A Private Network Is Not a Plant Boundary

PDF UPLOAD LINK

InnovAKT insight report · Intelligence Team

A wind farm. A shared mobile network. A heat-and-power plant. The connections were legitimate. The authority they created was not understood.

Explore the private-APN route described in CERT Polska’s follow-up investigation, and the evidence operators should ask for before trusting an external connection.

PDF · 13 pages · 1.3 MB · Report dated 8 October 2026

The question behind the incident

What can a trusted connection actually change?

The plant’s own perimeter was not the route in. The reconstructed path began elsewhere, crossed a private mobile network, and reached a controller with access to the plant’s OT environment.

That changes the assurance question. A connection being private, approved or necessary does not establish what it can reach—or what it can do once it arrives.

The boundary is what you can demonstrate, not what the network is called.

Explore the reconstructed route

Five connections. One path to the process.

Select a stage to follow the route. Each view separates what the incident report describes from the checks InnovAKT recommends for your own environment.

01 / 05 · Wind farm

A remote-access firewall provided the initial foothold.

Reported incident

The report describes an Internet-exposed VPN without multi-factor authentication and an attacker with administrative access.

What to verify

Verify remote human access, MFA, administrative privileges and the scope each session can reach.

02 / 05 · Management

The management path crossed the intended boundary.

Reported incident

The operational connection used serial DNP3, but the cellular router’s web and SSH administration were reachable behind the compromised firewall.

What to verify

Review administration separately from telemetry. Establish who can manage the gateway, from where, and under which approval.

03 / 05 · Shared network

“Private” did not mean isolated.

Reported incident

Devices on the grid operator’s private mobile network could communicate with one another, exposing a route between otherwise unrelated sites.

What to verify

Ask for provider-side isolation evidence and a controlled path test. Identify the enforcement point that blocks prohibited site-to-site traffic.

04 / 05 · Plant gateway

An external interface opened a route into OT.

Reported incident

The plant’s gateway controller exposed web administration with default credentials. The reconstructed route continued into the plant network.

What to verify

Remove default credentials, restrict management exposure and allow only the functions the connection actually needs.

05 / 05 · Physical process

Access became operational consequence.

Reported incident

Plant personnel reported stopped and password-protected PLCs. Network devices were also disrupted, complicating recovery. Heat supplies to customers continued.

What to verify

Validate action-level permissions and protective controls on the actual equipment. Rehearse recovery and control the entry path before reconnecting.

Simplified reconstruction based on CERT Polska. Not a complete network design. The router password’s origin and whether a vulnerability was used remain unresolved; reported PLC states came from plant personnel.

The recovery lesson

Restore the operation.
Do not restore the route.

Operators began recovery while the attacker was still active. Rapid action limited the outage and preserved heat supply to customers. But resetting equipment also removed evidence. Recovery planning has to address both the essential service and the access path that put it at risk.

05:30–10:10Attacker activity

Activity continued in the plant network during the morning of 29 December 2025.

≈07:00Process interruption

The steam turbine and process-water treatment system stopped.

From 07:30Recovery underway

Operators began restoring the plant while the attack was still in progress.

Before reconnecting, establish that the entry path is controlled, restored configurations are trusted, credentials are renewed, monitoring is active and operations has authorised the return to service.

Take this into the next leadership conversation

Ask for evidence. Open each question.

01 · Which outside connections can reach our control systems?

Ask for one current connection inventory reconciled with the provider and integrator. Include cellular, telecom, vendor, backup and maintenance paths, with a named owner for each.

02 · What could each connection change in the plant?

Trace the path to the final action. Distinguish observation from operating, stopping, programming, administration and recovery. A successful login is not proof of appropriate authority.

03 · Can the provider demonstrate isolation between sites?

Request the isolation configuration and an authorised, non-disruptive test. Required communication should succeed; prohibited communication should fail at a named enforcement point.

04 · Would we recognise an attack that looks like maintenance?

Check unexpected stops, password changes and lost communications against the approved scope and time window. Escalate unexplained events to someone who understands the physical process.

05 · Have we proved that a locked controller can be recovered?

Rehearse a representative restore using the people, software, configurations and spares actually available. Record the elapsed time and control the entry path before reconnection.

Keep the complete analysis

From the incident
to your next decision.

Start with the two-page executive summary. Then use the technical analysis to challenge the access, architecture and recovery assumptions behind your own critical operations.

Enter your first name, last name and business email. Your download appears immediately, and we’ll email you the link for later.

13-page PDF · 1.3 MB · InnovAKT Intelligence Team

By submitting, you request this report and its delivery email. This does not sign you up for a newsletter. Privacy notice.

Form not loading? Open the report request form or email InnovAKT.

PART 1 · PAGES 2–3The executive conversationIncident context, leadership questions and recommended decisions.
PART 2 · PAGES 4–12The engineering evidenceAccess paths, architecture, permissions, detection, recovery and acceptance criteria.
ASSESS → REMEDIATE → OPERATE → LEADA practical sequenceA 90-day planning model, adapted to vendor validation, change control and approved maintenance windows.

Sources and scope. InnovAKT’s report draws on CERT Polska’s initial report and follow-up investigation, with further engineering references in the PDF. It is independent public-source analysis, not a forensic investigation, site assessment or compliance certification. Suggested checks are recommendations, not proven counterfactuals.

No reviewed evidence connects this campaign to Aruba, Curaçao, Bonaire or any InnovAKT customer. The value for island utilities is the scenario to examine, not an assumption of local compromise.

Continue the discussion: Private Connectivity, Public Consequences · Review process authority with AKTAuthority · Talk with InnovAKT

Next
Next

Different Threats. The Same Operational Consequence.