Hexnode UEM can support device compliance and policy enforcement on managed administrative endpoints, while Hexnode XDR provides endpoint-focused investigation and response capabilities on supported Windows endpoints. Neither replaces OT segmentation or PLC security.
The Polish energy plant breach disclosed by CERT Polska shows how private connectivity can create an unexpected route into operational technology (OT). An attacker reportedly moved from a compromised FortiGate at a wind farm through a Teltonika cellular router and a private APN to reach a separate combined heat-and-power plant. Weak APN client isolation and default credentials on a WAGO PFC200 then provided a path into the plant’s OT network, eventually leading to its SCADA environment and Siemens PLCs.
The incident is particularly significant because the attacker moved laterally through a private APN rather than relying on a conventional internet-facing route. It highlights a critical OT security principle: private connectivity should not automatically be treated as trusted connectivity.
Polish energy plant breach: Attack chain at a glance
Compromised FortiGate → Teltonika cellular router → private APN without adequate client isolation → WAGO PFC200 with default credentials → SSH pivot → OT network and SCADA → Siemens PLC manipulation
The sequence matters because no single weakness explains the intrusion. Instead, weaknesses across network architecture, device configuration and credential security combined to create a path from one energy facility into another.
Confirmed incident details
Incident detail
Confirmed finding
Target
Polish combined heat-and-power plant
Population served
Roughly 50,000 residents
Operational disruption
December 29, 2025
Initial known foothold
Compromised FortiGate VPN/firewall at a wind farm
Private-network access
Teltonika cellular router connected to a private APN
Key network weakness
Inadequate APN client isolation
OT foothold
WAGO PFC200 PLC
Credential weakness
Default administrator credentials
Pivot mechanism
SSH enabled on the compromised controller
Systems later reached
SCADA interface and Siemens PLCs
PLC action
PLCs switched into STOP mode and password protection enabled
Operational impact
Steam turbine and process-water treatment system shut down
Public impact
No reported impact on residents
A compromised FortiGate opened a route toward another energy facility
The intrusion did not begin at the CHP plant itself.
CERT Polska’s investigation found that the attacker gained administrative access to a FortiGate device at a wind farm and later accessed a Teltonika RUTX50 cellular router. Investigators assessed that the attacker most likely used SSH tunneling through the router to reach the private APN.
That connection created an unexpected path between facilities.
The APN did not adequately isolate connected clients. As a result, the attacker could scan the private network and communicate with devices associated with other sites.
The private APN therefore became a lateral-movement path.
Private APNs can reduce direct exposure to the public internet. However, private addressing and carrier-managed connectivity do not automatically provide segmentation between every connected system.
That distinction became critical in this incident.
How the WAGO PFC200 turned APN access into an OT foothold
Beginning on December 18, 2025, the attacker discovered a WAGO PFC200 PLC belonging to the CHP plant.
The private APN exposed the controller’s web management interface. More importantly, the WAGO PFC200 still used default administrator credentials.
After compromising the WAGO controller, the attacker enabled SSH.
As a result, the PLC became a bridge into the plant’s OT network.
From there, the attacker scanned for SCADA infrastructure and other industrial systems. By December 25, connections had been made to three Siemens PLCs, reportedly as part of activity preceding the later disruption.
The PLC compromise was therefore not caused by one control failure. Several weaknesses compounded:
A previously compromised facility provided access to the private APN.
APN-connected clients were insufficiently isolated.
The WAGO PFC200 management interface was reachable through that network.
The PLC retained default administrator credentials.
SSH could be enabled after the controller was compromised.
The resulting foothold provided access deeper into the OT environment.
Together, these weaknesses increased the impact of each preceding control failure.
How to Conduct an Endpoint Security Audit
Learn how to assess device inventory, patch status, user access and endpoint security controls.
Siemens PLCs were switched into STOP mode on December 29
At approximately 5:30 a.m. on December 29, the attacker accessed the plant’s SCADA interface and Siemens PLCs.
The attacker switched PLCs into STOP mode and enabled password protection. These actions shut down the steam turbine and process-water treatment system, interrupting cogeneration operations.
The attacker also reset or reconfigured Moxa devices. Investigators identified additional activity intended to complicate recovery and forensic reconstruction, including damage to logs or device states along the intrusion path.
However, the operational disruption was limited.
Plant personnel restored the affected systems quickly. The outage was short-lived, and CERT Polska reported no impact on the roughly 50,000 residents served by the facility.
This distinction is important. The incident caused an operational shutdown, but available reporting does not support describing it as a prolonged heating outage affecting the population.
Why the private APN made the Polish energy plant breach unusual
Default credentials, exposed management interfaces and weak segmentation are familiar OT cybersecurity problems.
The distinctive element here was how the attacker reached them.
CERT Polska reported that the attacker moved laterally through a private APN from infrastructure associated with one facility toward another energy site. The agency described this route as a notable real-world attack vector for reaching an OT network.
The attacker did not need the WAGO PFC200 management interface to be directly exposed to the public internet.
Instead, compromise of one environment connected to the APN provided a route toward another connected facility because client isolation was inadequate.
That challenges an important architectural assumption: a private carrier network is not automatically a trusted security boundary.
OT operators should treat private APNs as potentially untrusted connectivity and limit communication between connected systems to what operational requirements actually demand.
Default PLC credentials amplified the APN exposure
Network segmentation was one part of the problem. In addition, the WAGO controller introduced another weakness: default administrator credentials.
A reachable management interface becomes considerably more dangerous when factory credentials remain valid.
Industrial controllers, gateways, routers and engineering interfaces should therefore be included in credential-hardening programs. They should not be treated as appliances that can retain default configurations indefinitely.
Likewise, administrative services require similar scrutiny.
SSH, Telnet and web administration interfaces should not remain broadly reachable simply because they sit behind private infrastructure. Organizations should restrict access to authorized management systems and explicitly required network paths.
For environments using private cellular connectivity, security reviews should cover both the carrier configuration and every administrative interface reachable through it.
What the FortiGate-to-Siemens path tells OT security teams
The attacker crossed several technology boundaries:
The Polish energy plant breach is particularly relevant to organizations reviewing SCADA security, remote industrial sites and private cellular infrastructure. It shows how weaknesses across multiple infrastructure layers can combine to create a path toward operational systems.
Security teams should ask:
Which devices can communicate with one another through each private APN?
Is client-to-client communication disabled unless explicitly required?
Which PLC, router and gateway management interfaces are reachable from those networks?
Have default credentials been removed from every reachable industrial device?
Are SSH, Telnet and web administration interfaces restricted to dedicated management paths?
Can a compromised remote facility communicate with another facility through shared infrastructure?
Are administrative endpoints subject to appropriate security and compliance requirements?
Taken together, these questions expose an important limitation of endpoint controls alone.
A compromised endpoint can be investigated and contained, but endpoint security cannot compensate for an APN architecture that unintentionally permits cross-site communication.
Where Hexnode fits around OT administrative access
The core failures in this incident involved APN isolation, OT segmentation, industrial-device credentials and exposed management services. Hexnode does not replace the controls needed to address those weaknesses directly.
Instead, Hexnode can help organizations secure managed administrative workstations, jump boxes and engineering endpoints used to access sensitive environments. Device policies, compliance controls and endpoint security capabilities can help reduce endpoint-side exposure and provide additional safeguards around administrative access.
This distinction matters because a compromised administrative endpoint can provide attackers with another potential path toward sensitive systems. Organizations should therefore secure these endpoints as part of a layered architecture alongside OT segmentation, PLC hardening and network-level security controls.
Enforcing posture on administrator endpoints with Hexnode UEM
Administrator workstations can become an important control point for OT access.
Hexnode UEM can help organizations enforce configurations and restrictions on supported managed endpoints. It can also manage applications and updates and evaluate devices against configured compliance requirements.
For Windows administrator endpoints, Hexnode UEM can help enforce device-level security controls such as BitLocker encryption, OS and patch management, and application restrictions. This gives organizations additional controls for securing managed Windows endpoints used in administrative workflows.
Separately, for supported Android, iOS/iPadOS and macOS devices, Hexnode UEM can provide device compliance information to Microsoft Entra ID for use in Conditional Access decisions.
These controls strengthen the endpoint side of an administrative workflow. They do not replace network segmentation, PLC hardening or APN client isolation.
Investigating suspicious activity on supported endpoints with Hexnode XDR
Hexnode XDR provides endpoint-focused detection, investigation and response capabilities.
Security teams can investigate endpoint activity using historical process and endpoint event data and Visual Process Tree analysis. Supported response actions include isolating an endpoint, killing a process or process tree, quarantining a file, and deleting the executable associated with a process through Delete the Process Root.
These capabilities can help security teams investigate suspicious activity affecting supported endpoints.
However, Hexnode XDR is not an OT network-monitoring platform. It should not be positioned as detecting PLC manipulation, monitoring private APN traffic or correlating industrial-network telemetry.
Therefore, the distinction between endpoint security and OT network security matters.
An effective architecture requires controls at multiple layers: hardened industrial devices and segmented networks within the OT environment, alongside managed, compliant and monitored endpoints used to administer sensitive systems.
Featured resource
Why XDR Is Stronger With UEM
Explore how combining UEM with XDR can strengthen endpoint security, improve security context and support threat response.
The attacker reportedly started from a compromised FortiGate VPN/firewall at a wind farm. A Teltonika cellular router provided access to a private APN that lacked adequate client isolation. That allowed the attacker to scan for and communicate with devices belonging to another facility connected to the same private network.
How was the WAGO PFC200 compromised?
The WAGO PFC200’s web management interface was reachable through the private APN and protected by default administrator credentials. After compromising the controller, the attacker enabled SSH and used the PLC as a bridge into the plant’s OT environment.
What did the attacker do to the Siemens PLCs?
On December 29, 2025, the attacker accessed the plant’s SCADA interface and Siemens PLCs. The PLCs were switched into STOP mode, and password protection was enabled. The activity shut down the steam turbine and process-water treatment system. Plant personnel restored the affected systems quickly, and CERT Polska reported no impact on residents.
Private APNs should be treated as untrusted connectivity
The Polish energy plant breach demonstrates how infrastructure intended to provide private connectivity can create an unexpected lateral path when isolation assumptions fail.
The attack chain moved from a compromised FortiGate at one facility to a Teltonika router, across a private APN and into a WAGO PFC200 at another facility. From there, SSH provided a bridge toward the OT network, SCADA environment and Siemens PLCs.
Ultimately, that sequence is what makes this incident distinct.
For industrial operators, the lesson is not to abandon private APNs. It is to avoid treating them as security boundaries by default.
Organizations should verify client isolation rather than assume that private connectivity provides it. Communication between sites should follow least-privilege principles. OT operators should remove default credentials from industrial devices and restrict access to unnecessary management interfaces.
Organizations should also test a simple but consequential scenario:
If one remote facility is compromised, what other systems become reachable from it?
In this incident, the answer extended all the way to operational controllers.
Strengthen security across your managed endpoints
Manage endpoint configurations, enforce security policies and maintain device compliance with Hexnode.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.