INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Poland's Water Plants Targeted in Coordinated Cyberattacks by Lazarus

| 2026-05-08 18:16 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
In May 2025 and again on May 8, 2026, Russian-linked APT groups suspected of being behind the attacks breached Industrial Control Systems (ICS) at five water treatment facilities in Poland. The affected entities include ABW, ICS, and Poland's Internal Security Agency. Five locations were targeted: Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo. Attackers exploited weak password policies and exposed management interfaces directly to the internet, gaining ability to alter equipment settings in real-time, posing a direct threat to public water services. The attack vectors are attributed to basic security failures that have been warned about by the OT and ICS security community for years.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT29APT29APT28APT28
Target & Sectors
BY PL
energyenergy manufacturingmanufacturing
Incident Timeline
‎2026/05/08
Threat actors APT28 and APT29, linked to election interference across Europe, breached the industrial control systems of five water treatment facilities in Poland.
threat_actor APT28
threat_actor APT29
Intelligence Sources