Summary Points
- Attackers exploited a private cellular network’s configuration, using default credentials and unsegregated client-to-client traffic, to pivot from wind farm to power plant control systems.
- The intrusion involved SSH tunneling through a compromised router, enabling access to critical industrial controllers and facilitating shutdown and damage to plant equipment.
- The attack resulted in the shutdown of key turbines and water systems, factory resets of critical network devices, and loss of logs, highlighting vulnerabilities in OT network segmentation and device security.
Threat, Attack Techniques, and Targets
The incident involved hackers breaching a Polish power plant’s control system through a private cellular network. They shut down a steam turbine and water treatment system. The attackers used a private APN managed by the distribution system operator, which allowed devices on the same network to communicate. This setup enabled the hackers to move from a wind farm network to the power plant’s controller. The attack originated at a wind farm, where the attacker gained access via an unprotected VPN and exploited weak or default credentials. They used SSH tunneling through a Teltonika router that still had default admin credentials. Once inside, they accessed a WAGO controller with default credentials, then moved into the plant’s operational technology (OT) network. During the attack, the hackers switched Siemens controllers to STOP mode, shutting down critical equipment. They also factory-reset devices, removed logs, and caused significant disruption.
Impact, Security Implications, and Remediation Guidance
The attack interrupted power and water treatment processes but did not cause outages for customers. It reveals serious security flaws in private cellular networks, especially when devices have default credentials and client-to-client traffic is allowed. Many organizations may use similar network configurations without enough security measures. The incident highlights how attackers can exploit private APNs for unauthorized access. For remediation, organizations should audit their private APN settings and enable client isolation. They should also segment networks, restrict traffic flows, remove unnecessary management interfaces, and change default credentials. As detailed guidance may vary, organizations are advised to consult their respective vendors or security authorities to implement proper security controls and monitor network activity.
Stay Ahead with the Latest Tech Trends
Explore the future of technology with our detailed insights on Artificial Intelligence.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
