Breach Analysis·11 August 2026

Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants

Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Night view of a water treatment plant control room with industrial control system screens and clarifier tanks outside
Breach Analysis

Article record

Breach AnalysisCategory
11 August 2026Published
4 min readReading time
Mark FermorWritten by
Night view of a water treatment plant control room with industrial control system screens and clarifier tanks outside

Why it matters

What this means for organisations holding critical data

Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.

Poland's Internal Security Agency (ABW) has confirmed that attackers reached the industrial control systems of five municipal water treatment plants during 2025. In some cases the intruders gained the ability to change equipment settings, which in the worst case could have affected water supply and water safety. The findings were published in the agency's 2024 to 2025 activity report and were reported by SecurityWeek and TechCrunch on 8 May 2026.

What Happened

The ABW named water treatment stations in Jablonna Lacka, Szczytno, Maldyty, Tolkmicko and Sierakowo as targets. According to the agency, attackers gaining access in some cases to industrial control systems held the capability to interfere with the operation of the plants. Reporting attributes the wider campaign to Russia linked hybrid operations, and places it within a sustained escalation across 2024 and 2025.

A Polish official disclosed in August 2025 that a cyber attack could have caused a city to lose its water supply, and that the attack was stopped. The 2026 report gives that warning its detail. It also confirms a shift the security community has been describing for several years: state linked activity against critical national infrastructure is moving from espionage and data theft towards attempts to cause physical disruption.

Why This Matters Beyond Poland

Water utilities run operational technology. A single set of credentials can map to pumps, valves, chemical dosing, filtration stages, alarms and supervisory screens. The consequence of a breach is not a data subject notification, it is a process that behaves in a way the operator did not command.

The same architecture is present across the United Kingdom in water, energy, transport and local government. Remote access for maintenance, engineering laptops that move between networks, and flat routes between corporate systems and plant systems are all common. Where those routes exist, an intrusion in the office estate is a route into the process estate.

The Firevault View

Two things need to survive an intrusion of this kind. The first is the ability to trust the configuration: the programmable logic controller programs, set points, engineering baselines, network diagrams and system images that define how a plant is meant to run. The second is the ability to restore that configuration without depending on the compromised environment to supply it.

Offline Secure Storage® addresses both. A gold copy of the engineering and configuration record is held on hardware that is physically disconnected when it is not in use. An attacker inside the connected estate cannot read, encrypt, alter or delete a copy that is not connected. Recovery starts from a verified reference rather than from an assumption that the online backup was untouched.

Where operators are aligning to the NCSC Cyber Assessment Framework, this is an outcome level control rather than a product claim. It supports asset and configuration management under Objective A, protection of essential functions under Objective B, and restoration of essential function under Objective D.

What Operators Should Do Now

  • Identify the configuration record that a plant cannot run without, and confirm where the authoritative copy is held.
  • Establish an offline gold copy of that record, physically disconnected between authorised access windows.
  • Test restoration of set points and controller programs from the offline copy, on the assumption that the connected estate is untrusted.
  • Review every remote access route into the process environment, including supplier and maintenance access.
  • Record the control against the CAF outcomes the organisation is measured on, rather than treating it as a backup line item.

Poland has provided one of the clearest documented cases in Europe of state linked access to water sector control systems. The lesson for operators elsewhere is not that an attack is coming. It is that the record which allows a plant to be brought back under command must sit somewhere an attacker cannot reach.

Mark Fermor, Firevault

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis11 August 20264 min read

Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants

Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.

Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy