They crossed from a wind farm to a power plant turbine through the grid operator's private APN
On 8 August CERT Polska published its analysis of the 29 December 2025 attack on a Polish combined heat and power plant. The attacker got in through a FortiGate with no multi-factor authentication, hopped to a cellular router, crossed the distribution operator's private APN and put three families of Siemens PLCs into STOP mode. The report does not cite a single CVE in the whole chain: what it describes is a mobile network we all call private in which any device could talk to any other.