Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack
Key Takeaways A critical FortiGate RCE (CVE-2022-42475) was exploited as the initial vector in a sophisticated attack on Poland’s energy infrastructure. The intrusion, affecting a wind farm and...
Key Takeaways
- A critical FortiGate RCE (CVE-2022-42475) was exploited as the initial vector in a sophisticated attack on Poland’s energy infrastructure.
- The intrusion, affecting a wind farm and a heat and power plant, caused operational disruption but did not interrupt essential services to residents.
- Attackers leveraged a compromised perimeter device and a private mobile data network (APN) to traverse networks, highlighting the risks of interconnected systems.
- The incident demonstrates a focus on disrupting industrial processes directly, rather than data theft, and emphasizes the importance of robust segmentation and credential management.
A detailed investigation into an attack on Poland’s energy sector has revealed a concerning pathway from a seemingly isolated remote-access device to operational disruption within critical industrial systems. This incident, which occurred on December 29, 2025, was part of a broader coordinated campaign targeting over 30 renewable energy facilities.
Table Of Content
The attackers successfully transitioned from a wind farm network to a combined heat and power (CHP) plant, exploiting trusted connectivity to cause significant operational interruptions. At the CHP plant, a steam turbine and water-treatment system were halted, disrupting cogeneration processes. Despite these disruptions, heat and electricity supplies to approximately 50,000 residents remained unaffected, as detailed in a report by CERT.PL.
Following a three-month forensic analysis, CERT.PL analysts meticulously traced the intrusion’s origins, initially suspected to be a maintenance error. Their findings highlighted a critical vector: the attackers did not require direct internet exposure for the plant. Instead, they navigated through a private mobile data environment, specifically an APN (Access Point Name), which was utilized for operational communications. This allowed them to bridge networks and extend their reach into sensitive industrial control systems (ICS).
This incident mirrors other coordinated attacks on Polish energy infrastructure, where the primary objective was operational disruption rather than data exfiltration. CERT.PL said in a report that this scenario underscores how an apparently isolated connection can introduce significant risk when attached devices possess the capability to communicate freely across different segments.
Compromised FortiGate VPN as Entry Point
The initial breach occurred via a perimeter device at a wind farm, which served dual functions as a firewall and VPN gateway. This internet-facing VPN was notably lacking multi-factor authentication (MFA) for its locally defined accounts. This vulnerability likely enabled the intruder to acquire administrative credentials, granting them access to a VPN account with privileges spanning multiple network segments, according to CERT.PL’s findings.
From this initial foothold, the attackers identified a cellular router. This device was strategically connected to both the wind farm network and a private APN, which served as a dedicated mobile network for the distribution system operator. The router’s web console and SSH service subsequently became the conduit into the private APN.
The next objective within the attack chain was a CHP controller, accessible through the compromised APN. This controller’s web administration interface was secured only by default credentials, which the attackers exploited. After successfully gaining access, they enabled SSH and established a new tunnel directly into the operational technology (OT) network, as detailed in the CERT.PL report.
The utilization of the private APN in this attack chain is particularly significant. Private APNs are frequently perceived as inherently secure transport mechanisms. However, in this instance, a misconfiguration allowed arbitrary connected devices to establish connections with each other, effectively enabling a breach at one site to propagate to another. This echoes a broader lesson observed in various FortiGate breach investigations: control over a single perimeter appliance can expose a far greater scope of an organization’s infrastructure than just the device itself.
Reconnaissance Led to Process Disruption
Between December 18 and 25, the intruder meticulously conducted reconnaissance, scanning for remote-control and industrial services. This phase involved thorough exploration of the CHP network and attempts to access its firewall and remote desktop systems. The reconnaissance included successful interactions with three Siemens controllers prior to the final disruptive operation, strongly suggesting deliberate preparation rather than an opportunistic attack, as noted by CERT.PL.
On the morning of December 29, the attackers successfully accessed the plant’s supervisory interface and subsequently manipulated Siemens S7 controllers. This manipulation forced the controllers into STOP mode, resulting in the shutdown of the steam turbine and the water-treatment system.
Plant personnel initiated recovery by restoring factory settings and reloading logic backups, which helped to limit the duration of the outage. However, this recovery action inadvertently erased critical device logs necessary for a comprehensive forensic review, as highlighted in the CERT.PL report.
Further compounding the recovery efforts, the attackers also reset serial-device servers and network switches, changed their passwords, and modified their network configurations. These actions were clearly intended to impede and slow down restoration. Malicious activity persisted for nearly five hours after the plant began its recovery process. Subsequently, the gateway controller was damaged, the cellular router was reset, and the original perimeter device was reverted to factory settings, destroying valuable forensic evidence, according to CERT.PL.
This incident diverges from the DynoWiper destructive malware observed elsewhere in the broader Polish campaign, as this attack path focused on direct manipulation of industrial devices. Nevertheless, both approaches achieved the same objective: interrupting essential operations and complicating recovery.
What You Should Do
- Audit Private APN Configurations: Regularly review and harden configurations for private APNs, implementing client isolation and treating them as untrusted when integrated with operational networks.
- Implement Network Segmentation: Restrict connections using allowlists and segment gateway devices from critical control systems.
- Monitor Unusual Traffic: Establish robust monitoring for anomalous network traffic within OT environments, especially across APN connections.
- Centralize and Protect Logs: Ensure gateway logs and other critical system logs are centralized, securely stored, and protected from tampering or deletion.
- Remove Exposed Administration Services: Eliminate any unnecessary exposed administration services and ensure all essential services are properly secured.
- Change Default Credentials: Immediately change all default credentials on industrial control systems, routers, and network devices.
- Regular Penetration Testing and Architecture Reviews: Integrate these security controls and the attack path considerations into routine penetration tests and architecture reviews to identify and remediate vulnerabilities proactively.
- Enable Multi-Factor Authentication (MFA): Mandate MFA for all remote access, especially for administrative accounts on VPNs and perimeter devices.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.