Utilities embrace private networks. Attackers are embracing them too.

  • CERT Polska's investigation of a December 2025 energy-sector attack identified a previously unobserved attack path involving a private APN network
  • Recent attacks on U.S. water systems have also targeted operational technology and programmable logic controllers (PLCs), forcing some utilities into manual operations
  • As utilities deploy more private LTE, private 5G and industrial IoT infrastructure, networking architecture itself is becoming part of the critical infrastructure attack surface

As utilities invest in digital transformation, private wireless networks have become an increasingly important part of how critical infrastructure is monitored and managed. A new analysis of a December 2025 attack on Poland's energy sector suggests those same connectivity technologies deserve greater attention from operators.

In a follow-up report published this month, CERT Polska detailed an attack that occurred alongside the broader campaign against Poland's energy infrastructure on December 29, 2025. The incident targeted a combined heat-and-power plant serving roughly 50,000 residents and resulted in the shutdown of a steam turbine and water treatment systems used in the cogeneration process. Plant operators were able to restore operations quickly, avoiding broader disruption, according to the CERT report.

What makes the case notable is what investigators learned afterward. According to CERT Polska, attackers gained access through a private APN (Access Point Name) environment, allowing them to reach operational technology systems. The report said a Teltonika RUTX50 router was used at the compromised facility.

The agency said the attack was enabled in part by a misconfiguration that allowed devices within the private APN network to communicate with one another, a setup investigators said appears to be common in Poland and elsewhere.

“The attacker logged into the router multiple times via SSH during December 2025,” the report stated. “Based on logs obtained from the mobile network operator, it was determined that the attacker most likely used SSH tunneling to gain access to the private APN network.” 

CERT Polska described the use of a private APN as a previously unobserved attack vector in a real-world incident. Rather than focusing solely on industrial equipment, the attackers were able to exploit the connectivity architecture supporting remote operations and monitoring.

Marcin Dudek, head of CERT Polska, presented the details of this incident at DEF CON in Las Vegas last week.

Attacks on US water and wastewater infrastructure

The CERT report arrives as utilities in the United States grapple with attacks targeting operational technology systems. The U.S. Environmental Protection Agency recently warned that threat actors were targeting PLCs and other operational technology (OT) components in water and wastewater infrastructure. In several cases, utilities shifted to manual operations after losing access to automated systems, while investigators examined whether some incidents were linked to Iranian threat actors

Some affected U.S. operators reportedly disconnected cellular-connected PLCs from their networks as a defensive measure while keeping services running through manual procedures, according to a July 29, 2026, article in Tech Times.

The lesson from both cases is that connectivity itself is becoming part of critical infrastructure. As utilities deploy more private LTE, private 5G and industrial IoT technologies, securing the links between operational systems may be just as important as securing the systems themselves.