Adversary Intelligence — 2026-05-11

Poland Internal Security Agency Documents APT28 and APT29 Breaches of Five Water Treatment Plants

Poland's ABW published a report on May 9 documenting security breaches at five water treatment facilities in 2025, naming the affected sites as Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. In several cases, ABW reported, attackers gained access to industrial control systems and obtained the capability to modify device operating parameters in real time, which the agency described as a direct threat to water supply continuity. ABW attributed the campaign to APT28 and APT29, both identified as Russian-linked, and to UNC1151, a Belarusian-aligned group. The agency identified weak password policies and management interfaces exposed directly to the public internet as the enabling conditions.

Analysis
Per a single Security Affairs report on ABW's published findings, Poland's Internal Security Agency formally attributed sabotage-capable intrusions at five water facilities to APT28, APT29, and Belarusian-aligned UNC1151. That reverses prior reporting that named those groups for concurrent Polish operations while leaving the water breaches unattributed. The enabling conditions were basic failures: weak passwords and management interfaces exposed to the internet, with five dispersed compromises through identical vectors indicating a coordinated rather than opportunistic campaign. ABW's attribution may overstate operational integration with named services if lower-tier proxies were the operators. Comparable operations against European water or OT infrastructure are likely through the remainder of 2026, and equivalent security failures remain endemic across the sector.
1 sources
  1. Cyberattacks on Polands Water Plants: A Blueprint for Hybrid Warfare - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE