Poland says hackers breached water treatment plants, and the US is facing the same threat


Poland’s intelligence service said it detected attacks on five water treatment plants where hackers could have taken control of the industrial equipment inside, including, in the worst case, tampering with the safety of the water supply.

The story is relevant beyond Poland’s borders: U.S. water infrastructure has faced similar threats in recent years. In 2021, a hacker briefly gained access to a water treatment plant in Oldsmar, Florida and attempted to increase the level of sodium hydroxide — a caustic chemical — to dangerous levels. The FBI and the U.S. Cybersecurity and Infrastructure Security Agency have since warned that water utilities remain a soft target for foreign hackers.

On Friday, Poland’s Internal Security Agency, the country’s top intelligence agency, published a report covering the last two years of the agency’s operations and threats the country faced. The report said Polish intelligence thwarted multiple acts of sabotage from Russian government spies and hackers, who targeted military facilities, critical infrastructure (essential systems such as power grids, water supplies, and transportation networks), as well as civilian targets. These attacks, according to the report, may have resulted in fatalities.  

“The most serious challenge remains the sabotage activity against Poland, inspired and organized by Russian intelligence services. This threat was (and is) real and immediate. It requires full mobilization,” read the report.

The report did not specify whether the hackers behind the attacks on the water treatment facilities were Russian government spies. But Poland has recently been the target of several attempts by Russian government hackers to attack its infrastructure, including a failed attempt to bring down the country’s energy grid. That breach was later attributed to poor security controls at the targeted facilities.

Poland’s experience is part of a growing global pattern of attacks on water and energy infrastructure. As recently as last month, a joint advisory from the Cybersecurity and Infrastructure Security Agency, the FBI, the NSA, and several other federal agencies warned that Iranian-backed hackers are actively targeting programmable logic controllers — the industrial computers that run water and energy facilities — at U.S. utilities. The same Iranian hacking group, CyberAv3ngers, previously broke into digital control panels at multiple U.S. water treatment plants in Pennsylvania in 2023, in attacks that federal agencies linked to escalating hostilities in the Middle East.

In other words, the attacks against Poland are not unique, they follow a strategy that the Russian government is applying both in war zones such as Ukraine, as well as against Western countries that it sees as longstanding enemies. The plan, according to Polish intelligence, is to destabilize and weaken the West, and cyberattacks and cyberespionage are just tools in a larger toolkit for Putin’s regime.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

  • Related Posts

    Before iOS 27, Here's Everything You Need to Know About iOS 26

    Apple will likely announce iOS 27 soon, but don’t forget to check out all these iOS 26 features. Source link

    Chrome’s 4GB AI model isn’t new, but you’re not wrong for being confused

    A curious omission Google users were more willing to excuse AI in 2024, but the backlash is real in 2026. People are increasingly looking to avoid AI features, which makes…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Marathon and Destiny developer Bungie underperformed last year, causing a $765 million impairment loss for PlayStation

    Marathon and Destiny developer Bungie underperformed last year, causing a $765 million impairment loss for PlayStation

    Kelly McParland: Doug Ford tempts fate with suite of snafus

    Before iOS 27, Here's Everything You Need to Know About iOS 26

    Before iOS 27, Here's Everything You Need to Know About iOS 26

    The Coolest People I Know Are Breaking This Dated Jewelry Rule in 2026

    The Coolest People I Know Are Breaking This Dated Jewelry Rule in 2026

    Gaza at the Venice Biennale: Where language falls short, threads take over | Gaza

    Gaza at the Venice Biennale: Where language falls short, threads take over | Gaza

    Joint statement following Belarus’ sham presidential elections

    Joint statement following Belarus’ sham presidential elections