Executive SummaryModern industrial operators are rapidly connecting remote infrastructure — wind turbines, solar arrays, water pumps, and distribution substations — using cellular networks, private APNs, and SD-WAN. Historically, these private cellular networks have been treated as trusted, secure, “walled-off” perimeters.A Landmark Investigation disclosed by CERT Polska in August 2026 shattered this assumption. In a highly coordinated campaign, threat actors breached a combined heat and power (CHP) plant in Poland, successfully shutting down a steam turbine and its process-water treatment system.This blog provides a highly technical analysis of this historic cyberattack, maps the step-by-step technical pathway of the pivot, explains why traditional cellular and SD-WAN setups create a catastrophic blast radius, and outlines how Zscaler’s Zero Trust Exchange platform significantly mitigates these vectors. The Incident — What HappenedThe incident occurred on December 29, 2025, and was publicly disclosed after a comprehensive investigation on August 8, 2026. This was a highly targeted, state-sponsored campaign designed to impact physical operations. The attack began at an unmanned remote wind farm and ultimately resulted in the forced shutdown of a steam turbine at a central combined heat and power plant — a facility supplying municipal heat to 50,000 residents.The attack chain followed a precise, multi-stage path: a remote wind farm firewall was compromised, granting the attackers footing on the facility’s local network. From there, they accessed an on-site Teltonika cellular router via SSH, which opened a tunnel into the grid operator’s private APN. Traversing that APN, they scanned the entire private cellular IP space and discovered a WAGO PLC at the CHP plant configured with default credentials. That PLC served as a bridge into the core OT network, and from there the attackers issued unauthorized stop commands to the Siemens PLCs controlling the steam turbine — achieving physical disruption.Incident at a GlanceMetric / AspectIncident DetailsTarget FacilityCombined Heat and Power (CHP) Plant (Poland) supplying municipal heat to 50,000 residents.AttributionSandworm (also known as the Russian state-sponsored threat group Electrum).Campaign ScopeCoordinated, simultaneous attacks targeting over 30 other Polish renewable energy and power distribution sites.Physical ImpactComplete temporary shutdown of a steam turbine and its process-water treatment system.Primary VectorLateral movement through a local grid operator’s private cellular Access Point Name (APN). Anatomy of the Attack — Step by StepThe following table reconstructs the precise six-stage attack chain executed by Sandworm. Each step built directly on the last, exploiting a combination of internet-exposed management interfaces, flat private cellular network topology, and default device credentials to achieve full OT impact.#Attack StageDescription1Initial AccessSandworm exploited an internet-facing unpatched firewall at a remote, unmanned wind farm.2Device ControlThe attackers accessed the wind farm’s on-site Teltonika cellular router via Secure Shell (SSH).3APN TunnelingUsing the compromised router, the attackers established a tunnel into the grid operator’s private APN.4Lateral ReconnaissanceDue to a lack of client isolation on the private APN, the attackers scanned the entire private cellular IP space.5PLC ExploitationThe scan discovered a WAGO PLC at the central CHP plant, which was exposed to the APN with default administrator credentials.6Operational DisruptionThe attackers used the WAGO PLC as a network bridge to access the core OT network, issuing unauthorized stop commands to the Siemens PLCs controlling the steam turbine. Why Traditional Defenses FailedThis breach highlights a fundamental security misconception: the belief that carrier-provided private APNs or corporate SD-WAN networks provide a secure, isolated boundary. In reality, these technologies deliver connectivity and no security. Both APNs and SDWAN systems are built to connect devices. The moment a single endpoint on that shared network is compromised, the entire flat address space becomes an attacker’s reconnaissance playground. The attacker leveraged the lack of controls on the APN to get into the flat network to pivot to the PLC. The following comparison maps the legacy assumptions that enabled this attack against the modern cyber reality — and demonstrates how Zscaler’s Zero Trust paradigm would have eliminated the attack path entirely.Attack StageTraditional VulnerabilityHow Zscaler Eliminates The ThreatStage 1: Initial Perimeter Breach(Exploited Remote Firewall)Exposed public-facing IPs and open SSH management ports on cellular gateways are easily scanned and targeted by brute-force attacks.Zero Public Attack Surface: Zscaler Cellular makes all remote gateways completely invisible to the internet. Outbound-only connections to the Zscaler Zero Trust Exchange mean there are zero public-facing IPs or open inbound ports to scan.Stage 2: Lateral APN Reconnaissance(Scanned Private Cellular Grid)A flat APN permits any compromised cellular device to discover, ping, and compromise other remote terminals and power plants.Total Peer Isolation: Zscaler prevents device-to-device visibility on the cellular network. Connected devices can only communicate outbound to the Zscaler broker, completely blocking attackers from scanning the APN.Stage 3: Credential Exploitation(Brute-forced WAGO PLC)Exposed local administrative portals are highly vulnerable to default credential harvesting and unauthorized access.Identity-Centric Access Proxy: Zscaler acts as a secure identity broker. Even if an attacker physically accesses the local APN, they cannot see or communicate with the WAGO PLC’s login portal without first passing MFA-backed identity policies.Stage 4: Core Network Bridging(Pivoted from PLC to Turbine)Flat internal routing allows a compromised edge controller to act as a bridge into the plant’s core OT control network.Agentless Device Segmentation: Zscaler isolates legacy assets at the application layer without requiring software agents on the PLCs. It blocks lateral traffic between the edge PLC and the core OT network, restricting communications to pre-approved paths.Stage 5: Industrial Disruption(Issued Stop Commands to Siemens PLCs)Plain-text industrial protocols (like Modbus or S7comm) lack cryptographic authentication, enabling unauthorized physical stop commands.Ransomware Kill Switch & Protocol Isolation: Administrators can instantly trigger a global isolation protocol to quarantine compromised zones. Zscaler also enforces granular protocol-level access without deploying any agents. Read More The Zscaler SolutionTo comprehend how Zscaler secures OT environments, we must first examine the core principles of the Zero Trust Security Model . Traditional network security relies on a “castle-and-moat” design, where perimeter firewalls secure the border, but everything inside is implicitly trusted. Once an intruder like Sandworm breaches the outer defense (the moat), they enjoy free lateral movement across the flat interior (the castle)Securing distributed OT infrastructure requires moving from a network-centric approach to an application-centric Zero Trust architecture. Zscaler delivers native security capabilities designed to eliminate the exact attack path used by Sandworm. Each capability below maps directly to a stage of the incident, removing the preconditions the threat actors depended on at every step of the kill chain. Zscaler Security CapabilityTechnical FunctionIndustrial ValueZscaler CellularSecures both inbound and outbound cellular communications. Devices do not have public IPs or open listening ports.Hides the Attack Surface: Eliminates the ability for threat actors to scan the cellular network or discover exposed remote terminals.Zscaler Zero Trust Device SegmentationImplements agentless, identity-based micro-segmentation for legacy PLCs and RTUs without requiring software on the endpoints.Inhibits Lateral Movement: Even if a remote router is compromised, Zscaler blocks it from communicating with the central plant’s controllers.Ransomware Kill SwitchAllows administrators to instantly sever all lateral network connections with a single command during an active incident.Grid Protection: Limits the blast radius of a breach to a single segment, keeping the broader municipal utility online. Protect Your OT Infrastructure TodayZscaler Zero Trust Exchange™ eliminates lateral movement, hides your OT assets from attackers, and gives you instant incident response — all without disrupting operations.→ Learn more at https://resources/security-terms-glossary/what-is-operational-technology-ot-security/products-and-solutions/zscaler-cellular Act Fast. Stay Secure.
[#item_full_content] Executive SummaryModern industrial operators are rapidly connecting remote infrastructure — wind turbines, solar arrays, water pumps, and distribution substations — using cellular networks, private APNs, and SD-WAN. Historically, these private cellular networks have been treated as trusted, secure, “walled-off” perimeters.A Landmark Investigation disclosed by CERT Polska in August 2026 shattered this assumption. In a highly coordinated campaign, threat actors breached a combined heat and power (CHP) plant in Poland, successfully shutting down a steam turbine and its process-water treatment system.This blog provides a highly technical analysis of this historic cyberattack, maps the step-by-step technical pathway of the pivot, explains why traditional cellular and SD-WAN setups create a catastrophic blast radius, and outlines how Zscaler’s Zero Trust Exchange platform significantly mitigates these vectors. The Incident — What HappenedThe incident occurred on December 29, 2025, and was publicly disclosed after a comprehensive investigation on August 8, 2026. This was a highly targeted, state-sponsored campaign designed to impact physical operations. The attack began at an unmanned remote wind farm and ultimately resulted in the forced shutdown of a steam turbine at a central combined heat and power plant — a facility supplying municipal heat to 50,000 residents.The attack chain followed a precise, multi-stage path: a remote wind farm firewall was compromised, granting the attackers footing on the facility’s local network. From there, they accessed an on-site Teltonika cellular router via SSH, which opened a tunnel into the grid operator’s private APN. Traversing that APN, they scanned the entire private cellular IP space and discovered a WAGO PLC at the CHP plant configured with default credentials. That PLC served as a bridge into the core OT network, and from there the attackers issued unauthorized stop commands to the Siemens PLCs controlling the steam turbine — achieving physical disruption.Incident at a GlanceMetric / AspectIncident DetailsTarget FacilityCombined Heat and Power (CHP) Plant (Poland) supplying municipal heat to 50,000 residents.AttributionSandworm (also known as the Russian state-sponsored threat group Electrum).Campaign ScopeCoordinated, simultaneous attacks targeting over 30 other Polish renewable energy and power distribution sites.Physical ImpactComplete temporary shutdown of a steam turbine and its process-water treatment system.Primary VectorLateral movement through a local grid operator’s private cellular Access Point Name (APN). Anatomy of the Attack — Step by StepThe following table reconstructs the precise six-stage attack chain executed by Sandworm. Each step built directly on the last, exploiting a combination of internet-exposed management interfaces, flat private cellular network topology, and default device credentials to achieve full OT impact.#Attack StageDescription1Initial AccessSandworm exploited an internet-facing unpatched firewall at a remote, unmanned wind farm.2Device ControlThe attackers accessed the wind farm’s on-site Teltonika cellular router via Secure Shell (SSH).3APN TunnelingUsing the compromised router, the attackers established a tunnel into the grid operator’s private APN.4Lateral ReconnaissanceDue to a lack of client isolation on the private APN, the attackers scanned the entire private cellular IP space.5PLC ExploitationThe scan discovered a WAGO PLC at the central CHP plant, which was exposed to the APN with default administrator credentials.6Operational DisruptionThe attackers used the WAGO PLC as a network bridge to access the core OT network, issuing unauthorized stop commands to the Siemens PLCs controlling the steam turbine. Why Traditional Defenses FailedThis breach highlights a fundamental security misconception: the belief that carrier-provided private APNs or corporate SD-WAN networks provide a secure, isolated boundary. In reality, these technologies deliver connectivity and no security. Both APNs and SDWAN systems are built to connect devices. The moment a single endpoint on that shared network is compromised, the entire flat address space becomes an attacker’s reconnaissance playground. The attacker leveraged the lack of controls on the APN to get into the flat network to pivot to the PLC. The following comparison maps the legacy assumptions that enabled this attack against the modern cyber reality — and demonstrates how Zscaler’s Zero Trust paradigm would have eliminated the attack path entirely.Attack StageTraditional VulnerabilityHow Zscaler Eliminates The ThreatStage 1: Initial Perimeter Breach(Exploited Remote Firewall)Exposed public-facing IPs and open SSH management ports on cellular gateways are easily scanned and targeted by brute-force attacks.Zero Public Attack Surface: Zscaler Cellular makes all remote gateways completely invisible to the internet. Outbound-only connections to the Zscaler Zero Trust Exchange mean there are zero public-facing IPs or open inbound ports to scan.Stage 2: Lateral APN Reconnaissance(Scanned Private Cellular Grid)A flat APN permits any compromised cellular device to discover, ping, and compromise other remote terminals and power plants.Total Peer Isolation: Zscaler prevents device-to-device visibility on the cellular network. Connected devices can only communicate outbound to the Zscaler broker, completely blocking attackers from scanning the APN.Stage 3: Credential Exploitation(Brute-forced WAGO PLC)Exposed local administrative portals are highly vulnerable to default credential harvesting and unauthorized access.Identity-Centric Access Proxy: Zscaler acts as a secure identity broker. Even if an attacker physically accesses the local APN, they cannot see or communicate with the WAGO PLC’s login portal without first passing MFA-backed identity policies.Stage 4: Core Network Bridging(Pivoted from PLC to Turbine)Flat internal routing allows a compromised edge controller to act as a bridge into the plant’s core OT control network.Agentless Device Segmentation: Zscaler isolates legacy assets at the application layer without requiring software agents on the PLCs. It blocks lateral traffic between the edge PLC and the core OT network, restricting communications to pre-approved paths.Stage 5: Industrial Disruption(Issued Stop Commands to Siemens PLCs)Plain-text industrial protocols (like Modbus or S7comm) lack cryptographic authentication, enabling unauthorized physical stop commands.Ransomware Kill Switch & Protocol Isolation: Administrators can instantly trigger a global isolation protocol to quarantine compromised zones. Zscaler also enforces granular protocol-level access without deploying any agents. Read More The Zscaler SolutionTo comprehend how Zscaler secures OT environments, we must first examine the core principles of the Zero Trust Security Model . Traditional network security relies on a “castle-and-moat” design, where perimeter firewalls secure the border, but everything inside is implicitly trusted. Once an intruder like Sandworm breaches the outer defense (the moat), they enjoy free lateral movement across the flat interior (the castle)Securing distributed OT infrastructure requires moving from a network-centric approach to an application-centric Zero Trust architecture. Zscaler delivers native security capabilities designed to eliminate the exact attack path used by Sandworm. Each capability below maps directly to a stage of the incident, removing the preconditions the threat actors depended on at every step of the kill chain. Zscaler Security CapabilityTechnical FunctionIndustrial ValueZscaler CellularSecures both inbound and outbound cellular communications. Devices do not have public IPs or open listening ports.Hides the Attack Surface: Eliminates the ability for threat actors to scan the cellular network or discover exposed remote terminals.Zscaler Zero Trust Device SegmentationImplements agentless, identity-based micro-segmentation for legacy PLCs and RTUs without requiring software on the endpoints.Inhibits Lateral Movement: Even if a remote router is compromised, Zscaler blocks it from communicating with the central plant’s controllers.Ransomware Kill SwitchAllows administrators to instantly sever all lateral network connections with a single command during an active incident.Grid Protection: Limits the blast radius of a breach to a single segment, keeping the broader municipal utility online. Protect Your OT Infrastructure TodayZscaler Zero Trust Exchange™ eliminates lateral movement, hides your OT assets from attackers, and gives you instant incident response — all without disrupting operations.→ Learn more at https://resources/security-terms-glossary/what-is-operational-technology-ot-security/products-and-solutions/zscaler-cellular Act Fast. Stay Secure.