HomeSecurityPolish security service reports ICS violations at water facilities

Polish security service reports ICS violations at water facilities

The Polish Internal Security Service (ABW) has recorded a significant escalation in cyberattacks targeting industrial process control systems (ICS) and other operational technology (OT) infrastructure in 2024 and 2025, with state-sponsored threat actors increasingly turning their attention to the physical disruption of critical services.

See also: Anthropic Mythos pushes White House to consider pre-publications for high-risk AI models

ICS

A Polish official revealed in August 2025 that a cyberattack could have caused a city to lose its water supply, but the attack was thwarted. No technical information was released at the time.

The government agency's new report provides more information about these types of attacks on the country's water sector.

According to ABW, the most significant incidents involved direct ICS intrusions into water treatment facilities in several Polish municipalities. In 2025, the agency recorded security breaches at water treatment plants in the areas of Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko and Sierakowo.

In some cases, attackers gained access to ICS and gained the ability to modify the operating parameters of the equipment, creating an immediate risk to operational continuity and public water supply.

See also: SimpleHelp and ScreenConnect misused for phishing attacks

Polish security service reports ICS violations at water facilities

The agency identified two main attack vectors that enabled these ICS intrusions: weak password policies and systems directly exposed to the internet. These are long-standing OT security hygiene failures, and were also recently used in a Russia-linked attack on Polish energy facilities.

Beyond water systems, ABW recorded an increase in attacks targeting supply chains, critical infrastructure, and ICS in other types of municipal services, including wastewater treatment plants and waste incineration plants.

Researchers found that attackers targeting supply chains were specifically looking for contract data, project documentation, and certification credentials that allow access to downstream systems.

ABW attributed the main responsibility to hacker groups, although these are often individuals employed by foreign governments, particularly Russian intelligence services.

See also: NCSC recommends passkeys as default authentication method

Polish security service reports ICS violations at water facilities

The report specifically mentions Russian APT groups such as APT28 and APT29, as well as the Belarus-linked UNC1151 group, as being active against Polish targets.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS