On 29 December, threat actors compromised a Polish combined heat and power plant via a Fortinet appliance and a private APN, gaining access to PLCs and interfering with water treatment and turbine operations.
CERT Polska released a detailed follow up report on August 8th 2026 outlining the attack, providing an opportunity to understand and map a real attack against critical infrastructure providers.
We can visualise this incident with Hunt Nexus.

The Entry Point: A Wind Farm, 30 Sites Away
The APN access connected back to a wind farm substation that was compromised weeks earlier through an internet-facing FortiGate VPN appliance with no multi-factor authentication.
From there, a Teltonika cellular router, dual-homed between the substation's OT network and the private APN, gave the attacker a route in.
The Pivot: A Private APN
The WAGO controller wasn't reachable from the internet. It was reachable from a private APN, a cellular network operated by the Distribution System Operator to let SCADA systems talk to remote substations.
That network had no client isolation between connected devices, which meant that once inside it, the attacker could scan for devices listening.
The Bridge: A WAGO PFC200 Controller
A WAGO PFC200 controller with a cellular modem had connectivity to both the SCADA system and the industrial device segments, used as a gateway by the threat actor.
Its partition table was deliberately corrupted and a factory reset by plant operators couldn't recover it.
The CHP Plant
The plant's steam turbine and water treatment system were shut down after three Siemens PLCs, an S7-300, S7-1200, and S7-1500, were switched to STOP mode and password-locked.
Alongside them, seven Moxa serial servers and three Moxa switches were factory-reset and reassigned unreachable IP addresses.
Hunt Nexus is part of the threathunt.app toolkit. Start a free trial and try the tool yourself at tools.threathunt.app.