Uploaded April 2026 | Updated September 2026, 1 week ago
In 2024, Operation Grim Beeper involved exploding pagers to kill or injure their owner. This was followed by a wave of exploding walkie-talkies distributed across the same networks. This was definitely a cyber-physical attack.
While the operation has been widely covered in media circles, Raphael reviewed the leading theories and distill the OT security lessons they reveal. This sophisticated attack bypassed the traditional defenses by embedding itself in the physical layer. From supply chain insertion and form factor deception, to air-gap evasion and physical-layer trust violations, the incident forces us to reevaluate the security of devices we have long overlooked.
As part of this session, a safe, inert simulation of the triggering mechanism is investigated. This case study challenges our OT / ICS Security Community to expand its threat models to include the physical devices we trust by default, and consider where that trust might break down.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x27. Feb 8 - 11 in Tampa:
[https://s4xevents.com](https://s4xevents.com/)
In 2024, Operation Grim Beeper involved exploding pagers to kill or injure their owner. This was followed by a wave of exploding walkie-talkies distributed across the same networks. This was definitely a cyber-physical attack.
While the operation has been widely covered in media circles, Raphael reviewed the leading theories and distill the OT security lessons they reveal. This sophisticated attack bypassed the traditional defenses by embedding itself in the physical layer. From supply chain insertion and form factor deception, to air-gap evasion and physical-layer trust violations, the incident forces us to reevaluate the security of devices we have long overlooked.
As part of this session, a safe, inert simulation of the triggering mechanism is investigated. This case study challenges our OT / ICS Security Community to expand its threat models to include the physical devices we trust by default, and consider where that trust might break down.
Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x27. Feb 8 - 11 in Tampa:
[https://s4xevents.com](https://s4xevents.com/)










