Emerging Technologies Security Blog Listing Page

When “Private” Does Not Mean Protected: Lessons from the Polish Power Plant Breach for 5G and OT Security

Written by Peter Thermos | Aug 13, 2026, 10:00:14 AM

A perspective on why private cellular networks must be treated as part of the operational technology threat surface and not as inherently trusted infrastructure.

Introduction

The recently disclosed breach of a Polish combined heat and power plant should be read as more than another operational technology incident. Its significance lies in the path the attacker leveraged to accomplish their objective. According to the report published by CERT Polska, the adversary reached the plant’s control environment through a private cellular access point name (Teltonika RUTX50 5G dual-SIM router), or private APN, after pivoting from a compromised wind-farm network and then used that access path to affect programmable logic controllers associated with the steam turbine and process-water treatment system [1], [2].

This incident underscores a central lesson; private connectivity should not be misconstrued as trusted connectivity. A dedicated cellular path or private 5G deployment may reduce exposure to the public internet, but it does not eliminate the need for explicit verification, segmentation, hardened management interfaces, credential discipline, and continuous assurance [4],[7]. In industrial environments, the risk is not merely unauthorized data access but rather the possibility that communications infrastructure becomes a bridge into physical process control.

What the Incident Reveals About Modern Critical Infrastructure

The reported attack vector was not groundbreaking due to an exotic cryptographic attack or an zero-day vulnerability. Rather, it was a consequential result stemming from ordinary design decisions aligned in a way that created a viable compromise path and assumed sense of security. The attack-chain elements comprised of an internet-facing VPN/firewall, administrative access, a cellular router, SSH tunneling, permissive private APN behavior, an exposed controller interface, and default credentials which collectively formed a route from one facility into another facility’s operational environment [1], [2].

For industrial operators, this pattern is familiar. Cyber risk often emerges not from a single catastrophic design choice, but from the interaction of assumptions across organizational boundaries. For example, a distribution system operator may manage the cellular connectivity, a plant may operate the control system, a telecommunications provider may deliver the access service and a contractor may maintain the equipment. Each party may believe that another layer is enforcing the necessary trust boundaries and maintains uniform security controls. The adversary, however sees the environment as one connected system and recognizes the absence of a holistic symbiotic governance and cohesive security.

The incident also illustrates a subtle but important distinction between availability of service and integrity of control. The plant restored the affected systems quickly enough to avoid a heat or electricity outage, but the attacker still showed the ability to disrupt controllers and slow recovery. In OT security, avoiding a public outage is not the only measure of severity. The more important question is whether an attacker demonstrated credible control over systems that support physical operations [1], [2].

Zero Trust in 5G Must Be Operational, Not Aspirational

Private cellular networks are valuable because they give operators controlled reachability to distributed industrial assets, but it shouldn’t be mistaken for protection. Furthermore, private 5G improves the security foundation through stronger subscriber authentication, cryptographic protections, network slicing, and edge integration, but those capabilities only reduce risk when they are governed by explicit access decisions and validated controls. This is where the discipline of operational zero trust is imperative [3], [4].

Zero trust in 5G cannot be reduced to an architectural slogan or a set of perimeter controls applied to a newer communications platform. It must operate as a continuous control model in which access is explicitly verified, narrowly authorized, monitored over time, and constrained by operational context. Defense-in-depth remains necessary because controls must be distributed across physical infrastructure, radio access, transport, cloud-native platforms, management systems, and applications. The Polish incident reinforces the need for both approaches. Transport isolation alone was insufficient and the missing element was consistent trust governance across the service delivery ecosystem.

A 5G-adapted zero-trust model must account for the realities of telecommunications and industrial deployments, including API-exposed core network functions, cloud-native platforms, edge computing, network slicing, O-RAN interfaces, distributed radio systems, and supplier-managed components. These domains introduce separate but connected trust decisions, which means every path into OT, including private APNs, 5G slices, field routers, maintenance tunnels, OAM&P interfaces, engineering workstations, and vendor-managed links, must be treated as untrusted until policy, identity, configuration, telemetry, and observed behavior prove otherwise.

From Compliance Controls to Assurance Testing

Standards and guidance provide necessary structure, but they do not prove that a deployed environment resists relevant attack paths. The GSMA 5G Security Guide emphasizes mutual authentication, zero-trust design principles, secure transport assumptions, and the expanded attack surface introduced by virtualization, containerization, network slicing, MEC, DevOps, and open interfaces. Those principles are essential, but they must be translated into testable controls across the actual deployment [5], [6].

Palindrome’s private 5G security case study illustrates this assurance-oriented approach. The assessment scope included radio access signaling, 5G core network functions, OAM&P interfaces, cloud and virtualization infrastructure, containerized environments, management web interfaces, and hardware security of radio nodes. The methodology combined threat modeling, deterministic testing of expected controls, and non-deterministic exploration of novel attack vectors. That combination is important because industrial compromise paths rarely respect the neat boundaries of an architecture diagram [7].

In industrial private 5G deployments, assurance testing should ask uncomfortable but operationally relevant questions. Can one device on a private cellular segment communicate with another device that it does not need to reach? Are management interfaces reachable from the wrong zone? Are OAM&P credentials overprivileged or reused? Can a compromised router or user equipment establish tunnels into OT assets? Are APIs enforcing authentication and authorization at the network-function level? Are Kubernetes network policies, role-based access controls, and secrets management aligned with the intended trust boundaries? Are radio nodes protected against hardware tampering, unauthorized debug access, and weak boot protections?

Practical Actions for Operators Using Private APNs or Private 5G

To ensure operators maintain a strong security posture, private cellular deployments should be managed through a maturity-based assurance model rather than a one-time hardening exercise.

Figure 1 Private cellular and private 5G security maturity model showing the progression from visibility, to control, to continuous assurance

The first level is visibility, where operators must maintain an accurate inventory of every cellular-enabled device, router, gateway, controller, engineering workstation, and management endpoint, including ownership, required communication paths, exposed services, authentication methods, firmware state, management access, and operational consequence of compromise. The next level is control, where private cellular segments should enforce explicit client isolation, least-privilege reachability, and default-deny access to peer-to-peer communication and management services unless there is a documented operational need and compensating controls [1], [2], [4], [7].

Higher maturity requires identity-driven access, continuous validation, and evidence-based monitoring. Default credentials must be eliminated, administrative access should be tied to named identities and time-bound privileges, and a valid SIM or subscription should not imply device trust, administrative authority, or lateral access. Operators should then correlate telemetry from cellular gateways, 5G core elements, firewalls, OT switches, controllers, and identity systems to detect scanning within private APNs, unexpected device-to-device communication, anomalous tunnels, unusual management-interface access, repeated failed authentication, PLC mode changes, and configuration changes to routers, gateways, and network functions. This progression from visibility, to control, to continuous assurance reflects the maturity-model approach to evolve a private cellular OT network into a governed operational capability rather than an assumed trust boundary [4].

Conclusion: Treat Connectivity as a Control Surface

The Polish power plant breach should change how critical infrastructure leaders discuss private connectivity. The issue is not whether private APNs or private 5G are insecure by design. The issue is whether they are operated with the same rigor expected of any pathway into operational technology. Private connectivity can improve reliability, performance, and manageability, but it also becomes part of the control surface that adversaries will evaluate [1], [2], [3], [7].

For energy, manufacturing, transportation, and public-sector operators, the path forward is neither to reject connectivity nor to rely on architectural labels for comfort. The path forward is to verify trust continuously, constrain communication intentionally, verify the environment through adversarial testing and treat every access path (e.g., public, private, cellular, wired, vendor-managed, or internally operated) as a potential route to operational consequence. This is the practical meaning of zero trust in private 5G and OT environments.

References

[1] S. Khandelwal, “Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine,” The Hacker News, Aug. 11, 2026.

[2] CERT Polska, “Follow-Up Report of the December 2025 Energy Sector Incident,” Aug. 8, 2026.

[3] Palindrome Technologies, “Operationalizing Zero Trust in 5G Architectures: Moving Beyond the Perimeter,” Jun. 24, 2026.

[4] S. Murali and P. Thermos, “Implementing Zero Trust in 5G Networks: An Introduction for a Maturity-Model-Based Path Using CISA, NIST, 3GPP, and O-RAN Guidance,” Palindrome Technologies, 2026.

[5] Palindrome Technologies, “Navigating 5G Security: A Practitioner’s Take on the GSMA 5G Security Guide (July 2024),” May 27, 2025.

[6] GSMA, “FS.40 5G Security Guide Version 3.0,” Jul. 16, 2024.

[7] P. Thermos and S. Murali, “Private 5G Security Uncovered: Lessons from Industrial Automation,” Palindrome Technologies.