ACE Cybersafe organized a hackathon on 4/6. We had five participants who were divided into two teams.
Our hackathon ran from early morning until late evening on Thursday, June 4th at LTU in Skellefteå. We had invited master’s students and other interested parties to collaborate and experiment with performing cyberattacks against our digital twin of the ACE building. The participants were given ”coffee”, lunch and dinner during the day.
The focus of our hackathon was to attack the digital infrastructure of the ACE Powerhouse. Since the building is not yet finished, we had built digital twins that simulated the energy system in the building.
The participants were given prepared exercises to break into their digital twin. The winning team was the one that needed the fewest clues to complete the task.
The winners were
Team Editha & Laud, which consosted of Editha Thomas Chitukuro and Laud Onumah.
Link to video clips from the hackathon.
Hackathon Scenario
A municipal smart-building operator has requested a security assessment of a Building Management System (BMS) used to monitor and control critical building services. The facility consists of a hierarchical architecture with a management layer, automation layer, and field layer. The environment includes a Building Management System, HVAC controllers, sensors, actuators, and supporting network infrastructure.
A recent internal audit identified several potential weaknesses in the deployment, including legacy authentication mechanisms, weak password practices, insecure service configurations, and insufficient network segmentation. The organization has therefore authorized a controlled penetration test to evaluate the security posture of the environment.
Your team has been tasked with conducting a security assessment of the deployed system. The objective is to identify weaknesses, demonstrate the potential impact of successful compromise, and document how an attacker could move through the system from initial access to manipulation of operational technology assets.
Assessment Objectives
The assessment will be performed in several phases.
Phase 1 – Initial Access
The building network includes a wireless access point used for maintenance operations. During a security review, it was discovered that weak password policies may be in use.
The objective of this phase is to gain access to the management network and identify externally reachable services.
Success criteria:
- Obtain access to the wireless network.
- Identify accessible network services.
- Discover a management firewall that protects the Building Management System network.
Phase 2 – Perimeter Assessment
The firewall is intended to protect the management layer from unauthorized access. However, previous assessments suggested that administrative services may still be exposed.
The objective of this phase is to evaluate the security of the firewall and determine whether administrative access can be obtained.
Success criteria:
- Identify exposed services.
- Gain administrative access to the firewall.
- Enumerate connected hosts and network relationships.
- Identify systems communicating with the firewall.
Phase 3 – BMS Discovery
Once access to the perimeter device has been obtained, the next task is to identify critical management systems operating within the protected network.
The objective of this phase is to locate the Building Management System and assess its security configuration.
Success criteria:
- Identify the BMS host.
- Discover available management interfaces.
- Evaluate authentication mechanisms.
- Access the BMS management interface and inspect available operational data.
Phase 4 – BMS Compromise
The security assessment has revealed indications that default credentials may still be active.
The objective of this phase is to evaluate the consequences of unauthorized administrative access.
Success criteria:
- Obtain administrative access to the BMS.
- Access the underlying operating environment.
- Enumerate files and services available on the system.
Phase 5 – Topology Recovery
The organization stores infrastructure information within the BMS. Security controls have been implemented to protect sensitive topology information.
The objective of this phase is to determine whether protected engineering information can be recovered.
Success criteria:
- Locate the encrypted topology file.
- Analyze the protection mechanism.
- Recover and inspect the stored topology information.
- Identify network relationships between management, automation, and field devices.
Phase 6 – Automation Layer Impact Assessment
Following compromise of the BMS, the next objective is to determine whether operational systems can be influenced.
The assessment focuses on the HVAC infrastructure within the automation layer.
Success criteria:
- Identify the ventilation controller.
- Demonstrate the ability to influence ventilation operations.
- Assess operational impact and document consequences.
Phase 7 – Field Layer Manipulation
The final phase examines the security of sensors and field devices connected to the automation network.
The objective is to evaluate whether compromised management systems can affect field-layer information.
Success criteria:
- Identify field devices and sensors.
- Modify a sensor value within the simulated environment.
- Demonstrate how manipulated sensor data propagates through the system.
- Trigger a simulated fire-alarm condition and document the resulting behavior.
Deliverables
Each team shall submit:
- A description of the attack path used.
- Evidence collected during each phase.
- Vulnerabilities identified.
- Operational impact assessment.
- Recommendations for mitigation and system hardening.
The final report should explain how weaknesses in authentication, network segmentation, service exposure, and operational technology security can enable an attacker to move from initial access to control of building infrastructure.
This version reads like a realistic penetration-testing assignment and emphasizes the learning objectives:
- reconnaissance,
- authentication weaknesses,
- lateral movement,
- OT/BMS security,
- encrypted data recovery,
- operational impact,
- and mitigation recommendations.







