Hackers Abuse Private APN to Pivot From Wind Farm Into Polish CHP Plant and Shut Down Turbine
Brief
Attackers abused a misconfigured private mobile APN network to move from a wind farm environment into the operational technology (OT) network of a Polish combined heat and power (CHP) plant, shutting down a steam turbine and water treatment systems.
The incident, investigated by CERT Polska, began with access to a wind farm network and later expanded through a private Access Point Name (APN) network used by the distribution system operator.
The private APN allowed connected devices to communicate with each other, creating an unexpected route into another critical energy environment.
The attackers first accessed a perimeter device at the wind farm and established a remote VPN connection .
They then identified a Teltonika RUTX50 cellular router, accessed its web management interface, and logged in to its SSH service. The SSH access was used to create a tunnel into the private APN.
