# State-Sponsored Actors Target Polish Water Infrastructure in Escalating Campaign Against Critical Systems


Poland's water treatment facilities have become the latest casualties in an intensifying cyber campaign against critical infrastructure, with government investigators revealing that attackers have successfully breached industrial control systems at five separate municipalities and gained the ability to manipulate equipment parameters that directly affect public water supply.


The Polish Internal Security Agency (ABW) documented these intrusions as part of a troubling trend throughout 2024 and 2025, where sophisticated threat actors—primarily attributed to Russian and Belarusian-linked groups—have systematically targeted operational technology (OT) infrastructure across the country. What distinguishes these attacks from typical corporate breaches is their potential for physical disruption: compromised systems could allow adversaries to degrade or disable essential utilities that millions of citizens depend on.


## The Threat


Between 2024 and 2025, ABW identified confirmed security breaches at water treatment stations in five Polish municipalities: Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. In multiple instances, attackers achieved direct access to industrial control systems and obtained the capability to modify operational parameters of critical equipment.


The implications are severe. Unlike traditional IT breaches that compromise data, successful manipulation of water treatment equipment could:


  • Disrupt service delivery — Alter chemical dosing, pressure settings, or flow rates, potentially causing water outages across affected regions
  • Degrade water quality — Modify treatment parameters in ways that affect public health
  • Create cascading failures — Compromise downstream systems in municipal infrastructure
  • Undermine public confidence — Generate panic even if attacks are detected before physical harm occurs

  • One previously unreported incident from August 2025 underscores the severity: Polish officials disclosed that a cyberattack on water infrastructure had the potential to deprive an entire city of water supply before being thwarted. No technical details were released at the time, but ABW's new report suggests this was not an isolated case.


    ## Background and Context


    Poland has emerged as a primary target for state-sponsored cyber operations, particularly from Russian intelligence services and their proxies. The water treatment breaches represent an escalation in targeting patterns that extends well beyond the water sector.


    ABW's investigation reveals that attackers have systematically compromised:


  • Municipal water systems across multiple Polish cities
  • Wastewater treatment plants
  • Waste incineration facilities
  • Energy infrastructure (in coordination with Russia-linked campaigns documented in 2024-2025)
  • Critical supply chains supporting these sectors

  • The surge in attacks correlates with a documented increase in aggression from state-sponsored threat actors, particularly following geopolitical tensions between Poland and Russia. Previous incidents include:


    | Target | Date | Actor |

    |--------|------|-------|

    | Polish Energy Sector | 2024-2025 | Russia-linked groups |

    | Polish Space Agency | 2025 | Unknown (suspected state-sponsored) |

    | Nuclear Research Center | 2025 | Unknown |


    ABW attributes primary responsibility to the following threat actors:


  • APT28 (Fancy Bear) — A Russian military intelligence-linked group with a documented history of targeting critical infrastructure
  • APT29 (Cozy Bear) — A Russian foreign intelligence service group known for sophisticated, long-term intrusions
  • UNC1151 — A Belarusian-linked threat collective with connections to state security services

  • These groups often operate under hacktivist personas or use false flags to obfuscate attribution, making it difficult for defenders to recognize state involvement in individual incidents.


    ## Technical Details


    The breaches exploited two fundamental and longstanding failures in operational technology security: weak password policies and internet-exposed systems.


    ### Weak Password Hygiene


    ICS environments frequently run on legacy equipment with default credentials or poorly managed password policies. The investigation revealed that multiple water treatment facilities utilized weak, predictable, or reused passwords across administrative accounts. In some cases:


  • Default manufacturer credentials remained active
  • Password rotation policies were absent or infrequently enforced
  • Administrative accounts lacked complexity requirements
  • Credentials were shared across multiple systems or staff members

  • While these failures are well-documented in OT security literature, implementation gaps persist across the industry—particularly at municipal facilities operating with limited IT budgets and technical expertise.


    ### Internet-Exposed Assets


    Perhaps more concerning, ABW found that ICS systems at some facilities were directly accessible from the internet without intermediary security controls. This represents a critical deviation from OT security best practices, which mandate:


  • Air-gapping critical systems from external networks
  • Implementing demilitarized zones (DMZs) between IT and OT environments
  • Deploying secure remote access solutions (VPNs, jump servers) rather than direct internet exposure

  • Direct internet exposure enables attackers to discover vulnerable systems using automated scanning tools (such as Shodan) without requiring initial network compromise. The combination of internet access and weak authentication created what security researchers describe as a "trivial" entry vector.


    ### Supply Chain Intelligence Gathering


    Beyond direct ICS intrusions, ABW documented that attackers targeting supply chains specifically sought:


  • Contract data — Information about maintenance schedules, system vendors, and service providers
  • Project documentation — Details about infrastructure design, equipment specifications, and operational procedures
  • Authentication credentials — Access tokens, API keys, and administrative credentials for downstream systems

  • This pattern suggests adversaries are conducting reconnaissance to build comprehensive intelligence about Polish critical infrastructure, enabling more sophisticated future attacks.


    ## Implications for Critical Infrastructure Defense


    These breaches expose a fundamental vulnerability in how Poland (and many developed nations) protect essential services. The water sector represents a particularly sensitive target because:


    Public Safety Impact: Unlike financial institutions or communications networks, water treatment directly affects immediate health and safety. Contaminated water supplies can sicken thousands within hours.


    Detection Challenges: Attacks on ICS are harder to detect than traditional IT intrusions because defensive monitoring is less mature. Many facilities lack the visibility to identify when equipment parameters have been remotely modified.


    Geopolitical Escalation: The attribution to Russian and Belarusian state actors suggests these are not profit-motivated criminal campaigns but rather strategic reconnaissance for potential wartime disruption. Water supply systems have historically been military targets, and cyber access provides a lower-risk method of achieving similar effects.


    Cascade Effects: Poland's infrastructure is interconnected; compromise of water treatment can affect energy systems, hospitals, and other critical services that depend on reliable water supplies.


    ## Recommendations for Defenders


    Organizations responsible for critical infrastructure should implement the following measures immediately:


    Immediate Actions:

  • Conduct comprehensive inventory of all internet-connected ICS assets using external scanning tools
  • Implement network segmentation to isolate OT systems from IT networks and the internet
  • Enforce multi-factor authentication on all administrative accounts
  • Change all default credentials and implement complex password policies
  • Deploy intrusion detection systems (IDS) specifically tuned for OT protocols

  • Medium-Term Improvements:

  • Implement zero-trust architecture principles in OT environments
  • Deploy remote access solutions (jump servers, VPNs) rather than direct internet exposure
  • Establish security operations centers (SOCs) with OT-specific monitoring capabilities
  • Conduct regular penetration testing of ICS environments
  • Implement asset management and change control processes

  • Long-Term Resilience:

  • Develop incident response plans specific to ICS compromise scenarios
  • Train operators on security fundamentals and social engineering risks
  • Coordinate with government agencies on threat intelligence sharing
  • Invest in next-generation ICS equipment with security-by-design principles
  • Establish redundancy and manual override capabilities for critical functions

  • ---


    ## HackWire Analysis


    The Polish water treatment breaches represent a watershed moment—quite literally—in the evolution of state-sponsored cyber operations. For years, critical infrastructure security experts have warned that ICS attacks remained theoretical or limited to espionage. These incidents confirm that advanced state actors now possess both the capability *and demonstrated willingness* to compromise systems that directly control public safety.


    What's alarming isn't the sophistication of the attacks—weak passwords and internet exposure are remedial security failures. Rather, it's the systematic targeting pattern across multiple municipalities and sectors within a single nation, suggesting adversaries are building an operational blueprint of Polish critical infrastructure. The supply chain reconnaissance component indicates they're not just looking for one-off access; they're mapping vulnerabilities across entire sectors to enable coordinated future operations.


    The timing matters: these breaches occurred amid ongoing Russian military aggression in Ukraine, where cyber operations have preceded and complemented kinetic attacks. The targeting of Poland—a NATO member and critical supply route to Ukraine—suggests Russia is potentially pre-positioning for escalation scenarios where sabotaging Polish infrastructure could achieve strategic military objectives.


    For defenders, the most sobering insight is that asset exposure, not advanced exploitation techniques, enabled compromise. This is not a case of zero-day exploits or sophisticated lateral movement. The water plants were accessed because they were directly connected to the internet with weak passwords. This is achievable by script-kiddies and nation-states alike. The difference is intent: while criminals might lock systems for ransom, nation-states can leave access dormant until needed for strategic purposes—which is arguably more dangerous.


    Organizations must recognize that ICS security is no longer an optional operational consideration; it's a geopolitical imperative. The window for remediation is narrow.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)