Polish ABW report confirms ICS breaches at five water treatment plants
- Event Year
- 2025
- Reliability
- Confirmed
- Country
- Poland
- Industry
- Water and Wastewater Systems
- Attack Type
- Targeted Attack
Description
In 2025, attackers breached systems at at least five Polish water treatment stations by logging into management interfaces that were reachable from the public internet and protected by weak password practices. Poland's Internal Security Agency (ABW) disclosed the incidents in its 2024-2025 Selected Activities report, published May 6, 2026. The report named Szczytno, Jabłonna Lacka, Małdyty, Tolkmicko, and Sierakowo as affected facilities, and stated that in some cases attackers reached industrial control systems and could alter device parameters.
CyberDefence24 reporting provides the granular facility detail behind several of the public claims. At Szczytno in May 2025, a pro-Russian group published footage of access to a waterworks control environment; CSIRT NASK had also warned of water-service problems in the town, although public reporting did not conclusively assign those problems to the cyber incident. At Jabłonna Lacka in September 2025, reporting and expert review of video evidence described an administrator session in which the attacker changed alarm, pump, and filter settings. Industrial Cyber reported tank-level changes of 11 cm and 9 cm during the observed session. ABW also described an August 2025 attack on an unnamed Polish city water system that could have interrupted water supply but was stopped before public disruption.
The incidents did not involve published malware, CVEs, or protocol exploitation. The public record describes credential abuse against exposed management panels and HMIs, followed by direct changes through existing control interfaces. ABW placed the incidents in a broader 2024-2025 threat environment involving intensified foreign intelligence activity, especially Russian services. Secondary reporting linked some water-sector activity to pro-Russian hacktivists, but ABW did not publicly attribute the five water-plant breaches to a specific group or country.
Impact
Confirmed access to water-treatment control environments and active parameter manipulation occurred at multiple Polish facilities. No public source reviewed confirmed an end-user outage caused by the named cyber incidents. ABW described direct risk to operational continuity and public water supply, and reported a separate August 2025 near-miss in which attackers could have caused loss of water supply to an unnamed city. Financial impact and recovery timelines were not publicly disclosed.
Sources
- https://www.abw.gov.pl/pl/aktualnosci/2815,Agencja-Bezpieczenstwa-Wewnetrznego-2024-2025-Wybrane-aktywnosci.html
- https://cyberdefence24.pl/cyberbezpieczenstwo/atak-prorosyjskiej-grupy-na-wodociag-csirt-nask-informowal-o-problemach-w-szczytnie
- https://cyberdefence24.pl/cyberbezpieczenstwo/kolejny-rosyjski-atak-na-polska-stacje-uzdatniania-wody
- https://therecord.media/polish-intelligence-warns-hackers-attacked-water-treatment
- https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/
- https://industrialcyber.co/reports/polish-abw-warns-cyberattacks-shifting-from-espionage-and-data-theft-toward-physical-disruption-of-critical-infrastructure/