Hackers breach a combined heat and power (CHP) plant in Poland, which provides heat to about 50,000 residents, by gaining access to its operational technology (OT) network. CERT Polska reports the attack occurred on December 29, and the incident is described as a first observed case involving a private mobile network entry path into an OT environment.

Both outlets say the attackers used a private APN (Access Point Name) as the entry vector. A private APN is a dedicated mobile connectivity setup between a distribution system operator (DSO) and a mobile carrier, arranged by the operator running the local electricity grid. Help Net Security characterizes this as a previously unseen method, while Bleeping Computer focuses on the mechanism of how the private APN enables OT network access. The reporting centers on the entry technique rather than on broader impacts beyond the plant’s service area.

Together, the articles emphasize that the private APN link is the notable factor in the intrusion path. They attribute the assessment of novelty to CERT Polska and frame the event as an example of how mobile network arrangements can be leveraged to reach OT systems.