# Poland's Heat Plant Hack Reveals the Cellular Blind Spot in OT Security
Last winter, while 50,000 residents in a Polish city relied on a combined heat-and-power plant to keep their homes warm, someone was already inside its operational network. Not through a phishing email. Not through an unpatched VPN appliance. Through a private APN — the kind of cellular gateway that operators deploy precisely because they believe it creates a walled garden.
They were wrong.
The breach, which occurred in 2024 and has only recently surfaced in detail, is a textbook case study in a threat vector that the OT security community discusses too infrequently: the cellular underbelly of industrial infrastructure. The attackers didn't need to overcome a firewall. They found a door that operators assumed was invisible.
## What a Private APN Actually Is — and Why It Isn't Safe
An Access Point Name is the gateway label that tells a cellular device which network path to route its traffic through. Private APNs are marketed to enterprises as a way to keep IoT and OT devices on a logically separate, "air-gapped-adjacent" cellular segment that doesn't touch the public internet. The pitch is compelling: your SCADA sensors, your remote terminal units, your plant monitoring equipment — all talking over cellular without commingling with the open web.
The problem is that "private" doesn't mean "unbreachable." It means the path is controlled by your mobile carrier and your corporate configuration, both of which can be misconfigured, compromised, or exploited. Attackers who gain access to a device on that APN — through a SIM swap, a compromised endpoint, or lateral movement from an IT network with a bridge to the APN — can reach everything that trusts the cellular segment.
In the Polish plant's case, the attackers used APN access to pivot directly into the OT network. The OT side, like most operational environments built before IT/OT convergence became an industry concern, was designed for availability and reliability — not for adversarial resilience. Devices on these networks often lack authentication, run legacy firmware, and assume that anything on the network belongs there.
That assumption is lethal when the perimeter fails.
## Critical Infrastructure, Comfortable Assumptions
Energy plants that supply district heating operate under a constraint most enterprise IT shops don't face: downtime directly translates to human suffering. In sub-zero temperatures, losing heat distribution isn't a service interruption — it's a public health emergency. That reality shapes how operators think about their networks, and not always in a security-forward way.
Operational continuity pressure discourages patching, network segmentation, and monitoring changes that might introduce instability. The result is OT environments where PLCs and RTUs run unchanged for years, remote access pathways accumulate without sunset dates, and cellular modems are installed to enable remote diagnostics — then forgotten by security teams who weren't told they existed.
Private APNs fit this pattern perfectly. They're often deployed by telecom vendors, integrated by OT system integrators, and managed by operations staff who have no visibility into the threat model. The IT security team frequently doesn't know the APN exists. The OT team assumes the carrier handles security. The carrier assumes the customer has segmented the network properly.
Everyone assumes. Nobody verifies.
## The Geopolitical Context Nobody Is Saying Out Loud
This incident didn't happen in a vacuum. Poland's energy infrastructure has been under sustained pressure since 2022, when the scope of state-sponsored attacks on European critical infrastructure expanded dramatically. Polish government agencies, rail networks, and energy operators have all been targeted in the years since, with attribution ranging from Russian GRU-affiliated actors to hacktivists operating as cover for state objectives.
The timing and target profile of this plant — a district heating facility, not a headline-grabbing power grid — is consistent with a pattern of "threshold" attacks: intrusions designed to map infrastructure, establish persistence, or demonstrate capability without triggering immediate escalation. District heating systems are particularly attractive because their failure is slow, distributed, and deniable. No dramatic blackout. Just a lot of people who are cold, and a plant scrambling to understand what happened.
Whether this specific attack was state-sponsored, financially motivated, or opportunistic reconnaissance hasn't been confirmed publicly. But the victim profile fits a documented campaign pattern, and defenders in the European energy sector would be wrong to treat it as an isolated incident.
## For Defenders: The Cellular Audit Nobody Has Done
The immediate takeaway for OT security teams isn't abstract. It's a question: do you have a complete inventory of every cellular-connected device in your operational environment, and do you know which APN each one uses?
Most organizations don't. The cellular footprint of industrial facilities has grown quietly, driven by convenience — remote meter reading, equipment telemetry, environmental monitoring — without corresponding growth in visibility. A credible response to the Polish incident involves:
Enumerate first. Work with your mobile carriers to pull a full list of SIMs registered to your organization. Cross-reference against your asset inventory. The gap between those two lists is your exposure.
Treat APN access like VPN access. Any device that can reach your OT network over cellular should require authentication, have its traffic monitored, and be subject to the same change-control process as a VPN endpoint. "It's a private APN" is not a substitute for zero-trust controls.
Segment aggressively within OT. Even if an attacker gains cellular access, micro-segmentation within the OT network limits lateral movement. A compromised building management sensor shouldn't be able to reach a turbine control system.
Log cellular traffic. Many private APN deployments have no logging at the network layer. If you can't see the traffic, you can't detect the intrusion.
The Polish plant discovered the breach — which means their monitoring caught something, eventually. Most OT environments wouldn't be that lucky.
---
## HackWire Analysis
The Polish APN breach matters because it breaks a comfortable assumption at exactly the wrong moment. European critical infrastructure operators spent the last two years hardening the vectors they knew about — corporate VPNs, remote desktop exposure, internet-facing HMIs — while cellular connectivity grew into a significant blind spot.
Private APNs occupy a trust position in the OT architecture diagram that they haven't earned. They're treated as equivalent to a dedicated physical network, but they share the fundamental vulnerability of any connectivity layer: if you can get a foothold on one authorized device, the "private" label stops protecting you.
What's missing from most coverage of this incident is the supply chain dimension. The cellular modems and IoT gateways that enable APN access are often sourced from third-party vendors, configured by integrators, and then handed off to operators who lack the tooling to audit them. That's a privileged access pathway with no lifecycle management — exactly the kind of oversight gap that well-resourced attackers probe for.
The broader pattern here is one we've tracked across dozens of OT incidents: the attack surface expands through convenience additions that nobody treats as security decisions. Remote diagnostics ports, vendor maintenance tunnels, cellular telemetry — all installed because they make operations easier, none of them subject to the scrutiny of a new firewall rule. Until defenders apply the same rigor to "operational convenience" connections that they apply to perimeter infrastructure, incidents like this Polish plant will keep happening. The attackers have already figured out where defenders aren't looking.
— HackWire Editorial
---
## Related Coverage