FortiGate VPN breach opened Polish energy attack
A Fortinet FortiGate VPN device in Poland's energy sector was hacked, letting attackers move from a wind farm into a heat and power plant. They stopped a steam turbine and water-treatment system, causing a partial outage for 50,000 homes.
- Report priority
- High
- Involves
- FortiGate VPN
What is known
The attacker first hacked a FortiGate VPN device on a wind farm's perimeter network, then moved through private mobile data links to reach the power plant's systems.
What to do
Check if you use Fortinet FortiGate VPN devices in Poland's energy sector, especially for wind farms or private mobile data networks.
Fortinet has not yet released a specific patch for this incident, but update your FortiGate VPN firmware to the latest version and review your network segmentation to prevent similar attacks.
Reported details
An attacker hacks a FortiGate VPN device on a wind farm's perimeter network. They then use private mobile data links to move into the heat and power plant's systems. There, they stop a steam turbine and water-treatment system, causing a partial outage for 50,000 homes.
A FortiGate VPN device with exposed administrative access served as the initial entry point in a coordinated attack on Poland's energy infrastructure. The vulnerability stemmed from the lack of multi-factor authentication for locally defined VPN accounts, allowing attackers to establish a connection that could traverse the entire network. From there, they exploited a cellular router linked to a private mobile data network (APN) used for operational communications, bypassing traditional perimeter defenses.
The router's web console and SSH service were compromised, enabling lateral movement into a combined heat and power (CHP) controller, whose default credentials were left unchanged. The attacker then used SSH to create a tunnel into the operational technology (OT) network, disrupting critical systems like a steam turbine and water-treatment process at a heat and power plant. The incident occurred on December 29, 2025, as part of a broader campaign targeting over 30 renewable energy facilities.
References
- cert.pl · CERT_Polska_Energy_Sector_Incident_Follow_up_Report_2025.pdf Cyber Security News
- super.underdefense.com · 2027-security-operating-model-webinar Cyber Security News
- zerodayinitiative.com · ZDI-26-524 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-526 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-525 Zero Day Initiative
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- acn.gov.it · rilevate-vulnerabilita-in-mastodon ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-prodotti-zyxel-1 ACN CSIRT Italy
- acn.gov.it · aggiornamenti-per-prodotti-autodesk-11 ACN CSIRT Italy
- acn.gov.it · vulnerabilita-in-prodotti-zoom-3 ACN CSIRT Italy
- neuracybintel.com · silent-takeovers-how-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-on-windows NeuraCybIntel
- acn.gov.it · vulnerabilita-in-prodotti-rapid7 ACN CSIRT Italy
- infosecurity-magazine.com · logistics-ceva-data-breach Infosecurity Magazine