Cyberattack in Poland Causes Heat and Power Outages for 50,000 Residents

Smarter visibility and detection could have overcome operational shortcomings.

Electrical Utility Worker Standing in Front of Power Lines

Poland’s computer emergency response team (CERT) recently published a follow-up report on a cyberattack that shut down a steam turbine and water treatment system at a combined heat and power plant serving 50,000 people. For months, nobody knew it was an attack. The shutdown happened during Christmas maintenance, operators assumed a contractor had made a mistake, and the incident was filed for informational purposes only. It took a three-month investigation, prompted by the coincidence that more than 30 other energy sites were hit the same day, to establish what had actually happened.

What the investigators found was an attack that crossed three networks, spent 11 days in reconnaissance, and left visible traces in all of them.

The Cellular Network

The attackers came in through firewalls at wind farm substations they had already compromised and then reached a cellular router sitting on a private mobile data network. Distributed energy sites use these networks to talk to grid operators, and the industry has long treated them as walled-off and inherently safe. This one let any device on it talk to any other device, which meant a foothold at a wind farm gave the attackers a path to a heat plant that had no business relationship with it whatsoever.

A router at one facility opening a session to a controller at another is not subtle. It is a communication pattern that had never existed before. Watching traffic on that cellular network the way you would watch anything internet-facing turns that first hop into an alert rather than a footnote discovered months later.

The OT Network

Once through, the attackers had 11 days before they did anything destructive. They probed industrial equipment, tested credentials against the plant’s firewall, and connected to controllers on Christmas Day to map their targets. Then, before dawn on December 29, they disabled the Siemens controllers and locked operators out with new passwords.

Every one of those steps is a protocol-level event. The difference between seeing a controller reachable on the network and understanding that someone opened an engineering session, enumerated devices, and changed authentication is the difference between raw connectivity data and knowing what is being said. That distinction is why the plant staff read the turbine trip as human error. Nothing in their visibility told them otherwise.

East-West Traffic

The perimeter was never really the story here. The adversary was already inside a completely trusted zone, moving laterally between facilities that shared nothing but a network. Perimeter tooling is not built to question traffic that originates inside, which is why lateral movement is the phase of an attack that so often goes undetected until the damage is done.

Baselining internal traffic changes that. Off-hours access to a controller, a device suddenly talking to peers it has never contacted, credential attempts against a firewall from an internal source—none of these are exotic detections. They just require that someone is looking at east-west flows with the same seriousness applied to north-south.

Closing the Gaps

NETSCOUT Omnis Cyber Intelligence (OCI) was built for precisely this problem. It provides continuous packet-level visibility across cellular, operational-technology (OT), and internal east-west traffic, with deep packet inspection that decodes industrial protocols and behavioral analysis that surfaces flows and peer relationships that deviate from the baseline. In this incident OCI would have had 11 days and several independent signals to work with, and operators would have known something was wrong long before the turbine stopped.

Secondarily, the attackers went to considerable trouble to destroy evidence, wiping device configurations and corrupting the gateway they had used so badly it could not be repaired. Investigators pieced the attack together only by chance. Evidence held in captured packets does not depend on that kind of luck.

Learn more about Omnis Cyber Intelligence from NETSCOUT