KRONOS ELITE

Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare

Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare
  • By @securityaffairs, Pierluigi Paganini
  • Security
  • 08 May 2026

Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare

Poland’s Internal Security Agency (ABW) has published a detailed account of a sustained campaign targeting the country’s water plants, documenting security breaches at five water treatment facilities in 2025. The incidents mark one of the clearest documented cases in Europe of state-linked hackers gaining direct access to industrial control systems managing public water supplies. The affected facilities were located in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. In several cases, attackers didn’t just observe, they obtained the ability to modify operational parameters of equipment in real time, creating a direct and concrete risk to the continuity of public water services. A breach of this kind isn’t a data theft. It is the digital equivalent of sabotage. “In some cases, the attackers gained access to industrial control systems and obtained the capability to modify device operating parameters.” reads the report published by ABW. “This created a direct threat to the continuity of water supply processes and the proper functioning of municipal infrastructure.” The attack vectors ABW identified are as unglamorous as they are alarming: weak password policies and systems left directly exposed to the internet. These are not sophisticated zero-day exploits. They are basic security failures that the OT and ICS security community has been warning about for years. “The incidents were made possible by inadequate security measures, including weak password policies and the exposure of management interfaces directly to the public internet.” continues the report. “In several cases, systems responsible for operational technology were accessible without sufficient protection mechanisms.” The attribution points firmly eastward. ABW identified Russian APT groups APT28 and APT29, the same actors linked to election interference across Europe and the SolarWinds supply chain attack, as well as UNC1151, a Belarusian-aligned group previously connected to the Ghostwriter operation targeting NATO countries. “APT28, APT29 and UNC1151 are among the most active state-linked cyber espionage groups operating against European targets.” concludes the report. “Their activities combine intelligence collection, disruptive cyber operations and coordinated information warfare campaigns.”

Related Briefings

  • Weapons
  • By @kazinform_eng
  • 19 Jul 2026

2 tankers carrying Kazakh oil attacked by drones at CPC terminal

At the Marine Terminal of the Caspian Pipeline Consortium (CPC), two tankers carrying Kazakh oil were struck by drones, forcing a suspension of loading operatio...

Read More
  • Weapons
  • By Caliber.Az
  • 19 Jul 2026

Drone attack hits CPC’s oil terminal, halting crude shipments

July 2026 13:26 The marine terminal of the Caspian Pipeline Consortium (CPC) came under a drone attack, the consortium said. According to the CPC, oil loading o...

Read More

Iran targets military bases as US launches wave of strikes

minutes agoElla KiplingReutersThe US and Iran have continued to exchange fire as negotiations stallTehran has launched fresh attacks on US military bases in nei...

Read More
  • Weapons
  • By Ramisha Ali
  • 15 Jul 2026

US strikes Iranian missile sites as tensions escalate

The United States has launched fresh strikes on Iranian missile and coastal defense sites after reinstating a naval blockade. Iran responded by warning it could...

Read More