# A Polish Power Plant Got Hit Through the "Secure" Network — and That's the Real Warning
The attack on a Polish combined heat and power plant last week didn't come through a phishing email, a misconfigured firewall, or a public-facing VPN with a weak password. It came through the private cellular network — the out-of-band channel the local grid operator uses to reach remote equipment precisely because it's supposed to be harder to breach than the open internet.
Attackers shut down a steam turbine and the facility's process-water treatment system. The plant serves heat to roughly 50,000 residents. Recovery operations were underway by 7:30 a.m. — while the intruders were still active inside the network.
That last detail deserves to sit with you for a moment.
## The Cellular Channel Was the Trust Boundary — Until It Wasn't
Private LTE and 4G networks have become standard infrastructure for energy utilities across Europe and North America. The pitch is intuitive: instead of routing SCADA traffic over the public internet or aging, expensive licensed radio systems, operators build their own cellular fabric. They control who's on it, what devices can connect, and how the traffic flows. No shared spectrum. No public endpoints. The implicit promise is isolation.
What this incident makes clear is that "private" and "secure" have been quietly conflated in ICS planning for years.
Private cellular networks still have attack surfaces. Network management consoles, SIM provisioning systems, base station firmware, and the devices that authenticate onto the network all represent potential entry points. If an attacker can register a rogue device, intercept an authentication handshake, or compromise the management layer of the cellular infrastructure itself, the traffic riding that network is no longer private in any meaningful sense.
The specific method used in the Polish attack hasn't been publicly confirmed yet. But the logical candidates are familiar to anyone who works in telecom security: compromised management credentials, a vulnerable base station controller, or a supply-chain issue with a device authorized to operate on the network. Any of these would give an attacker legitimate-looking network presence, which is exactly why detection was apparently slow enough for them to reach the turbine controls.
## District Heat Is Not Optional in Poland in Winter
Context that tends to get lost in English-language cybersecurity reporting: Polish district heating systems are not supplementary. In a country where 40 percent of the population lives in apartment buildings served by centralized heat networks, a plant disruption in the heating season is a public health emergency, not an inconvenience.
The 50,000 residents served by this plant were lucky. The attack apparently didn't hold long enough to deprive them of heat. But the calculus changes fast. Equipment that trips unexpectedly — especially steam turbines and process-water systems — doesn't restart at the push of a button. Turbines require careful cool-down and inspection cycles. Process-water systems serving heat exchangers have pressure and temperature protocols that must be followed to restart safely. The attackers understood enough about what they were shutting down to maximize disruption potential, even if they didn't fully capitalize on it.
That operational knowledge is a fingerprint worth tracking. Shutting down both the primary generation equipment and the water treatment system simultaneously isn't random vandalism — it's a layered approach designed to complicate recovery.
## Recovery Under Fire
The detail that defenders in critical infrastructure should study most carefully: engineers were working to restore systems at 7:30 a.m. while the threat actors were still inside the network.
This is a contested recovery scenario, and it's genuinely difficult. In a conventional IT incident, you isolate the compromised segment, rebuild from known-good state, and restore. When the attacker is still present, every recovery step is a potential target. They can observe what you're doing and attempt to interfere again. They can watch for the moment your defenses are partially down during restoration and hit something else.
Most OT incident response playbooks are built around post-intrusion recovery — after the attacker is evicted. The Polish case is a reminder that "evict first, recover second" isn't always achievable, and teams need to have thought through what contested restoration looks like before they're doing it in an actual emergency.
## The Broader Pattern: OT Attackers Are Getting Smarter About Entry Points
The progression of ICS attacks over the past decade follows a recognizable arc. The 2015 and 2016 Ukraine power grid attacks demonstrated that attackers could cross from IT networks into OT environments. Colonial Pipeline in 2021 showed how ransomware on the business-IT side could force operators to voluntarily take OT offline. The Oldsmar water treatment intrusion exposed just how badly remote-access tools were managed at smaller utilities.
The Polish attack represents something slightly different: an attack that came through infrastructure the operators believed was specifically more secure than the alternatives. That's a more sophisticated adversary play. It targets the assumptions built into the security architecture rather than the vulnerabilities in it.
This matters because it suggests the attacker community has done reconnaissance not just on the target's systems but on its trust model. They knew the cellular network was the preferred OT communication path. They went there on purpose.
---
## HackWire Analysis
The cybersecurity conversation around OT and industrial control systems has made real progress in the last five years — but it has lagged badly on private cellular networks as an attack surface.
The energy sector's adoption of private LTE for operational communications accelerated sharply after 2018, driven partly by cost, partly by reliability needs, and partly by genuine security concerns about legacy radio systems. Security teams who flagged the risks often got a simple response: it's private, it's not on the internet, it's fine.
What's missing from most OT security frameworks right now is rigorous treatment of the cellular management plane as an attack surface equivalent to traditional network infrastructure. Base station controllers, SIM lifecycle management systems, and device authentication records don't typically appear in OT asset inventories. They're not scanned. They're often managed by a telecom vendor under a contract that predates current threat models.
The Polish incident should be a forcing function for utilities to answer some uncomfortable questions: Who has administrative access to your private cellular infrastructure? When was the management console last audited? What would you detect if a device that shouldn't be there started authenticating onto your OT cellular network?
The answers at most utilities are not great.
There's also a policy dimension that's being ignored. The EU's NIS2 directive, which came into full force in October 2024, extends cybersecurity obligations to energy sector operators — but its guidance on operational technology networks lags its treatment of IT systems. Private cellular networks occupy an ambiguous space between traditional OT security standards and telecom regulatory frameworks, and that ambiguity is where attackers operate.
For defenders: this is the moment to treat your private cellular network like it's internet-adjacent. Because to a motivated attacker who's done the reconnaissance, it effectively is.
— HackWire Editorial
---
## Related Coverage