2 min read

Poland's water utilities become the latest target in Russia's shadow campaign- 218

Poland's water utilities become the latest target in Russia's shadow campaign- 218

May 7, 2026

Poland's domestic intelligence service has confirmed what regional cybersecurity researchers had already begun tracking: hackers breached water treatment control systems in five Polish towns during 2025, in some cases gaining the ability to alter technical parameters on live industrial equipment. The disclosure — Poland's first public security summary since 2014 — frames the intrusions not as isolated criminal incidents but as one thread in a sustained, evolving Russian sabotage campaign against a country that has become the logistics backbone of Western military support to Ukraine.

The Internal Security Agency's (ABW) report names the affected facilities directly: Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. In some cases, attackers reached industrial control systems with the ability to alter device parameters, creating what the agency called a direct risk to continuity of water supply. The ABW stopped short of formal attribution, but its broader assessment leaves little ambiguity: Poland faced intensified hostile cyber activity through 2024 and 2025, with particular emphasis on Russian special services. Polish outlet CyberDefence24 had previously linked several of the water-facility incidents to a pro-Russian hacktivist group that posted propaganda videos of the intrusions online, including footage of altered pump and alarm settings obtained through a compromised administrator account.

Recruitment Structure

What distinguishes this report from routine incident disclosure is the operational picture it paints of how Russian sabotage recruitment has matured. Rather than relying solely on loosely-recruited online operatives, the ABW describes a shift toward more structured networks tied to organized crime groups, using encrypted messaging and cryptocurrency payments to hire people for tasks often disguised as ordinary work. That evolution tracks with a broader pattern of physical sabotage across Poland — arson, reconnaissance, and damage to railway infrastructure — that led Prime Minister Donald Tusk to pledge the government would act ruthlessly against anyone aiding Russian services, following dozens of arrests.

The numbers underline the scale of the shift rather than any single incident. Espionage investigations linked largely to Russia and Belarus rose from six in 2022, the year of the full-scale invasion, to 48 in 2025 alone. Poland's incident response team logged more than 40,000 reports of potential cybersecurity incidents over the same reporting period. Alongside the water utility intrusions, the ABW's broader narrative includes a hack of the national railway's communications network, an outage of the country's air traffic control system, and the compromise of state news agency PAP to publish a false mobilization order — incidents the agency now explicitly links to a campaign willing to accept civilian casualties as a byproduct of sabotage. Poland's response so far has combined arrests, expulsions, and diplomatic measures, including the closure of three Russian consulates since late 2024. The ABW's decision to resume public reporting after an eleven-year silence is itself a signal: the agency wants the pattern seen, not just the individual incidents.

Escalation Timeline