Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack

August 11, 2026

Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion.

The campaign moved from a wind-farm network into a heat and power plant, turning trusted connectivity into disruption.

The incident occurred on 29 December 2025, alongside coordinated destructive attacks against more than 30 renewable facilities.

At the plant, the intrusion stopped a steam turbine and water-treatment system, interrupting cogeneration, though heat and electricity supplies to roughly 50,000 residents continued.

CERT.PL analysts identified the route after a three-month investigation of an apparent maintenance error.

Their findings show the attacker did not need to expose the plant directly to the internet; instead, they crossed networks through a private mobile data environment used for operational communications.

A private APN in distributed energy resources (DERs) (Source - Cert.Pl)
A private APN in distributed energy resources (DERs) (Source – Cert.Pl)

The case echoes the coordinated Poland energy attacks, where disruption rather than data theft was the goal.

CERT.PL said in a report shared with Cyber Security News (CSN) that this shows how an apparently isolated connection creates risk when attached devices can talk freely.

Compromised FortiGate VPN

The attacker first gained access to a wind-farm perimeter device that combined firewall and VPN duties.

The internet-facing VPN lacked multi-factor authentication for locally defined accounts, and administrative control likely gave the intruder credentials for a VPN account able to reach every network segment.

The attacker then found a cellular router connected both to the wind farm and a private APN, a mobile network for the distribution system operator. Its web console and SSH service became the bridge into the APN.

Placement of the Cellular Router Within a Segment of the Wind (Source - Cert.Pl)
Placement of the Cellular Router Within a Segment of the Wind (Source – Cert.Pl)

The next target was a CHP controller, reachable through the APN. Its web administration interface used default credentials. After enabling SSH, the attacker created another tunnel into the operational technology network.

That chain is significant because private APNs are often treated as protected transport.

Here, a configuration allowed connections between arbitrary attached devices, effectively letting a breach at one site reach another.

Readers tracking FortiGate breach investigations will recognize the broader lesson: control of a perimeter appliance can expose far more than the appliance itself.

Reconnaissance Led to Process Disruption

Between 18 and 25 December, the intruder scanned for remote-control and industrial services, then explored the CHP network and attempted access to its firewall and remote desktop systems.

The activity included successful contact with three Siemens controllers before the final operation, indicating deliberate preparation rather than an opportunistic strike.

On the morning of 29 December, the actor reached the plant’s supervisory interface and then Siemens S7 controllers. The controllers entered STOP mode, shutting down the steam turbine and water-treatment system.

Attack Path from the Wind Farm to the Combined Heat and Power Plant (Source - Cert.Pl)
Attack Path from the Wind Farm to the Combined Heat and Power Plant (Source – Cert.Pl)

Staff restored factory settings and reloaded logic backups, limiting the outage, but that recovery also removed device logs needed for forensic review.

The attacker also reset serial-device servers and network switches, changed their passwords, and altered their network settings to slow restoration.

Activity continued for almost five hours after the plant began recovery. The gateway controller was then damaged, the cellular router reset, and the original perimeter device restored to factory settings, erasing valuable evidence.

The episode differs from the DynoWiper destructive malware activity reported elsewhere in the wider Polish campaign because this path focused on manipulating industrial devices directly.

It nevertheless reaches the same objective: interrupting essential operations while making recovery harder.

Attack against the CHP plant leveraging (Source - Cert.Pl)
Attack against the CHP plant leveraging (Source – Cert.Pl)

CERT.PL recommends auditing private-APN configurations, enabling client isolation, and treating the APN as untrusted when it enters an operational network.

Organizations should restrict connections with allowlists, segment the gateway from control systems, monitor unusual traffic, centralize gateway logs, remove exposed administration services, change default credentials, and include these links in penetration tests and architecture reviews.

Those controls should be independently tested regularly. The advice aligns with the need to protect exposed VPN access, but it also applies to every supposedly private route into industrial systems.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address 127.0.0.1 Unreachable address assigned to affected device interfaces during the attack, apparently to obstruct recovery and reconfiguration. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Original article can be found here