Zscaler Blog
Get the latest Zscaler blog updates in your inbox
Rethinking OT Boundaries: Sandworm's Cellular Breach of a Polish Power Plant
Executive Summary
Modern industrial operators are rapidly connecting remote infrastructure — wind turbines, solar arrays, water pumps, and distribution substations — using cellular networks, private APNs, and SD-WAN. Historically, these private cellular networks have been treated as trusted, secure, "walled-off" perimeters.
A Landmark Investigation disclosed by CERT Polska in August 2026 shattered this assumption. In a highly coordinated campaign, threat actors breached a combined heat and power (CHP) plant in Poland, successfully shutting down a steam turbine and its process-water treatment system.
This blog provides a highly technical analysis of this historic cyberattack, maps the step-by-step technical pathway of the pivot, explains why traditional cellular and SD-WAN setups create a catastrophic blast radius, and outlines how Zscaler's Zero Trust Exchange platform significantly mitigates these vectors.
The Incident — What Happened
The incident occurred on December 29, 2025, and was publicly disclosed after a comprehensive investigation on August 8, 2026. This was a highly targeted, state-sponsored campaign designed to impact physical operations. The attack began at an unmanned remote wind farm and ultimately resulted in the forced shutdown of a steam turbine at a central combined heat and power plant — a facility supplying municipal heat to 50,000 residents.
The attack chain followed a precise, multi-stage path: a remote wind farm firewall was compromised, granting the attackers footing on the facility's local network. From there, they accessed an on-site Teltonika cellular router via SSH, which opened a tunnel into the grid operator's private APN. Traversing that APN, they scanned the entire private cellular IP space and discovered a WAGO PLC at the CHP plant configured with default credentials. That PLC served as a bridge into the core OT network, and from there the attackers issued unauthorized stop commands to the Siemens PLCs controlling the steam turbine — achieving physical disruption.
Incident at a Glance
Metric / Aspect | Incident Details |
Target Facility | Combined Heat and Power (CHP) Plant (Poland) supplying municipal heat to 50,000 residents. |
Attribution | Sandworm (also known as the Russian state-sponsored threat group Electrum). |
Campaign Scope | Coordinated, simultaneous attacks targeting over 30 other Polish renewable energy and power distribution sites. |
Physical Impact | Complete temporary shutdown of a steam turbine and its process-water treatment system. |
Primary Vector | Lateral movement through a local grid operator's private cellular Access Point Name (APN). |
Anatomy of the Attack — Step by Step
The following table reconstructs the precise six-stage attack chain executed by Sandworm. Each step built directly on the last, exploiting a combination of internet-exposed management interfaces, flat private cellular network topology, and default device credentials to achieve full OT impact.
# | Attack Stage | Description |
1 | Initial Access | Sandworm exploited an internet-facing unpatched firewall at a remote, unmanned wind farm. |
2 | Device Control | The attackers accessed the wind farm's on-site Teltonika cellular router via Secure Shell (SSH). |
3 | APN Tunneling | Using the compromised router, the attackers established a tunnel into the grid operator's private APN. |
4 | Lateral Reconnaissance | Due to a lack of client isolation on the private APN, the attackers scanned the entire private cellular IP space. |
5 | PLC Exploitation | The scan discovered a WAGO PLC at the central CHP plant, which was exposed to the APN with default administrator credentials. |
6 | Operational Disruption | The attackers used the WAGO PLC as a network bridge to access the core OT network, issuing unauthorized stop commands to the Siemens PLCs controlling the steam turbine. |
Why Traditional Defenses Failed
This breach highlights a fundamental security misconception: the belief that carrier-provided private APNs or corporate SD-WAN networks provide a secure, isolated boundary. In reality, these technologies deliver connectivity and no security. Both APNs and SDWAN systems are built to connect devices. The moment a single endpoint on that shared network is compromised, the entire flat address space becomes an attacker's reconnaissance playground. The attacker leveraged the lack of controls on the APN to get into the flat network to pivot to the PLC. The following comparison maps the legacy assumptions that enabled this attack against the modern cyber reality — and demonstrates how Zscaler's Zero Trust paradigm would have eliminated the attack path entirely.
Attack Stage | Traditional Vulnerability | How Zscaler Eliminates The Threat |
Stage 1: Initial Perimeter Breach | Exposed public-facing IPs and open SSH management ports on cellular gateways are easily scanned and targeted by brute-force attacks. | Zero Public Attack Surface: Zscaler Cellular makes all remote gateways completely invisible to the internet. Outbound-only connections to the Zscaler Zero Trust Exchange mean there are zero public-facing IPs or open inbound ports to scan. |
Stage 2: Lateral APN Reconnaissance | A flat APN permits any compromised cellular device to discover, ping, and compromise other remote terminals and power plants. | Total Peer Isolation: Zscaler prevents device-to-device visibility on the cellular network. Connected devices can only communicate outbound to the Zscaler broker, completely blocking attackers from scanning the APN. |
Stage 3: Credential Exploitation | Exposed local administrative portals are highly vulnerable to default credential harvesting and unauthorized access. | Identity-Centric Access Proxy: Zscaler acts as a secure identity broker. Even if an attacker physically accesses the local APN, they cannot see or communicate with the WAGO PLC's login portal without first passing MFA-backed identity policies. |
Stage 4: Core Network Bridging | Flat internal routing allows a compromised edge controller to act as a bridge into the plant's core OT control network. | Agentless Device Segmentation: Zscaler isolates legacy assets at the application layer without requiring software agents on the PLCs. It blocks lateral traffic between the edge PLC and the core OT network, restricting communications to pre-approved paths. |
Stage 5: Industrial Disruption | Plain-text industrial protocols (like Modbus or S7comm) lack cryptographic authentication, enabling unauthorized physical stop commands. | Ransomware Kill Switch & Protocol Isolation: Administrators can instantly trigger a global isolation protocol to quarantine compromised zones. Zscaler also enforces granular protocol-level access without deploying any agents. Read More |
The Zscaler Solution
To comprehend how Zscaler secures OT environments, we must first examine the core principles of the Zero Trust Security Model . Traditional network security relies on a "castle-and-moat" design, where perimeter firewalls secure the border, but everything inside is implicitly trusted. Once an intruder like Sandworm breaches the outer defense (the moat), they enjoy free lateral movement across the flat interior (the castle)
Securing distributed OT infrastructure requires moving from a network-centric approach to an application-centric Zero Trust architecture. Zscaler delivers native security capabilities designed to eliminate the exact attack path used by Sandworm. Each capability below maps directly to a stage of the incident, removing the preconditions the threat actors depended on at every step of the kill chain.

Zscaler Security Capability | Technical Function | Industrial Value |
Zscaler Cellular | Secures both inbound and outbound cellular communications. Devices do not have public IPs or open listening ports. | Hides the Attack Surface: Eliminates the ability for threat actors to scan the cellular network or discover exposed remote terminals. |
Zscaler Zero Trust Device Segmentation | Implements agentless, identity-based micro-segmentation for legacy PLCs and RTUs without requiring software on the endpoints. | Inhibits Lateral Movement: Even if a remote router is compromised, Zscaler blocks it from communicating with the central plant's controllers. |
Ransomware Kill Switch | Allows administrators to instantly sever all lateral network connections with a single command during an active incident. | Grid Protection: Limits the blast radius of a breach to a single segment, keeping the broader municipal utility online. |
Protect Your OT Infrastructure Today Zscaler Zero Trust Exchange™ eliminates lateral movement, hides your OT assets from attackers, and gives you instant incident response — all without disrupting operations. → Learn more at https://resources/security-terms-glossary/what-is-operational-technology-ot-security /products-and-solutions/zscaler-cellular Act Fast. Stay Secure. |
Was this post useful?
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.
Get the latest Zscaler blog updates in your inbox
By submitting the form, you are agreeing to our privacy policy.



