Intelligence Journeys
AI Use Cases for Utilities
Private Broadband for Utilities

OneLayer Turns Real Cellular Threats Into Automatic Detections

OneLayer has turned four real-world attack patterns, including the December 2025 Polish power plant breach, into automatic detections inside OneLayer Bridge. See how the platform catches SIM spoofing, rogue modems, and unauthorized device connections before they become incidents, and check your own network's posture with TeckNexus's free OneLayer assessment tools.
OneLayer Turns Real Cellular Threats Into Automatic Detections

Private cellular networks are becoming a bigger target, and the threats hitting them are getting more specific to how these networks actually work. OneLayer, the cybersecurity and visibility layer for enterprise private cellular networks, has laid out four real-world threat patterns that its OneLayer Bridge platform now catches automatically, with nothing for customers to configure.

The approach behind these detections is straightforward: OneLayer’s team tracks disclosed attacks, tests them against the device and traffic data OneLayer Bridge already collects, and turns the ones that hold up into standing detections that roll out to every customer. Here is what that process has surfaced so far.

Four Private Cellular Threats OneLayer Bridge Detects Automatically

Each detection below maps to a real alert inside OneLayer Bridge. The screenshot shows what one looks like in practice: a device-to-device SSH connection flagged the moment it happens, with the source and destination devices identified by IMEI and IP so a security team can act immediately.

Private APN Security: Detecting East-West Lateral Movement

 The clearest example is the December 2025 attack on a Polish combined heat and power plant serving roughly 50,000 residents. Attackers pivoted from an unrelated wind farm through SSH tunnels opened across a shared private APN. OneLayer published a technical breakdown the same day CERT Polska released its follow-up report, on August 11, 2026, ahead of the mainstream security press. OneLayer Bridge’s Observe pillar flags that same east-west SSH activity the moment a tunnel opens.

FCC Covered List Cellular Modems: Automatic Flagging

As the Covered List grows and federal scrutiny of certain overseas cellular hardware manufacturers keeps expanding, a provisioned device can no longer be assumed trustworthy. OneLayer Bridge fingerprints the make, model, and chipset of every device it onboards, and flags any modem from a manufacturer on the Covered List the moment it is seen or the list changes.


IMEI Spoofing Detection: Catching Fake Device Identities

Research this month showed a malicious SIM card can run commands directly on a device’s modem, demonstrated against EV chargers, industrial routers, and telematics units built on widely deployed cellular modem chipsets. It is the same identity layer behind OneLayer’s IMEI spoofing detection: a device presenting an identifier that is not its own. OneLayer Bridge fingerprints every device against its known identity, so a spoofed or swapped identifier is flagged on connection.

Industrial Cellular Router Vulnerabilities: Unauthorized Device Migration

Newly disclosed vulnerabilities in industrial cellular routers, widely used across utilities and manufacturing, would let an attacker remotely impersonate a legitimate device. It is the scenario OneLayer customers ask about most: a device shows up behind a different router than the one it was onboarded on, intentional or not. OneLayer Bridge fingerprints every device against the router it is onboarded on, so that migration is flagged the moment it happens.

Why Automatic Threat Detection Matters for Private Cellular Security

“Every one of these threats comes at the enterprise from a different direction: the SIM, the modem, the router, the traffic moving between devices. What enterprises need is one layer of protection across the whole cellular estate,” said Dave Mor, CEO, OneLayer. “That layer is built on data that is hard to bring together: signaling, the core, the routers, and the devices themselves, fused into a single picture.”

“Every one of these detections started the same way: our team spotted a pattern and validated that OneLayer Bridge could already see it, using the device fingerprinting and traffic visibility built into the platform,” said Liron Ben-Horin, VP of Systems Engineering, OneLayer. “That is the value we bring: cellular domain expertise and a research process that keeps running, so customers are not the ones who have to catch the next one.”

All four detections are live today for every OneLayer Bridge customer, with no new hardware or configuration required, and the detection library keeps growing as new patterns emerge.

What This Means for Enterprise Private 5G Security

The pattern across all four detections is the same: private cellular has its own attack surface, distinct from traditional IT and OT security, and it needs visibility purpose-built for it. Device identity, modem provenance, onboarding relationships, and east-west traffic between cellular-connected assets are not things a standard network security stack was designed to watch.

For enterprises running or planning private cellular deployments, the practical next question is where their own network stands today. That is exactly what TeckNexus and OneLayer built the following assessments to answer.


Assess Your Private Cellular Network Security with OneLayer and TeckNexus

TeckNexus has partnered with OneLayer to offer two free, self-service assessment tools that help enterprises benchmark their private cellular security and onboarding posture against the patterns described above.

OneLayer Device Onboarding Assessment Evaluate how devices are provisioned and onboarded onto your private cellular network, and identify gaps that could let an unauthorized or misconfigured device slip through.

OneLayer Security & Asset Assessment Get a snapshot of your network’s asset visibility and security posture, covering the kind of device fingerprinting, identity verification, and traffic monitoring gaps that the threats above are built to exploit.

Partner Hubs

Download content, access intelligence tools, and hear from executives.

Partner Events

  • M360 ASEAN
  • FutureNet Asia 2026
  • Network X Vienna 2026
Scroll to Top