Polish Hydropower Plant Disruption (2025)

Victim:

Polish Hydropower Plant

Attacker/Malware:

Russian Hacktivists’ custom malware

Industry:

Energy

Estimated Cost:

Disrupted turbine controls, causing anomalous power output and water flow (no physical damage or outages occurred)

Primary Attack Vector:

Likely unpatched VPN or SCADA interfaces, attackers used stolen credentials from earlier reconnaissance.

Prevention Failure:

Weak Credentials, Lack of Segmentation

BlastWave Solution:

Network Cloaking

Kill Chain Analysis:

Direct Targeting of Control Systems

In August 2025, Russian hacktivists were reported to have disrupted operations at a Polish hydropower plant.

Initial breach (May 2025) of the Tczew plant’s control systems; attackers gained partial access but caused minimal disruption because the facility was offline for maintenance, resulting in no operational impact. In August 2025, hackers remotely manipulate the plant’s interface, targeting SCADA-like systems. Turbine RPM spiked erratically (e.g., sudden accelerations/decelerations), water levels fluctuated, and power output dropped to zero intermittently for ~30–60 minutes.

BlastWave Prevention Analysis:

Securing Internet-Facing ICS

The Polish plant disruption falls into the category of direct, opportunistic attacks leveraging exposed ICS components. BlastWave Gateways placed in front of the plant’s control systems would deliver Network Cloaking.

The hackers would have been unable to discover or access the internet-facing PLCs or HMIs because the ports would be invisible to unauthorized network traffic, thwarting the attack’s initial access vector.

Had the OT network been cloaked, the attackers would not have been able to discover the control systems at all.

Download Hackopedia Volume 1 Now – It's Free

Our Privacy Policy applies.

Take the Next Step

Reading about past failures is only useful if it changes future outcomes. If attackers can see your OT network, they can target it. If they can target it, compliance, safety, and uptime are already at risk.

BlastWave eliminates reconnaissance, initial access, and lateral movement — without agents, without downtime, and without changing IPs, protocols, or PLCs.

Secure Your OT Network