Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptionoperational-disruptionindustrial-control-system-vulnerability

Poland Water Plant Breaches Spur Broader Critical Infrastructure Resilience Push

Updated 1mo agoFirst seen Apr 15, 20267 sources

Poland’s Internal Security Agency said hackers breached five water treatment plants and could potentially have taken control of industrial equipment, raising the risk of compromised water safety and possible physical harm. The incidents were disclosed alongside a wider warning that sabotage campaigns targeting Polish military sites, civilian entities, and critical infrastructure pose an immediate threat, while Sweden separately reported that suspected pro-Russian hackers attempted to disrupt a thermal power plant but were stopped by built-in protections. Officials in both countries described the activity as part of a broader pattern of increasingly aggressive attacks on operational technology across Europe, particularly against infrastructure in countries supporting Ukraine.

In the United States, the disclosures add urgency to CISA’s new CI Fortify initiative, which tells critical infrastructure operators in sectors including water, energy, transportation, and communications to prepare to keep essential services running for weeks to months while isolated from business networks, vendors, and telecom providers. CISA said the program is designed for scenarios in which attackers may already have access to OT environments and foreign adversaries are prepositioned inside U.S. infrastructure, with guidance focused on isolating control systems, maintaining offline and manual operations, and rehearsing recovery through tested backups, documentation, and component replacement plans.

Share:
Poland Water Plant Breaches Spur Broader Critical Infrastructure Resilience Push
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 8, 20262mo ago

ABW linked Poland water-plant breaches to APT28, APT29, and UNC1151

Poland's Internal Security Agency attributed the 2025 compromises of five water treatment plants to Russia-linked APT28 and APT29 and to Belarusian-aligned UNC1151. The agency said the intrusions were enabled by internet-exposed management interfaces and weak passwords, not advanced zero-day exploits.

Cyberattacks on Poland's Water Plants: A Blueprint for Hybrid Warfare - Security Affairs

Poland published a two-year threat report on sabotage attempts

Poland's Internal Security Agency released a broader report saying it had thwarted multiple sabotage operations attributed to Russian spies and hackers targeting military facilities, critical infrastructure, and civilian entities. The agency warned that such attacks posed a real and immediate threat and could have caused fatalities.

Poland detected intrusions at five water treatment plants

Poland's Internal Security Agency said attackers breached five water treatment plants and could potentially have taken control of industrial equipment, creating a worst-case risk to water safety. The agency presented the incidents as part of a broader pattern of hostile activity against Polish critical infrastructure.

May 5, 20262mo ago

CISA urged operators to plan for weeks or months in isolation

As part of CI Fortify, CISA publicly called on critical infrastructure owners to prepare to operate while disconnected from business IT, vendors, and telecom dependencies for extended periods during conflict or major cyberattack. The guidance emphasized backups, documentation, component replacement rehearsals, and manual operations to sustain service continuity.

CISA launched the CI Fortify initiative

CISA rolled out CI Fortify to help critical infrastructure operators maintain essential services during severe cyber incidents by focusing on OT isolation and recovery. The initiative includes pilot assessments and planning support for sectors such as water, energy, transportation, and communications.

Apr 15, 20262mo ago

Sweden publicly disclosed the 2025 power plant intrusion attempt

Swedish civil defense minister Carl-Oskar Bohlin said a suspected pro-Russian hacker group had attempted to breach a thermal power plant in western Sweden in spring 2025. Officials framed the case as part of a broader trend of increasingly destructive cyber operations against European critical infrastructure.

Apr 1, 20251y ago

Hackers attempted to breach a Swedish thermal power plant

In spring 2025, a suspected pro-Russian group tried to disrupt a thermal power plant in western Sweden, but built-in protections prevented the intrusion from succeeding. Sweden's security service investigated and linked the perpetrators to actors believed connected to Russian intelligence services.

Jan 1, 20233y ago

CyberAv3ngers targeted U.S. water utilities

In 2023, the Iranian-linked CyberAv3ngers group conducted intrusions affecting U.S. water infrastructure, reinforcing concerns that foreign state-backed actors were targeting internet-exposed industrial control systems. The activity was later cited alongside broader federal warnings to the sector.

Feb 5, 20215y ago

Hackers remotely altered controls at Oldsmar water plant

An intruder accessed the Oldsmar, Florida water treatment facility and changed chemical settings, demonstrating the real-world risk of cyber compromise to water safety. The incident later became a prominent example cited in warnings about water-sector cyber threats.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Malware
1 linked
Organizations
8 linked
Nozomi NetworksElisitySTVTechCrunchSANS InstituteSecurity AffairsKochavaXage Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.