Here's what happened: Investigators documented a cyberattack against a Polish power plant where threat actors gained initial access through a private cellular network (APN). According to the incident details, the attackers exploited two critical weaknesses: the network lacked client isolation, and a WAGO industrial controller was running default administrator credentials. From there, the attackers pivoted laterally into the plant's operational technology (OT) network, ultimately reaching SCADA systems and Siemens programmable logic controllers (PLCs).
Why this matters: This attack signals a gap in how critical infrastructure operators are treating cellular networks. Private APNs have traditionally been viewed as inherently secure because they're closed systems. This breach suggests that assumption is dangerous. The attack chain—default credentials, lack of network segmentation, lateral movement into OT—follows a pattern seen in previous industrial incidents, but the cellular entry vector is the new variable. CERT Polska's assessment that this is the first known real-world example of OT network compromise via private APN suggests others may not yet recognize the risk.
The implications extend beyond this single facility. Industrial sites increasingly rely on cellular networks for remote access, diagnostics, and coordination. If private APNs can be penetrated without robust internal network isolation, any facility using similar architecture faces comparable exposure.
What to watch: Monitor whether security advisories from CISA, Siemens, or WAGO follow this disclosure. Watch for indicators that other operators are auditing default credentials on industrial controllers and implementing proper network segmentation. The absence of urgent guidance or patches could suggest this attack surface remains widely unaddressed.
This is a maturation moment for industrial cyber threat actors—they've demonstrated they can move from IT infrastructure into OT systems using a pathway many operators haven't hardened. The real risk isn't this one plant; it's the dozens or hundreds of similar architectures still running with the same vulnerabilities.

