Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Products & Solutions

Rethinking OT Boundaries: Sandworm's Cellular Breach of a Polish Power Plant

image

Executive Summary

Modern industrial operators are rapidly connecting remote infrastructure — wind turbines, solar arrays, water pumps, and distribution substations — using cellular networks, private APNs, and SD-WAN. Historically, these private cellular networks have been treated as trusted, secure, "walled-off" perimeters.

Landmark Investigation disclosed by CERT Polska in August 2026 shattered this assumption. In a highly coordinated campaign, threat actors breached a combined heat and power (CHP) plant in Poland, successfully shutting down a steam turbine and its process-water treatment system.

This blog provides a highly technical analysis of this historic cyberattack, maps the step-by-step technical pathway of the pivot, explains why traditional cellular and SD-WAN setups create a catastrophic blast radius, and outlines how Zscaler's Zero Trust Exchange platform significantly mitigates these vectors.

The Incident — What Happened

The incident occurred on December 29, 2025, and was publicly disclosed after a comprehensive investigation on August 8, 2026. This was a highly targeted, state-sponsored campaign designed to impact physical operations. The attack began at an unmanned remote wind farm and ultimately resulted in the forced shutdown of a steam turbine at a central combined heat and power plant — a facility supplying municipal heat to 50,000 residents.

The attack chain followed a precise, multi-stage path: a remote wind farm firewall was compromised, granting the attackers footing on the facility's local network. From there, they accessed an on-site Teltonika cellular router via SSH, which opened a tunnel into the grid operator's private APN. Traversing that APN, they scanned the entire private cellular IP space and discovered a WAGO PLC at the CHP plant configured with default credentials. That PLC served as a bridge into the core OT network, and from there the attackers issued unauthorized stop commands to the Siemens PLCs controlling the steam turbine — achieving physical disruption.

Incident at a Glance

Metric / Aspect

Incident Details

Target Facility

Combined Heat and Power (CHP) Plant (Poland) supplying municipal heat to 50,000 residents.

Attribution

Sandworm (also known as the Russian state-sponsored threat group Electrum).

Campaign Scope

Coordinated, simultaneous attacks targeting over 30 other Polish renewable energy and power distribution sites.

Physical Impact

Complete temporary shutdown of a steam turbine and its process-water treatment system.

Primary Vector

Lateral movement through a local grid operator's private cellular Access Point Name (APN).

Anatomy of the Attack — Step by Step

The following table reconstructs the precise six-stage attack chain executed by Sandworm. Each step built directly on the last, exploiting a combination of internet-exposed management interfaces, flat private cellular network topology, and default device credentials to achieve full OT impact.

#

Attack Stage

Description

1

Initial Access

Sandworm exploited an internet-facing unpatched firewall at a remote, unmanned wind farm.

2

Device Control

The attackers accessed the wind farm's on-site Teltonika cellular router via Secure Shell (SSH).

3

APN Tunneling

Using the compromised router, the attackers established a tunnel into the grid operator's private APN.

4

Lateral Reconnaissance

Due to a lack of client isolation on the private APN, the attackers scanned the entire private cellular IP space.

5

PLC Exploitation

The scan discovered a WAGO PLC at the central CHP plant, which was exposed to the APN with default administrator credentials.

6

Operational Disruption

The attackers used the WAGO PLC as a network bridge to access the core OT network, issuing unauthorized stop commands to the Siemens PLCs controlling the steam turbine.

 

Why Traditional Defenses Failed

This breach highlights a fundamental security misconception: the belief that carrier-provided private APNs or corporate SD-WAN networks provide a secure, isolated boundary. In reality, these technologies deliver connectivity and no security. Both APNs and SDWAN systems are built to connect devices. The moment a single endpoint on that shared network is compromised, the entire flat address space becomes an attacker's reconnaissance playground. The attacker leveraged the lack of controls on the APN to get into the flat network to pivot to the PLC. The following comparison maps the legacy assumptions that enabled this attack against the modern cyber reality — and demonstrates how Zscaler's Zero Trust paradigm would have eliminated the attack path entirely.

Attack Stage

Traditional Vulnerability

How Zscaler Eliminates The Threat

Stage 1: Initial Perimeter Breach
(Exploited Remote Firewall)

Exposed public-facing IPs and open SSH management ports on cellular gateways are easily scanned and targeted by brute-force attacks.

Zero Public Attack Surface: Zscaler Cellular makes all remote gateways completely invisible to the internet. Outbound-only connections to the Zscaler Zero Trust Exchange mean there are zero public-facing IPs or open inbound ports to scan.

Stage 2: Lateral APN Reconnaissance
(Scanned Private Cellular Grid)

A flat APN permits any compromised cellular device to discover, ping, and compromise other remote terminals and power plants.

Total Peer Isolation: Zscaler prevents device-to-device visibility on the cellular network. Connected devices can only communicate outbound to the Zscaler broker, completely blocking attackers from scanning the APN.

Stage 3: Credential Exploitation
(Brute-forced WAGO PLC)

Exposed local administrative portals are highly vulnerable to default credential harvesting and unauthorized access.

Identity-Centric Access Proxy: Zscaler acts as a secure identity broker. Even if an attacker physically accesses the local APN, they cannot see or communicate with the WAGO PLC's login portal without first passing MFA-backed identity policies.

Stage 4: Core Network Bridging
(Pivoted from PLC to Turbine)

Flat internal routing allows a compromised edge controller to act as a bridge into the plant's core OT control network.

Agentless Device Segmentation: Zscaler isolates legacy assets at the application layer without requiring software agents on the PLCs. It blocks lateral traffic between the edge PLC and the core OT network, restricting communications to pre-approved paths.

Stage 5: Industrial Disruption
(Issued Stop Commands to Siemens PLCs)

Plain-text industrial protocols (like Modbus or S7comm) lack cryptographic authentication, enabling unauthorized physical stop commands.

Ransomware Kill Switch & Protocol Isolation: Administrators can instantly trigger a global isolation protocol to quarantine compromised zones. Zscaler also enforces granular protocol-level access without deploying any agents. Read More 

The Zscaler Solution

To comprehend how Zscaler secures OT environments, we must first examine the core principles of the Zero Trust Security Model . Traditional network security relies on a "castle-and-moat" design, where perimeter firewalls secure the border, but everything inside is implicitly trusted. Once an intruder like Sandworm breaches the outer defense (the moat), they enjoy free lateral movement across the flat interior (the castle)

Securing distributed OT infrastructure requires moving from a network-centric approach to an application-centric Zero Trust architecture. Zscaler delivers native security capabilities designed to eliminate the exact attack path used by Sandworm. Each capability below maps directly to a stage of the incident, removing the preconditions the threat actors depended on at every step of the kill chain.

Zscaler Cellular Services

 

 

Zscaler Security Capability

Technical Function

Industrial Value

Zscaler Cellular

Secures both inbound and outbound cellular communications. Devices do not have public IPs or open listening ports.

Hides the Attack Surface: Eliminates the ability for threat actors to scan the cellular network or discover exposed remote terminals.

Zscaler Zero Trust Device Segmentation

Implements agentless, identity-based micro-segmentation for legacy PLCs and RTUs without requiring software on the endpoints.

Inhibits Lateral Movement: Even if a remote router is compromised, Zscaler blocks it from communicating with the central plant's controllers.

Ransomware Kill Switch

Allows administrators to instantly sever all lateral network connections with a single command during an active incident.

Grid Protection: Limits the blast radius of a breach to a single segment, keeping the broader municipal utility online.

Protect Your OT Infrastructure Today

Zscaler Zero Trust Exchange™ eliminates lateral movement, hides your OT assets from attackers, and gives you instant incident response — all without disrupting operations.

→  Learn more at https://resources/security-terms-glossary/what-is-operational-technology-ot-security

/products-and-solutions/zscaler-cellular 

Act Fast. Stay Secure.

 

form submtited
Gracias por leer

¿Este post ha sido útil?

Exención de responsabilidad: Este blog post ha sido creado por Zscaler con fines informativos exclusivamente y se ofrece "como es" sin ninguna garantía de precisión, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por errores u omisiones ni por las acciones que se tomen basándose en la información proporcionada. Cualquier sitio web o recurso de terceros enlazado en esta publicación de blog se proporciona únicamente por conveniencia, y Zscaler no se hace responsable de su contenido ni de sus prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, acepta estos términos y reconoce ser el único responsable de verificar y utilizar la información de manera adecuada según sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.