Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by gaining access through the private LTE/5G cellular network that the local grid operator uses for remote equipment control — marking a first-of-kind confirmed breach of industrial controls through telecommunications infrastructure rather than traditional attack vectors like VPN, email, or perimeter firewall exploitation.
How Cellular ICS Networks Became the Attack Vector
The plant supplies heat to roughly 50,000 residents; recovery began at approximately 7:30 a.m. while intruders were still active inside the network. Customers lost neither heat nor hot water, indicating that automated emergency failover systems functioned correctly and prevented civilian infrastructure disruption despite confirmed hostile access to industrial control equipment. The cellular network itself was the attack vector — an attacker using the telecommunications infrastructure of an industrial cellular network to reach SCADA systems rather than traditional methods like VPN, email, or perimeter firewall exploitation.
Polish Utility Cellular Infrastructure Expands the ICS Attack Surface
This represents a significant escalation in attack surface for critical infrastructure: the industrial cellular networks that utilities use to manage remote substations, pumps, and valves can now be used by attackers as an alternative to traditional network access, effectively creating a back door through the cellular carrier itself. A successful breach of cellular ICS systems would affect thousands of utility operators whose communications channels are accessible from any LTE-capable location without traversing perimeter defense systems.
Forensic Investigation Scope and Sector-Wide Implications
Recovery initiated while threat actors remained inside the network means forensic investigators must determine the full scope of data access, potential persistence mechanisms, and whether cellular-based access created undetectable lateral movement paths through infrastructure that traditional endpoint monitoring approaches may not have covered. Poland has no publicly disclosed history of this specific attack method in its critical infrastructure sector, making the incident particularly noteworthy for EU-wide utility operators who monitor their own cellular ICS network exposure since no similar European precedent exists.
Critical infrastructure operators worldwide should audit their cellular ICS networks for unauthorized SIM cards and IoT devices registered to corporate cellular infrastructure, review MFA implementation on all cellular-based remote access systems, and ensure cellular VPN connections use mutual authentication rather than one-way device-to-network verification — each of which addresses directly the attack vector exploited in the Polish power plant incident before investigators can determine whether additional undetected cellular ICS compromises exist across their broader energy distribution networks.
