惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
G
Google Developers Blog
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
J
Java Code Geeks
U
Unit 42
云风的 BLOG
云风的 BLOG
阮一峰的网络日志
阮一峰的网络日志
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Docker
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
V
V2EX
T
Tailwind CSS Blog

NETSCOUT

From Data Overload to Network Intelligence | NETSCOUT How IT and Executives View Business Impact of Network Disruptions | NETSCOUT NETSCOUT Earns Top Recognition in 2026 for DDoS Mitigation | NETSCOUT Observability with AI-Ready Data Helps Reduce Time to Solve Problems | NETSCOUT Getting Beyond the Noise for Data That Really Thinks | NETSCOUT The Future of Observability Isn’t More Data; It’s Smarter Data | NETSCOUT What Is Keeping IT Leaders and Teams Up at Night Right Now? | NETSCOUT The Compelling Need for AI-Ready ‘Smart Data’ | NETSCOUT How AI Is Reshaping the Radio Access Network | NETSCOUT Six Critical Business Benefits of Real-Time Data Insights | NETSCOUT AI Reality Check: Why IT Teams Are Embracing AI | NETSCOUT The Future of Telecom Operations Is Powered by Autonomy at Scale | NETSCOUT Why Customer Lifetime Value Begins on the Network | NETSCOUT Service Providers Rethink Fraud Detection in the 5G Era | NETSCOUT Resilience Is the Foundation of Modern Security Strategy | NETSCOUT How Machines Are Taking Over Network Traffic | NETSCOUT Why AI Moves Faster Than the Controls Built to Manage It | NETSCOUT NETSCOUT Named a SPARK Matrix™ Leader in Network Observability for the Third Consecutive Year | NETSCOUT Why CDNs Alone Are Not Sufficient for Modern DDoS Protection | NETSCOUT All That Glitters Isn’t Gold: Why AI Needs Better Data | NETSCOUT From Horseback to Real-Time Observability | NETSCOUT Why Digital Twins Are Now Mission-Critical for Scaling 5G with Confidence | NETSCOUT NETSCOUT Earns Six Leader Badges in the G2 Summer 2026 Grid Reports | NETSCOUT When Too Much Data Becomes Too Big an AI Problem | NETSCOUT Game-Changing AI in the RAN Plays by Its Own Rules | NETSCOUT 75,000 DDoS-for-Hire Actors Targeted by Law Enforcement | NETSCOUT What Is NETSCOUT Smart Data and Why Is It So Important? | NETSCOUT Understanding Network Traffic for Threat Hunting | NETSCOUT Black Box Versus Glass Box DDoS Protection Intellyx Names NETSCOUT to Prestigious 2026 Digital Innovator Award List
Cyberattack in Poland Causes Heat and Power Outages for 5...
Brad.Christian · 2026-08-25 · via NETSCOUT

Poland’s computer emergency response team (CERT) recently published a follow-up report on a cyberattack that shut down a steam turbine and water treatment system at a combined heat and power plant serving 50,000 people. For months, nobody knew it was an attack. The shutdown happened during Christmas maintenance, operators assumed a contractor had made a mistake, and the incident was filed for informational purposes only. It took a three-month investigation, prompted by the coincidence that more than 30 other energy sites were hit the same day, to establish what had actually happened.

What the investigators found was an attack that crossed three networks, spent 11 days in reconnaissance, and left visible traces in all of them.

The Cellular Network

The attackers came in through firewalls at wind farm substations they had already compromised and then reached a cellular router sitting on a private mobile data network. Distributed energy sites use these networks to talk to grid operators, and the industry has long treated them as walled-off and inherently safe. This one let any device on it talk to any other device, which meant a foothold at a wind farm gave the attackers a path to a heat plant that had no business relationship with it whatsoever.

A router at one facility opening a session to a controller at another is not subtle. It is a communication pattern that had never existed before. Watching traffic on that cellular network the way you would watch anything internet-facing turns that first hop into an alert rather than a footnote discovered months later.

The OT Network

Once through, the attackers had 11 days before they did anything destructive. They probed industrial equipment, tested credentials against the plant’s firewall, and connected to controllers on Christmas Day to map their targets. Then, before dawn on December 29, they disabled the Siemens controllers and locked operators out with new passwords.

Every one of those steps is a protocol-level event. The difference between seeing a controller reachable on the network and understanding that someone opened an engineering session, enumerated devices, and changed authentication is the difference between raw connectivity data and knowing what is being said. That distinction is why the plant staff read the turbine trip as human error. Nothing in their visibility told them otherwise.

East-West Traffic

The perimeter was never really the story here. The adversary was already inside a completely trusted zone, moving laterally between facilities that shared nothing but a network. Perimeter tooling is not built to question traffic that originates inside, which is why lateral movement is the phase of an attack that so often goes undetected until the damage is done.

Baselining internal traffic changes that. Off-hours access to a controller, a device suddenly talking to peers it has never contacted, credential attempts against a firewall from an internal source—none of these are exotic detections. They just require that someone is looking at east-west flows with the same seriousness applied to north-south.

Closing the Gaps

NETSCOUT Omnis Cyber Intelligence (OCI) was built for precisely this problem. It provides continuous packet-level visibility across cellular, operational-technology (OT), and internal east-west traffic, with deep packet inspection that decodes industrial protocols and behavioral analysis that surfaces flows and peer relationships that deviate from the baseline. In this incident OCI would have had 11 days and several independent signals to work with, and operators would have known something was wrong long before the turbine stopped.

Secondarily, the attackers went to considerable trouble to destroy evidence, wiping device configurations and corrupting the gateway they had used so badly it could not be repaired. Investigators pieced the attack together only by chance. Evidence held in captured packets does not depend on that kind of luck.

Learn more about Omnis Cyber Intelligence from NETSCOUT