Poland’s Internal Security Agency said hackers breached five water treatment plants and could potentially have taken control of industrial equipment, raising the risk of compromised water safety and possible physical harm. The incidents were disclosed alongside a wider warning that sabotage campaigns targeting Polish military sites, civilian entities, and critical infrastructure pose an immediate threat, while Sweden separately reported that suspected pro-Russian hackers attempted to disrupt a thermal power plant but were stopped by built-in protections. Officials in both countries described the activity as part of a broader pattern of increasingly aggressive attacks on operational technology across Europe, particularly against infrastructure in countries supporting Ukraine.
In the United States, the disclosures add urgency to CISA’s new CI Fortify initiative, which tells critical infrastructure operators in sectors including water, energy, transportation, and communications to prepare to keep essential services running for weeks to months while isolated from business networks, vendors, and telecom providers. CISA said the program is designed for scenarios in which attackers may already have access to OT environments and foreign adversaries are prepositioned inside U.S. infrastructure, with guidance focused on isolating control systems, maintaining offline and manual operations, and rehearsing recovery through tested backups, documentation, and component replacement plans.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Poland's Internal Security Agency attributed the 2025 compromises of five water treatment plants to Russia-linked APT28 and APT29 and to Belarusian-aligned UNC1151. The agency said the intrusions were enabled by internet-exposed management interfaces and weak passwords, not advanced zero-day exploits.
Poland's Internal Security Agency released a broader report saying it had thwarted multiple sabotage operations attributed to Russian spies and hackers targeting military facilities, critical infrastructure, and civilian entities. The agency warned that such attacks posed a real and immediate threat and could have caused fatalities.
Poland's Internal Security Agency said attackers breached five water treatment plants and could potentially have taken control of industrial equipment, creating a worst-case risk to water safety. The agency presented the incidents as part of a broader pattern of hostile activity against Polish critical infrastructure.
As part of CI Fortify, CISA publicly called on critical infrastructure owners to prepare to operate while disconnected from business IT, vendors, and telecom dependencies for extended periods during conflict or major cyberattack. The guidance emphasized backups, documentation, component replacement rehearsals, and manual operations to sustain service continuity.
CISA rolled out CI Fortify to help critical infrastructure operators maintain essential services during severe cyber incidents by focusing on OT isolation and recovery. The initiative includes pilot assessments and planning support for sectors such as water, energy, transportation, and communications.
Swedish civil defense minister Carl-Oskar Bohlin said a suspected pro-Russian hacker group had attempted to breach a thermal power plant in western Sweden in spring 2025. Officials framed the case as part of a broader trend of increasingly destructive cyber operations against European critical infrastructure.
In spring 2025, a suspected pro-Russian group tried to disrupt a thermal power plant in western Sweden, but built-in protections prevented the intrusion from succeeding. Sweden's security service investigated and linked the perpetrators to actors believed connected to Russian intelligence services.
In 2023, the Iranian-linked CyberAv3ngers group conducted intrusions affecting U.S. water infrastructure, reinforcing concerns that foreign state-backed actors were targeting internet-exposed industrial control systems. The activity was later cited alongside broader federal warnings to the sector.
An intruder accessed the Oldsmar, Florida water treatment facility and changed chemical settings, demonstrating the real-world risk of cyber compromise to water safety. The incident later became a prominent example cited in warnings about water-sector cyber threats.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcesecurityaffairs.com
Open sourcetechcrunch.com
Open sourceinfosecurity-magazine.com
Open sourcebankinfosecurity.com
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.