A recent cyber attack on a Polish combined heat and power plant exploited a Fortinet device and a private Access Point Name (APN) to bridge the gap between information technology (IT) and operational technology (OT) systems. The attackers successfully reached programmable logic controllers (PLCs) and disrupted critical systems, including turbine and water treatment operations. This incident, documented by Poland's Computer Emergency Response Team (CERT), marks a notable example of adversaries leveraging a private APN as an entry point, a tactic not previously observed by CERT. The attack's impact on a facility serving approximately 50,000 residents underscores the potential consequences of such breaches1. The involvement of a Fortinet device in this incident may have broader implications, potentially influencing regulatory and supply-chain decisions. So what matters to practitioners is that this attack demonstrates how conventional network designs can be repurposed as a vulnerability, highlighting the need for robust security measures across both IT and OT domains.