Policy & Regulation
Hackers target water infrastructure in Poland and the U.S.
Poland’s intelligence agency reported attacks on five water treatment plants, highlighting a broader threat to critical infrastructure in the West from foreign hackers.
On Friday, Poland’s Internal Security Agency, the country’s top intelligence agency, published a report detailing operations and threats over the last two years. The agency revealed that it detected attacks on five water treatment plants. According to the report, hackers could have taken control of the industrial equipment inside these facilities, including, in the worst case, tampering with the safety of the water supply. The agency also stated that these attacks, according to the report, may have resulted in fatalities.
The report highlights that Polish intelligence thwarted multiple acts of sabotage by Russian government spies and hackers. These spies and hackers targeted military facilities, civilian targets, and critical infrastructure—defined as essential systems such as power grids, water supplies, and transportation networks. The Russian government is the alleged source of sabotage activity against Poland. To underscore the threat, the country’s top intelligence agency wrote: “The most serious challenge remains the sabotage activity against Poland, inspired and organized by Russian intelligence services. This threat was (and is) real and immediate. It requires full mobilization,”
These threats are not unique to Poland, as U.S. water infrastructure faces similar threats from foreign hackers. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA)—the US federal agency responsible for infrastructure security—have warned that water utilities remain a soft target for foreign hackers. In 2021, a hacker gained access to a water treatment plant in Oldsmar, Florida. Later, in 2023, the Iranian-backed hacking group CyberAv3ngers broke into digital control panels at water facilities in Pennsylvania. Federal agencies linked these Pennsylvania attacks to hostilities in the Middle East.
The threat from Iranian-backed groups remains active. A joint advisory from CISA, the FBI, the National Security Agency (NSA), and several other federal agencies warned that Iranian-backed hackers are actively targeting programmable logic controllers—the industrial computers that run water and energy facilities—at U.S. utilities. This advisory specifically warned that water utilities remain a soft target for foreign hackers, highlighting how critical infrastructure in the West has faced threats from foreign adversaries.
Why it matters
The report highlights a growing pattern of cyberattacks on critical infrastructure, specifically water and energy facilities, aimed at destabilizing Western nations. These incidents underscore the vulnerability of essential utilities to foreign state-sponsored hackers.