
Aerial view of a wastewater treatment plant, known as biofactories, where the waters of the Mapocho River are treated in Santiago on May 7, 2026.
Franco FAFASULI/AFP via Getty Images
Poland formally charged two Russian nationals for a campaign of 17 cyberattacks on critical infrastructure including seven water and wastewater treatment plants — the first criminal prosecution under Polish law targeting Russian-linked hackers specifically for water supply attacks — after investigators documented that the attackers entered facilities through internet-exposed industrial control systems protected only by default passwords, cutting water to approximately 2,500 residents for six hours in the most consequential single incident.
The charges were filed by the District Prosecutor’s Office in Białystok, according to Polish cybersecurity outlet CyberDefence24, which reported the prosecution on Monday.
How Default Passwords Let Hackers Inside Poland’s Taps
The attack mechanism documented in the Polish cases was elementary by the standards of nation-state cyber operations. Marcin Dudek, head of CERT Polska — Poland’s national computer emergency response team — confirmed that multiple facilities were broken into by exploiting what he called “very weak passwords, e.g. ‘111111’ or ‘123456,’” according to a PAP interview published on Defence24.
What those passwords protected were HMI terminals — Human-Machine Interfaces — the operator-facing screens through which technicians monitor and control water treatment processes: pump speeds, filtration cycles, alarm thresholds, chemical dosing. At the Jabłonna Lacka Water Treatment Station in Masovian Voivodeship, investigators documented what happened when an attacker logged in as administrator: overflow alarms were suppressed to their minimum settings, deep-well pump start and stop thresholds were pushed to their maximum, filter-flush thresholds were maximized, and pump modes were toggled across off, manual, and regeneration states. Tank water levels rose 11 cm (4.3 inches) and 9 cm (3.5 inches) during the active session, according to CPO Magazine’s analysis of the incident.
“That is not random vandalism,” wrote Piotr Kupisiewicz, CTO at cybersecurity firm Elisity, analyzing the Jabłonna Lacka footage in a May 2026 assessment for Industrial Cyber. “The configuration was designed to suppress alarms while pushing the pump and filter assemblies into unsafe operating envelopes. The operator was technically literate. The defender’s telemetry was not.” His analysis appears in Industrial Cyber’s ABW report coverage.
The operators at targeted facilities often did not recognize the intrusions as attacks. At the Tolkmicko waterworks, director Jerzy Brzozowski said his team initially assumed the anomalies were routine equipment malfunctions: “We thought it was just a normal station glitch that happens from time to time. It turned out CERT had already spotted it.”
The same confusion played out at the Chodaczów sewage treatment facility in Podkarpackie Voivodeship, where local officials reported the incident “looked like a malfunction,” and at a heating plant in Ruciane-Nida, where the on-shift operator reset the system after a boiler shutdown, attributing it to a pre-existing display issue rather than a network intrusion.
This “living off the HMI” tradecraft — using a facility’s own legitimate control interface rather than installing malware — evades standard industrial cybersecurity defenses. “A boundary packet capture cannot reveal a manipulation that occurs entirely within an authenticated SCADA session,” Kupisiewicz noted. “The session itself is the evidence.” Standard intrusion detection systems hunting for malware signatures will find nothing; the attacker has simply logged into a control panel.
Denis Calderone, CTO at Suzu Labs, identified the root cause bluntly: “Every one of those problems traces back to the same root cause — that these systems were converged onto IP networks with zero defensive posture in mind. If anyone had architected even basic protections against internet-borne attack vectors when these HMIs and PLCs were networked, you wouldn’t see this kind of systemic exposure across five water treatment facilities in a single country.”
What the Białystok Prosecution Does, and Does Not, Accomplish
The two accused Russians remain at large in Russia, and because Russia has no extradition treaty with Poland, the charges have been formally suspended pending apprehension. Polish prosecutors announced the charges as a matter of public record nonetheless.
That decision carries strategic weight beyond the individual case. Formal charges against named individuals — even those unreachable in Russia — establish an evidentiary record, place the accused on international law enforcement watch lists, and assert that cyberattacks on civilian water infrastructure constitute criminal acts under domestic law. The prosecution frames the defendants as members of a pro-Kremlin hacktivist group operating within an organized criminal conspiracy, not as independent political actors with a geopolitical grievance.
That framing is significant. Pro-Russian hacktivist groups have long served as instruments of state policy with plausible deniability, posting videos of their intrusions on Telegram to spread propaganda while Russia denies responsibility. Poland’s Internal Security Agency (ABW), in its May 2026 annual report — the first publicly released since 2014 — identified hacktivist groups as “often personas used by foreign governments, particularly Russian intelligence services,” naming Russian APT groups APT28 and APT29, and the Belarusian-linked UNC1151, as operating against Polish targets, according to reporting by SecurityWeek on the ABW disclosures.
“The ABW report names Russian intelligence services as the driving force behind intensified cyber operations against Poland in 2024 and 2025, and these water attacks are part of a broader pattern that includes the national railway, air traffic control, and a foiled attempt to shut off water to one of Poland’s ten largest cities,” Calderone wrote. “The ABW opened 48 espionage investigations in 2025 alone, up from six the year Russia invaded Ukraine. This is a coordinated intelligence operation with critical infrastructure as a central target.”
A Sustained Campaign, Attack by Attack
The Białystok prosecution is the legal endpoint of a documented campaign that Poland’s Defence24 publication tracked across multiple voivodeships from April 2024 through late 2025, with attacks arriving every few months:
April 2024 saw the first documented attack, targeting a sewage treatment plant in Wydminy in the Warmińsko-Mazurskie Voivodeship. October 2024 brought a breach of the sewage plant in Kuźnica, Podlaskie Voivodeship. The pace accelerated through 2025: the Witkowo sewage facility in Wielkopolskie Voivodeship was hit in April, Szczytno’s water treatment plant in Mazowieckie Voivodeship in May, the Jabłonna Lacka station in September — where the 2,500 residents lost water — and the Chodaczów facility in Podkarpackie Voivodeship in October.
In several attacks, hackers published videos of their intrusions to Telegram channels. The propaganda dimension was explicit: demonstrating capability to Polish residents, signaling to potential future targets, and broadcasting footage of control interfaces being manipulated in real time.
The campaign reached a higher level of ambition in August 2025, when Deputy Prime Minister Krzysztof Gawkowski confirmed that Russian-backed entities had successfully infiltrated the network of one of Poland’s ten largest cities and attempted to cut its water supply — a move stopped “at the last minute” before the attackers could cause disruption.
At a hydropower plant in Pomerania near Gdańsk, pro-Russian hackers breached the facility twice — publishing footage of turbine shutdowns and control parameter manipulation each time.
Western Allies Respond with Sanctions; Poland Responds with a Billion-Euro Budget
The escalation in 2025 prompted parallel legal and diplomatic action from Western allies. The European Union and the United Kingdom jointly imposed coordinated cyber sanctions in July 2026, formally attributing both the December 2025 energy grid attack and broader water treatment facility intrusions to FSB Center 16 — the Russian Federal Security Service’s signals intelligence arm, also tracked by security companies as Berserk Bear or Ghost Blizzard, according to The Record’s sanctions reporting.
The UK Foreign Office stated the energy grid attack had “failed but could have caused 500,000 citizens to lose electricity in the depths of winter,” describing it as “another example of the Russian state’s irresponsible attempts to sow chaos across Europe.” The EU-UK package was the first time both jurisdictions had simultaneously acted under their respective cyber sanctions regimes.
Poland’s government responded to the broader campaign with a record cybersecurity budget of €1 billion (approximately $1.156 billion USD) for 2026, up from €600 million (approximately $694 million USD) in 2024 — with €80 million (approximately $92.5 million USD) allocated specifically to the cyber defenses of water management systems, as The Next Web reported.
For water utilities already under attack, those figures signal a policy recognition that the threat is physical, not merely digital. Dudek offered a tempered assessment of the damage so far: no water was contaminated in any of the documented attacks, no direct health risk materialized, and additional mechanical safety features in some systems limited how far out-of-envelope the attackers could push parameters before hardware interlocks engaged. But the supply interruptions were real. “We’ve had cases where an attack led to a temporary interruption in the operation of a water treatment plant, which meant that for a short period of time, people had no water,” Dudek told the Polish Press Agency.
How Are Water Utilities Supposed to Defend Against This?
The CISA and EPA published a joint advisory on internet-exposed HMIs in December 2024, specifically warning water and wastewater operators that it constituted a known and active exploitation pattern.
Calderone’s remediation checklist for water operators is direct: “HMIs and SCADA interfaces need to come off the public internet, period. If remote access is operationally necessary, put it behind a VPN with multi-factor authentication, not directly reachable on the open web. Segment OT networks from IT networks with monitored firewall boundaries. And operators need to be trained to recognize that unexpected parameter changes might not be a glitch. If your pumps or alarms are behaving strangely and you can’t explain why, treat it as a potential intrusion until proven otherwise.”
The problem is institutional, not just technical. ABW documented that “attacked entities were visible from the public internet, including Human-Machine Interfaces responsible for technological processes.” In some cases, the HMIs enforced a maximum password length of eight characters with no lockout on repeated attempts — meaning a brute-force attack could guess credentials mechanically, with no need for social engineering or sophisticated malware.
The same systemic failure exists in the United States, where parallel Iranian-linked attacks have breached water systems across at least 12 states. The US EPA’s own audit found that 70% of inspected water systems since 2023 were in violation of basic cybersecurity planning requirements under the America’s Water Infrastructure Act of 2018. The specific vulnerability pattern — internet-exposed PLCs and HMIs, default credentials, no network segmentation — is identical.
Kupisiewicz summed up the targeting logic for facilities that assume their small size protects them: “A 5,459-resident municipality is exactly the right size for this kind of attack, because it produces a propaganda video without forcing a serious response. Obscurity is no longer protection. Obscurity is a discount on the attacker’s targeting cost.”
Charges Follow Broader Pattern of Polish Legal Action Against Russian Proxies
The Białystok prosecution arrived alongside a broader surge in Polish legal actions against Russian and Belarusian hybrid warfare operators. Earlier in August 2025, Polish prosecutors charged six individuals — three Polish and three Belarusian nationals — with carrying out physical sabotage on behalf of Russian and Belarusian intelligence services, including arson and other destabilization acts, according to United24 Media’s reporting.
The prosecutorial strategy reflects what ABW’s report described as Russia’s evolving approach: moving from “loosely recruited online operatives toward more structured networks linked to organized crime groups, using encrypted messaging platforms and cryptocurrency for recruitment.” The criminal conspiracy framing in the Białystok case applies that same lens to cyberattacks — not isolated opportunistic hacking, but a campaign operated within an organized criminal structure.
Poland’s government has publicly characterized its situation in terms that leave little diplomatic ambiguity. Deputy Prime Minister Krzysztof Gawkowski declared at a launch event for Poland’s new municipal cybersecurity program in July 2026: “We are in a digital war with Russia.” Poland absorbs between 20 and 50 cyberattacks targeting critical infrastructure each day, according to government figures. The country recorded more than 279,000 classified cyber incidents across public institutions in 2025 alone, as TechTimes previously reported.
The parallel US prosecution of Russian-backed hacktivist operators offers a template for what such charges can accomplish even without extradition. Federal prosecutors in California, as part of Operation Red Circus, charged an individual for supporting CyberArmyofRussia_Reborn — a GRU-backed group that attacked water systems in Texas and a children’s water park in the Netherlands — even though other alleged members remain outside US jurisdiction, according to EPA’s Red Circus press release.
Frequently Asked QuestionsHow did Russian-linked hackers actually break into Polish water treatment plants?
The method was not sophisticated hacking in the technical sense. Attackers identified water treatment facilities whose control interfaces — the HMIs and SCADA terminals that operators use to adjust pumps, alarms, and filtration systems — were directly accessible on the public internet. Many of these systems had default or trivially guessable passwords, including “111111” and “123456,” according to CERT Polska head Marcin Dudek. Once logged in as administrator, attackers could adjust operational parameters, suppress alarms, and manipulate pump settings through the facility’s own legitimate control software — leaving no malware signature for standard detection systems to find. The evidence trail is the authenticated control session itself, not a network intrusion. Details appear in Industrial Cyber’s analysis of the ABW report and Dudek’s PAP interview via Defence24.
Were residents’ drinking water supplies contaminated by any of these attacks?
No. CERT Polska’s Marcin Dudek confirmed that none of the documented attacks resulted in water contamination. Mechanical safety systems in some facilities — hardware interlocks that prevent parameters from exceeding physical limits — constrained what attackers could achieve even after gaining access. The primary documented harm was a supply interruption: approximately 2,500 residents in Jabłonna Lacka lost water access for roughly six hours when pump parameters were manipulated. The more immediate risk flagged by security experts is not contamination but the demonstrated willingness and capability to disrupt civilian water supply at will — and the ease with which the same technique could be replicated at similarly unprotected facilities, as reported by Defence24’s incident timeline coverage.
Why are water treatment plants vulnerable to this kind of attack, and what can be done?
Water utilities globally — including in the US, where the EPA found 70% of inspected systems failed basic cybersecurity planning requirements — converged their operational technology onto standard internet-connected networks over the past two decades without the security architecture that enterprise IT systems require. The result is that control systems designed to be physically isolated now sit directly on the open internet. The fix is not technically complex: remove HMI terminals from public internet access, require VPN with multi-factor authentication for any remote connection, segment the operational technology network from the administrative IT network, and alert on anomalous parameter changes. The barrier is not cost but institutional attention — most small utilities lack dedicated cybersecurity staff and still treat unexpected parameter changes as equipment glitches rather than possible intrusions. Both CISA and EPA’s joint advisory and Industrial Cyber’s expert analysis address this remediation gap in detail.
What legal theory does the Białystok prosecution use to hold Russian hackers accountable even though they’re beyond Poland’s reach?
Polish prosecutors charged the two Russians under organized criminal conspiracy law, framing the pro-Kremlin hacktivist group not as independent political actors but as participants in a criminal organization operating with state direction. Even though the case has been formally suspended pending apprehension — which is unlikely while the suspects remain in Russia — the prosecution establishes a public evidentiary record, places named individuals on international watchlists, and asserts that cyberattacks on civilian water infrastructure are crimes, not acts of war that require a different legal framework. The strategy parallels the US approach in Operation Red Circus, where federal prosecutors in California charged an individual connected to CyberArmyofRussia_Reborn — a GRU-backed group that attacked water systems in Texas and a children’s water park in the Netherlands — even though other alleged members remain outside US jurisdiction, according to the EPA’s Operation Red Circus announcement and CyberDefence24’s reporting on the Białystok prosecution.