NETSCOUT: Cyberattack in Poland Cuts Heat for 50,000
News | 27.08.2026
A cyberattack on a Polish combined heat and power plant disrupted heat and electricity for 50,000 residents — and stayed hidden for three months because operators could not see what was happening inside their own networks.
Poland's CERT recently published a follow-up report on a cyberattack that shut down a steam turbine and water treatment system at a combined heat and power plant serving 50,000 people. For months, nobody knew it was an attack. The shutdown happened during Christmas maintenance, operators assumed a contractor error, and the incident was filed for informational purposes only. It took a three-month investigation, prompted by the coincidence that more than 30 other energy sites were hit the same day, to establish what had actually happened.
The investigators found an attack that crossed three networks, spent 11 days in reconnaissance, and left visible traces in all of them — traces that were never observed because no one was watching internal, cellular, or OT traffic with the same discipline applied to the perimeter.
What was announced
According to the CERT report, attackers entered through firewalls at wind farm substations they had already compromised and pivoted to a cellular router on a private mobile data network. Distributed energy sites use these networks to communicate with grid operators, and the industry has long treated them as walled-off and inherently safe. In reality, any device on the network could talk to any other device, so a foothold at a wind farm gave the attackers a direct path to a heat plant with no business relationship to it.
Once inside, the attackers had 11 days before doing anything destructive. They probed industrial equipment, tested credentials against the plant's firewall, and connected to controllers on Christmas Day to map their targets. Before dawn on December 29, they disabled the Siemens controllers and locked operators out with new passwords. They also wiped device configurations and corrupted the gateway they had used so badly it could not be repaired.
Why this matters
For CISOs, CIOs, and OT security leaders, this incident illustrates three uncomfortable realities. First, private cellular networks used by distributed energy sites are not inherently trusted zones — they are flat networks where one compromised device reaches everything else. Second, perimeter tooling is not built to question traffic that originates inside, which is why lateral movement so often goes undetected until damage is done. Third, without packet-level evidence, forensic reconstruction depends on luck.
The plant staff read the turbine trip as human error because nothing in their visibility told them otherwise. A router at one facility opening a session to a controller at another is not subtle — it is a communication pattern that had never existed before. Watching that cellular network the way you would watch anything internet-facing turns the first hop into an alert rather than a footnote discovered months later.
Technical details
- Attack duration: 11 days of reconnaissance before destructive action.
- Entry vector: compromised firewalls at wind farm substations, pivot through a shared private cellular data network.
- Impact: Siemens controllers disabled, operators locked out with new passwords, steam turbine and water treatment shut down.
- Evidence destruction: device configurations wiped, gateway corrupted beyond repair.
- Detection gap: incident misclassified as contractor error for three months.
- NETSCOUT Omnis Cyber Intelligence: continuous packet-level visibility across cellular, OT, and east-west traffic with deep packet inspection of industrial protocols and behavioral baselining of peer relationships.
Softprom and NETSCOUT
Softprom is the official distributor of NETSCOUT. Organizations operating critical infrastructure, distributed energy assets, or complex OT environments can access NETSCOUT Omnis Cyber Intelligence and network visibility solutions through Softprom's engineering and consulting teams.
Discover how Omnis Cyber Intelligence delivers packet-level visibility across OT, cellular, and internal traffic — request a consultation with NETSCOUT experts at Softprom.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.