The Turbine Stopped. The Network Was Private.
# The Turbine Stopped. The Network Was Private.
The most interesting failure of the day didn't happen in a cloud instance or a corporate mail server. It happened in Poland, where an attacker managed to shut down a steam turbine at a power plant. The elegance of the move was almost admirable: they didn't go through the front door. Instead, they pivoted from a compromised wind farm via a private cellular network to reach the plant's controls.
It is a lovely bit of irony. We spend millions on "private" networks under the assumption that isolation equals security. In reality, a private network is often just a smaller room with a different set of keys, and if you can get into the wind farm, you've already found the corridor to the turbine. The paperwork for this one will be fascinating. I suspect the post-incident report will spend a great deal of time arguing over whether the cellular network constituted a "perimeter" or an "internal segment," because the regulatory fines usually hinge on which definition wins the argument.
While Poland deals with its turbines, the rest of us are watching a coordinated effort to turn our basic utilities into ransomware play-grounds. The wire is currently dominated by Gunra ransomware, a group that seems to have developed a particular fondness for critical infrastructure. They aren't using some sophisticated, bespoke zero-day; they're simply exploiting known bugs in Fortinet and Schneider Electric products.
The FBI and South Korean authorities have issued warnings, and CISA has done the same. To the uninitiated, a CISA warning looks like a shield. To those of us who follow the machinery of regulation, it looks like a liability shift. By issuing a public warning about Fortinet vulnerabilities, the government effectively moves the needle from "systemic failure" to "negligence" for any operator who fails to patch.
This coincides with reports of suspected Iranian nation-state actors targeting water systems across multiple US states. When you combine state-sponsored probing with the opportunistic hunger of Gunra, you get a very precarious situation for municipal governments. Most of these water districts are run by people whose primary expertise is hydraulics, not packet inspection. They aren't reading CISA directives in real-time; they're reading them three weeks later when their vendor tells them there's a "maintenance window" required.
The sector data reflects this tension. Technology remains the most targeted area, ranking #1 of 17 sectors this week with 424 stories recorded. Government follows at #2 with 238 stories, and Healthcare sits at #3 with 108. The gap between the "Technology" target and the "Government/Infrastructure" target is shrinking because the tools are now standardised. Gunra isn't inventing new ways to break in; they're just using a map that's already been published.
I maintain that the current model of "warn and hope" is fundamentally broken. A warning is not a remediation strategy. Until there is a regulatory mechanism that mandates patching timelines for critical infrastructure, with fines that actually outweigh the cost of downtime, we are simply documenting the decline in real-time. In Brussels, there have been whispers about stricter enforcement under NIS2, but as always, the distance between a directive and a functional firewall is vast.
Then we have the data side of the house, which remains as predictably miserable as ever. DentaQuest has reported a breach exposing the personal information of approximately 15 million people. This is one of the largest exposures recorded this year.
From a regulatory perspective, the scale here is almost secondary to the timing. With 15 million records gone, the notification process becomes a logistical nightmare. Under most current frameworks, the clock starts ticking from the moment of discovery, not the moment of the breach. I imagine the legal teams at DentaQuest are currently spending their afternoons calculating exactly how many days they can lean on the "forensic investigation" excuse before the regulators decide they've been too quiet.
The second-order effect here isn't just about the 15 million individuals who now have to monitor their credit reports. It's about the insurance providers. We are entering a cycle where cyber insurers will stop covering "known vulnerabilities" entirely. If you're hit by Gunra via a Fortinet flaw that CISA warned about four days prior, your insurer isn't going to see an unfortunate accident; they're going to see a breach of contract. We've seen this happen in the fire insurance market: if you don't have a working sprinkler system, the policy is void. We are rapidly approaching the "digital sprinkler" era of cybersecurity insurance.
The most frustrating part of today's wire is the repetition. We see the same pattern: a vendor releases a patch, attackers weaponise the flaw within hours, and the victims are identified by their sector rank on a spreadsheet. The Technology sector's 424 stories this week aren't just numbers; they represent a systemic failure to decouple critical functions from fragile edges.
One might argue that we can't possibly patch everything instantly, as the sheer volume of alerts is overwhelming for any mid-sized IT team. That is true, but it's an excuse for the operator, not a justification for the status quo. The objection is usually that "regulation stifles innovation." I would counter that there is very little innovation in getting ransomed via a three-month-old firewall bug.
If I were to bet on what changes my mind about this trajectory, it wouldn't be another CISA warning or a new FBI bulletin. It would be a fine so large that it forces a board of directors to actually understand what a "critical vulnerability" is. Until the cost of negligence exceeds the cost of competence, we will keep seeing steam turbines shut down via wind farms and millions of dental records leaked into the wild.
For now, the paperwork continues. The notification letters are being drafted, the forensic firms are billing by the hour, and the water utilities are hoping their Fortinet boxes aren't on the wrong side of a Gunra scan.
I'll be watching to see if any of the affected water districts actually report their patching status to the public. I suspect they won't. It's much easier to file a report saying you've "implemented enhanced security measures" than it is to admit you're still running firmware from 2024.
◼