Most industrial security programmes draw a hard line between “the internet” and “our private network.” CERT Polska’s latest report shows what happens when an attacker finds a private network that was never actually private.
From a wind farm’s firewall to a heat plant’s turbine
On December 29, 2025, coordinated attacks hit more than 30 Polish wind and solar installations and a combined heat and power plant serving nearly half a million customers, using initial access gained through internet-exposed FortiGate VPN and firewall devices, several of them running without multi-factor authentication and with configurations that had previously leaked on criminal forums. CERT Polska’s three-month follow-up investigation, published this month, traces how the attacker used a Teltonika cellular router on the compromised wind farm’s network to tunnel into a private Access Point Name, an APN, operated by the regional distribution system operator. The APN was meant to isolate connected sites from one another. It did not. A misconfiguration let any device on the private network reach any other, and the attacker used that gap to scan for and find a second, unrelated facility entirely.
Default credentials on the web interface that mattered most
By December 18, the attacker had located a WAGO PFC200 programmable logic controller at the CHP plant with its web interface exposed on the APN and protected by nothing more than the factory-default administrator credentials. From there they switched off the steam turbine and the plant’s process-water treatment system, interrupting cogeneration, then reconfigured Moxa devices and wiped logs on the WAGO controller, the Teltonika router and the FortiGate firewall to slow forensic recovery. Plant staff restored operations quickly enough that the outage never reached the public, but the attacker’s ability to move from a wind farm’s VPN box to a second facility’s turbine controls, through infrastructure nobody was monitoring as an attack surface, is the part of this report that should change how OT teams think about their network boundaries.
Attribution to a known Russian state actor
CERT Polska attributes the campaign to Static Tundra, also tracked as Berserk Bear, a threat cluster assessed to be linked to Center 16 of Russia’s FSB. This is not an opportunistic ransomware crew testing default passwords at scale, it is a state actor treating private cellular infrastructure as a viable lateral movement path between otherwise unconnected energy sites, which raises the stakes for every operator using similar APN arrangements.
What CERT Polska is telling operators to do now
The agency’s central recommendation is blunt: stop treating private APNs and similar carrier-provided networks as inherently trusted just because they are not the public internet. It is calling on energy operators to audit private network configurations for exactly this kind of cross-device reachability, remove default credentials from every connected controller, and fold these networks into the same security testing programmes applied to internet-facing systems. CERT Polska also flagged a reporting gap under NIS2’s current scope, arguing that unexplained operational disruptions and near-misses need to be reportable, not only confirmed incidents, since this attack pattern was only fully understood by connecting signals across two separate sites.
If your organisation operates OT infrastructure over private cellular, leased, or carrier-managed networks and has never had them tested as an attack surface, or you need help mapping your NIS2 reporting obligations against what actually needs to be disclosed, contact Excello Digital. We help European critical infrastructure operators find the trust assumptions in their network architecture before a state-linked actor does.
