Private LTE, private 5G, cellular routers, and industrial IoT links are becoming normal parts of utility operations. That connectivity can improve monitoring and response, but it also changes the threat model: the network path into operational technology may no longer look like a traditional corporate VPN, firewall rule, or remote desktop session.
Fierce Network reported on CERT Polska’s follow-up analysis of a December 2025 attack against Poland’s energy sector, where investigators identified a private APN environment as part of the attack path into operational technology systems. CERT Polska’s own report says the incident affected a smaller combined heat-and-power plant serving roughly 50,000 residents, temporarily shutting down a steam turbine and water treatment systems used in the cogeneration process before operators restored service.
The important lesson is not “private wireless is bad.” It is that private wireless is now part of the critical infrastructure attack surface. If a private APN, cellular router, or industrial wireless segment allows devices to communicate too broadly, an attacker who compromises one reachable node may be able to pivot into systems defenders assumed were isolated.
What happened
According to the reporting and CERT Polska’s follow-up, investigators found that attackers used access through a private APN network to reach OT systems. The compromised environment included a Teltonika RUTX50 router, and CERT Polska highlighted a misconfiguration that allowed arbitrary devices inside the private APN environment to communicate with one another.
That matters because many organizations treat carrier-provided private connectivity as inherently trusted. In practice, a private APN or private wireless deployment still needs segmentation, device identity, logging, access control, and incident response planning. “Private” does not automatically mean “safe,” especially when remote operations, cellular routers, and plant-floor systems share the same trust zone.
Why this matters for utilities, SMBs, and government contractors
Utilities are not the only organizations adopting this model. Municipal services, manufacturers, logistics operators, ports, agriculture technology providers, and government contractors increasingly use private wireless or cellular-connected equipment to monitor remote sites. Those networks often sit between IT and OT: close enough to support business operations, but sensitive enough that compromise can affect physical processes.
For smaller organizations, the risk is especially practical. A cellular router installed years ago by a vendor may still have SSH exposed, shared credentials, limited logging, permissive peer-to-peer communication, or unclear ownership between IT, facilities, engineering, and the service provider. That creates a blind spot where attackers can hide in the connectivity layer rather than the industrial controller itself.
Defensive takeaways
- Inventory private wireless paths. Track private APNs, cellular routers, modems, gateways, SIMs, VPN overlays, and vendor-managed remote access paths as production assets.
- Remove flat trust inside private APNs. Devices inside the same carrier/private wireless environment should not automatically be able to reach each other. Enforce explicit allowlists and deny peer-to-peer traffic by default.
- Harden cellular routers like edge firewalls. Disable unnecessary management services, restrict SSH/admin access, rotate default credentials, require MFA where supported, and log administrative activity centrally.
- Segment wireless from OT control. Treat private LTE/5G gateways as conduits into high-impact environments, not as trusted internal switches.
- Test manual operations and isolation plans. If a wireless segment or APN must be disconnected during an incident, operators should know what breaks, what stays online, and who has authority to make the call.
- Demand architecture evidence from providers. Ask carriers, managed service providers, and industrial vendors how tenant isolation, device-to-device communication, logging, and emergency shutdown procedures work.
Bulwark Black assessment
This is the same pattern defenders keep seeing across VPN appliances, service mesh control planes, RMM platforms, and now private wireless: the supporting connectivity layer becomes the real target. Attackers do not need to begin with a PLC exploit if the network architecture gives them a poorly monitored route to the systems that matter.
For organizations with OT, facilities systems, or remote infrastructure, private wireless should be reviewed as a control plane. The right question is not only “is the plant reachable from the internet?” It is “what trusted connectivity paths reach the plant, what can they talk to, and how would we detect misuse?”
Original reporting: Fierce Network — Utilities embrace private networks. Attackers are embracing them too.
Primary source: CERT Polska — Follow-Up Report of the December 2025 Energy Sector Incident
