decrypted · 12 august 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law
The Polish plant hack that proved the NCSC's new OT guidance right
This week Poland's national CERT published a forensic account of how attackers shut down a steam turbine at a heat-and-power plant serving around 50,000 residents, having walked in through a "private" mobile network nobody had treated as hostile. Days earlier, the NCSC quietly added its first worked example for the water sector to its secure connectivity principles for operational technology. Read together, they are the clearest Secure by Design lesson UK critical infrastructure operators will get this month: the guidance already exists, and here is what happens when the assumption behind it goes unchallenged.
How a wind farm became a way into a power station
On 29 December 2025, attackers broke into a Polish combined heat and power plant. CERT Polska's follow-up report, published this week, traces the path: a compromised firewall at a wind farm, then a cellular router onto a private APN, a dedicated mobile data channel normally reserved for one operator's own kit. The APN had no client isolation, so any device on it could reach any other. That let the attackers find a PLC at the heat plant still running default administrator credentials, bridge onto the operational technology network over SSH, then locate three further PLCs, switch them into STOP mode and password-protect them, halting the steam turbine and the water treatment system that makes process water. Staff restored the plant quickly enough that nobody lost heat, but CERT Polska called it the first real-world case of a private APN used as an attack path into critical infrastructure, and warned the same "trust the APN" configuration is common well beyond Poland.
What the NCSC is telling water and energy operators
The mistake was treating a private APN as safe simply because it was not the public internet, precisely the assumption the NCSC's secure connectivity principles for operational technology exist to correct: reduce what is exposed, centralise and monitor connectivity rather than letting individual sites bolt on their own routes, and treat every boundary, cellular or otherwise, as actively defended rather than inherited as trustworthy. This week's addition is a fictional case study of "Admin Corp Water" applying the eight principles to a legacy-heavy network, the first content the NCSC has co-authored with practitioners from its Industrial Control Systems Community of Interest. It is not dramatic reading, but it is concrete design guidance for people who actually run water and energy infrastructure. UK operators should read it against their own private APNs, cellular routers and remote access paths, especially with the Cyber Security and Resilience Bill continuing through Parliament, set to widen formal oversight of UK critical infrastructure operators. Nobody defends default credentials once they turn up in an incident report.
Also this week
TeamCity's build server, wide open. JetBrains patched a critical flaw in TeamCity On-Premises on 28 July; CISA added it to its exploited vulnerabilities catalogue a week later. CVE-2026-63077 sits in the agent polling protocol: an unauthenticated attacker with network access to a TeamCity server can trigger a deserialisation bug and run operating system commands as the server itself, no credentials needed. US federal agencies had until 8 August to patch; anyone running TeamCity On-Premises, a common choice in UK software teams' build pipelines, should treat that deadline as their own. A build server holds source code, secrets and release artefacts behind one login page; this is what happens when that page turns out not to be one.
A Windows zero-day, already in Lazarus's hands. Microsoft's August update round fixed hundreds of flaws, but one had already been found by North Korea's Lazarus group before the patch shipped. CVE-2026-68820, a use-after-free in the Windows networking driver afd.sys, was exploited to install an updated version of Lazarus's FudModule kernel rootkit, according to Check Point's research into the group's Operation Dream Job campaign. The lure is still a fake job offer; the payload now survives inside the kernel. Every UK organisation running Windows has this patch waiting.
Vishing gangs are calling UK finance staff directly. An extortion group tracked as UNC6671, formerly BlackFile, spent the summer phoning employees' personal mobiles, posing as IT helpdesk staff running an urgent passkey migration, and steering them to fake login pages that intercept passwords and one-time codes in real time. Google's Mandiant and SecurityWeek both link the group to attacks on financial services, private equity and law firms across North America, Australia and the UK, with ransom settlements averaging around three-quarters of a million dollars. The fix is not another awareness poster: it is phishing-resistant authentication, FIDO2 keys or passkeys bound to the real domain, so the fake one simply does not work however convincing the caller.
Sources
- Water sector example added to the NCSC's Secure connectivity principles
- Follow-up report of the December 2025 energy sector incident - CERT Polska
- Hackers breached a small Polish energy plant via private APN last year - BleepingComputer
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild - The Hacker News
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days - BleepingComputer
- Vishing Extortion Group UNC6671 Rebrands After Making Millions - SecurityWeek
If you want to talk through what Secure by Design means for your own systems, get in touch.
More like this
- MikroTik routers are being hijacked exactly as NCSC warned they would be 8 september 2026
- CrowdStrike's macro clean-up tool turns into a SYSTEM shell 5 september 2026
- The UK just gave ministers a veto over your suppliers 2 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.