Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants
Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.
Article record
Why it matters
What this means for organisations holding critical data
Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.
Poland's Internal Security Agency (ABW) has confirmed that attackers reached the industrial control systems of five municipal water treatment plants during 2025. In some cases the intruders gained the ability to change equipment settings, which in the worst case could have affected water supply and water safety. The findings were published in the agency's 2024 to 2025 activity report and were reported by SecurityWeek and TechCrunch on 8 May 2026.
What Happened
The ABW named water treatment stations in Jablonna Lacka, Szczytno, Maldyty, Tolkmicko and Sierakowo as targets. According to the agency, attackers gaining access in some cases to industrial control systems held the capability to interfere with the operation of the plants. Reporting attributes the wider campaign to Russia linked hybrid operations, and places it within a sustained escalation across 2024 and 2025.
A Polish official disclosed in August 2025 that a cyber attack could have caused a city to lose its water supply, and that the attack was stopped. The 2026 report gives that warning its detail. It also confirms a shift the security community has been describing for several years: state linked activity against critical national infrastructure is moving from espionage and data theft towards attempts to cause physical disruption.
Why This Matters Beyond Poland
Water utilities run operational technology. A single set of credentials can map to pumps, valves, chemical dosing, filtration stages, alarms and supervisory screens. The consequence of a breach is not a data subject notification, it is a process that behaves in a way the operator did not command.
The same architecture is present across the United Kingdom in water, energy, transport and local government. Remote access for maintenance, engineering laptops that move between networks, and flat routes between corporate systems and plant systems are all common. Where those routes exist, an intrusion in the office estate is a route into the process estate.
The Firevault View
Two things need to survive an intrusion of this kind. The first is the ability to trust the configuration: the programmable logic controller programs, set points, engineering baselines, network diagrams and system images that define how a plant is meant to run. The second is the ability to restore that configuration without depending on the compromised environment to supply it.
Offline Secure Storage® addresses both. A gold copy of the engineering and configuration record is held on hardware that is physically disconnected when it is not in use. An attacker inside the connected estate cannot read, encrypt, alter or delete a copy that is not connected. Recovery starts from a verified reference rather than from an assumption that the online backup was untouched.
Where operators are aligning to the NCSC Cyber Assessment Framework, this is an outcome level control rather than a product claim. It supports asset and configuration management under Objective A, protection of essential functions under Objective B, and restoration of essential function under Objective D.
What Operators Should Do Now
- Identify the configuration record that a plant cannot run without, and confirm where the authoritative copy is held.
- Establish an offline gold copy of that record, physically disconnected between authorised access windows.
- Test restoration of set points and controller programs from the offline copy, on the assumption that the connected estate is untrusted.
- Review every remote access route into the process environment, including supplier and maintenance access.
- Record the control against the CAF outcomes the organisation is measured on, rather than treating it as a backup line item.
Poland has provided one of the clearest documented cases in Europe of state linked access to water sector control systems. The lesson for operators elsewhere is not that an attack is coming. It is that the record which allows a plant to be brought back under command must sit somewhere an attacker cannot reach.
Mark Fermor, Firevault
Sources
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






