🔴 [LATEST] IRAN DEPLOYS 2 CYBER FRONTS: HANDALA TARGETS ISRAEL, CYBERAV3NGERS TARGETS US    ◆    🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS

~/Threat Intelligencearticle

Threat Intelligence

NoName057(16) Targets Romania: Claims Breach of RCN Solutions HMI at Major Glass Factory

> By Haider | Aug 04, 2026 | 4 min read

The pro-Russian hacktivist group NoName057(16) has announced a new cyberattack targeting critical industrial infrastructure in Romania. In a recent manifesto published on their Telegram channel, the group claims to have obtained full administrative access to the control systems of Italian laminating furnaces manufactured by R.C.N. SOLUTION S.R.L. (RCN Solutions) at one of Romania’s largest glass production facilities. This incident, operating under the banner of #OpRomania, highlights the increasing intersection of geopolitical hacktivism and Industrial Control Systems (ICS) vulnerabilities.

NoName057(16)

> TABLE_OF_CONTENTS [toggle]

The Scope of the HMI Compromise

According to the evidence released by NoName057(16), the attackers successfully breached the Human-Machine Interface (HMI) governing the industrial equipment used for the production of laminated glass. The group asserts they have secured complete “admin rights” over the targeted infrastructure. in the field of Operational Technology (OT), an HMI compromise of this depth grants the intruder dangerous capabilities to manipulate physical manufacturing processes.

The threat actors specifically listed the parameters they now control, which include manipulating glass recipes, altering vacuum settings, adjusting core furnace temperatures, and managing overall production cycles. In addition, they claim to have the ability to execute password changes, effectively locking legitimate operators out of the control panel. By disrupting these precise environmental controls, attackers can cause significant physical damage to the materials, the machinery, or force an extended operational halt.

Operational Impact and NATO Allegations

The immediate operational impact of this breach appears to be a complete halt in production. NoName057(16) proudly declared that “the ovens are idle” and “the cycles are blocked.” They highlighted a specific error state on the control interface: “CICLO NEGATO FORNO APERTO” (Cycle Denied, Oven Open), using it as a symbolic representation of their successful sabotage. By forcing the furnace into an open and denied state, the attackers ensure that the lamination process cannot proceed safely or effectively.

In a move typical of state-aligned hacktivist propaganda, the group justified their attack by claiming the targeted Romanian facility manufactures glass for NATO facilities. The manifesto stated: “While they glue glass for NATO facilities, we enter their ovens as if they were our own home.” This rhetoric aims to frame the industrial sabotage as a legitimate retaliation against the European Union and NATO allies, aligning with the group’s broader Russophobic narrative and their ongoing recruitment drive for the DDoSia Project.

Vulnerabilities in Industrial Control Systems

This incident involving RCN Solutions’ equipment underscores a chronic vulnerability within modern manufacturing environments: the exposure of legacy or poorly secured ICS and OT assets to the public internet. While R.C.N. SOLUTION S.R.L., headquartered in Albairate, Italy, manufactures highly specialized glass laminating machinery, the responsibility for securing the deployment of these systems typically falls on the facility operators. Frequently, HMIs are connected to corporate networks or left accessible remotely without robust multi-factor authentication (MFA) or proper network segmentation.

When hacktivist groups pivot from their traditional Distributed Denial of Service (DDoS) campaigns to exploiting OT vulnerabilities, the risk profile for targeted nations escalates dramatically. Unlike a website defacement, manipulating temperature and vacuum controls in a glass furnace can lead to costly material wastage, prolonged downtime, and potential safety hazards for factory floor personnel.

Mitigation Strategies for OT Environments

To defend against groups like NoName057(16), organizations operating industrial equipment must adopt aggressive OT security postures. The primary defense is strict network segmentation; HMIs and Programmable Logic Controllers (PLCs) should never be directly accessible from the internet. All remote access must be routed through secure Virtual Private Networks (VPNs) heavily guarded by phishing-resistant MFA.

In addition, facilities must monitor OT network traffic for anomalous behavior, such as unexpected parameter changes or unauthorized administrative logins during off-hours. According to best practices established by the Cybersecurity and Infrastructure Security Agency (CISA), implementing continuous monitoring and maintaining offline backups of “known-good” configurations (such as glass recipes and cycle settings) are critical steps in ensuring rapid recovery from a cyber-physical sabotage event. Finally, operators should review similar ICS cyber threats to understand the evolving tactics of politically motivated threat actors.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

> INTELLIGENCE_NOTICE

The report above detailing NoName057(16) Targets Romania: Claims Breach of RCN Solutions HMI at Major Glass Factory is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Security Researcher & Malware Reverse Engineer specializing in deconstructing APT toolkits and validating underground breach claims.

> related_intel --suggest