover-up. On the way out, they tried to erase the trail — resetting the cellular router, changing its settings to block reconfiguration, and wiping the original security appliance at the wind farm to destroy its logs. One industrial controller they damaged so badly it reportedly wouldn’t boot even after a factory reset. Investigators had to reconstruct the sequence backward from the fragments that survived.
The one sentence that makes this historic: the investigators stated that, to the best of their knowledge, this was the first time anyone has observed a real attack reaching an industrial control network by crossing through a private cellular network like this. It’s a genuinely new move — and its lesson is not about cellular networks specifically. It’s about a kind of danger that hides in the connections between companies, in places nobody owns and nobody watches.
The real lesson: the danger you don’t control
Strip away the turbines and this is a story about trusted connections — the links between your business and other organizations that exist for good, practical reasons, and that you rarely think about as a risk. The wind farm and the power plant were both just… connected to a shared network, by a third party, for legitimate operational purposes. Neither one ran that network. Neither one was really watching it. And that quiet, trusted, unwatched connection became the highway for the entire attack.
That pattern is everywhere in ordinary business, and it almost never gets examined:
- Your vendors’ remote access. The company that services your HVAC, your alarm system, your point-of-sale, your specialized equipment — many of them have a remote connection into your systems so they can support you. That’s a door into your business that someone else holds the key to. If they get breached, that door may open into you.
- Shared platforms and portals. The systems you share with partners, suppliers, franchisors, or clients are connections that run in both directions. Their security is now part of yours.
- The “managed” device in the closet. The internet-connected box some outside company installed and maintains — the one you were told not to touch. Do you know how it’s secured? Do you know if it can reach the rest of your network? Who’s watching it?
- Convenience connections between your own locations. The link a technician set up years ago so two offices, or the shop and the warehouse, could share resources. A breach at the weakest location can become a breach everywhere the network reaches.
In this attack, the plant did a lot right internally and still got hit — because the danger didn’t come through its front door. It came through a side door connected to a neighbor, over a road built and owned by someone else. That is the uncomfortable, important idea: your security is only as strong as the things you’re connected to, including the ones you don’t control and can’t see.
The recurring villains: default passwords and no MFA
It’s worth pausing on how the attackers actually opened each door, because it’s maddeningly familiar and it’s the part every business can act on immediately. This was not, at its entry points, a story of exotic genius. Two boringly common failures did the heavy lifting:
- No multi-factor authentication on the internet-facing gateway that gave them their first foothold. A second verification step could have stopped the intrusion at step one.
- Default credentials on a controller inside the plant — the factory-set username and password that were never changed, letting the attackers use it as a stepping stone once they were on the network.
We highlight this in nearly every breach we write about because it keeps being true: the sophisticated attack usually gets its start through an unsophisticated opening. Multi-factor authentication everywhere it’s offered, and changing every default password on every device, are not glamorous. They are simply the two cheapest, highest-value locks a business can install — and their absence is what turned a wind farm into a doorway to a power plant.
Worth asking about your own business: Which outside companies have a remote connection into your systems — and when did anyone last check how well-secured their end is? * Is there any device on your network that a vendor installed and manages, that you can’t see into? * If your weakest-secured location or partner were breached, could an attacker travel from there into everything else? * And does every internet-facing login you have — including the ones a vendor set up — require more than just a password?
The good news, and what to do
Here’s the reassuring part. The plant’s staff caught the disruption and restored operations quickly enough that no customer lost heat or power — a real credit to having people who knew their systems and could respond. And the underlying defense against this whole class of attack, while it takes expertise to implement, rests on a principle that’s easy to grasp: things that don’t need to talk to each other shouldn’t be able to. A wind farm and a power plant have no reason to reach each other’s controls. Your guest Wi-Fi has no reason to reach your accounting system. A vendor’s maintenance connection to one machine has no reason to reach your whole network.
Building those internal walls — so that a breach in one place stays contained instead of spreading everywhere — is called segmentation, and it’s one of the most effective protections there is. Combined with mapping every outside connection into your business and making sure each one is locked down and can only reach what it truly needs, it’s how you make sure a problem at a company you’ve never heard of doesn’t become a problem for you.
That mapping and containment is exactly what our environment review is built to deliver. We identify every way into your network — including the vendor connections, the managed devices, and the links between locations that you’ve stopped noticing — assess how each is secured, and help you wall off the parts of your business that should never have been reachable from one another. The power plant in this story was undone by a road it didn’t build and a door it didn’t own. The first step to being safe from that is simply knowing every road that leads to you. Most businesses have never once mapped them. That’s the gap worth closing before someone else maps them for you.
Sources: CERT Polska incident report (disclosed August 8, 2026, concerning a December 29, 2025 incident); The Hacker News; BleepingComputer; Help Net Security; SecurityWeek; Security Affairs; SC Media; GBHackers, August 2026. CERT Polska described this as, to its knowledge, the first observed real-world use of a private APN to reach an OT network. No public attribution has been made; this article takes no view on responsibility.













