Allied Intelligence — 2026-05-11

Polish Intelligence Agency Thwarts Cyberattacks on Water Treatment Plants

Poland's Internal Security Agency (ABW) reported ICS breaches at water treatment stations in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo during 2025, with attackers gaining access to operational controls capable of modifying equipment parameters. SecurityWeek, citing ABW's report, identified weak password policies and direct internet exposure as the primary intrusion vectors. ABW attributed the attacks primarily to hacktivist groups it characterized as personas for foreign governments, and the report specifically named Russian APT groups APT28 and APT29 and Belarusian-linked UNC1151 as operating against Polish targets. The agency also documented supply chain intrusions focused on obtaining contract data, project documentation, and authentication credentials enabling downstream system access.

Analysis
ABW's publication of specific municipal names and attack vectors signals deliberate pressure for sector-wide remediation. Attackers reaching ICS-level parameter control at five facilities held physical disruption capability, averted only by timely detection. Parallel supply chain intrusions using stolen credentials and project documentation reveal a campaign architected for persistence, though independent hacktivist actors without state direction remain viable given the vulnerabilities are longstanding and widely known. ABW names APT28, APT29, and UNC1151 as broadly active against Polish targets but stops short of state attribution for these breaches, a distinction with diplomatic and legal weight. Formal attribution within 60 days is unlikely: Warsaw gains solidarity leverage from naming Moscow but faces pressure to protect active counterintelligence work, per secondary outlets without corroboration.
2 sources
  1. Poland's intelligence agency thwarts cyberattacks on water treatment plants - SC World
  2. Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE