
Iranian-Linked Actors Breach Polish Power Plant via Cellular APN; US Water Sector Attacks Expand to 12 States
Recent breaches at a Polish CHP plant and dozens of US water utilities highlight critical vulnerabilities in internet-exposed PLCs and private cellular networks used for remote OT management.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Mandiant and CISA Joint Intelligence
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, critical infrastructure security has faced a significant escalation as threat actors successfully breached a Combined Heat and Power (CHP) plant in Poland and expanded a coordinated campaign against U.S. water utilities. On August 11, 2026, reports confirmed that attackers pivoted through a private cellular Access Point Name (APN) to shut down a turbine and water treatment system at a Polish facility serving 50,000 residents Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine. Simultaneously, the number of U.S. states reporting intrusions into municipal water systems has risen to 12, with New Jersey and Alabama joining the list of affected regions Multistate Water System Attacks Widen, Iran Suspected.
Threat Analysis
The current threat landscape for Operational Technology (OT) is characterized by a shift from traditional IT-to-OT pivoting toward direct exploitation of remote access vectors. In the Polish incident, the use of a private cellular APN—often mistakenly considered 'secure by obscurity'—allowed attackers to bypass perimeter defenses. In the U.S., the campaign continues to target Programmable Logic Controllers (PLCs) that are directly exposed to the internet. These attacks are increasingly opportunistic, leveraging default credentials and known vulnerabilities in protocols like Modbus and DNP3 3rd August – Threat Intelligence Report.
Technical Details
The U.S. campaign has specifically targeted PLCs from manufacturers including Siemens, Schneider Electric, and Rockwell Automation CISA Updates AA26-097A: Iranian IRGC-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric. Attackers have been observed changing device passwords and IP addresses, forcing operators to physically visit sites to reinstall software and regain control Baltimore Public Works Is on Guard in Wake of Cyber Attacks. In the Polish breach, the attackers manipulated the Human-Machine Interface (HMI) to trigger an emergency shutdown of a steam turbine, demonstrating a high level of familiarity with industrial processes.
Attribution Assessment
Federal agencies, including the FBI and CISA, have linked the U.S. water sector attacks to the Iranian Revolutionary Guard Corps (IRGC) and its affiliated group, CyberAv3ngers Multistate Water System Attacks Widen, Iran Suspected. While the Polish attack is still under investigation, the tactics, techniques, and procedures (TTPs) align with the 'propagandistic' nature of Iranian-backed hacktivism, which aims to stoke public fear rather than cause permanent physical destruction.
Implications
While no drinking water contamination or long-term power outages have been reported, these incidents underscore the fragility of local utility cybersecurity. The ability of actors to disrupt service for thousands of residents through relatively simple exploits highlights a systemic lack of risk assessment in the water and wastewater sectors Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector. The psychological impact of these 'we can get to you' attacks remains a primary objective for nation-state adversaries.
Recommendations
Encrygma analysts recommend that OT operators immediately: 1. Audit all cellular APNs and ensure they are not reachable from the public internet. 2. Implement Multi-Factor Authentication (MFA) for all remote access to ICS environments. 3. Change all default passwords on PLCs and HMIs. 4. Disconnect any PLC or industrial controller that does not strictly require internet connectivity for operations US water facilities targeted by ‘malicious cyber actors’ – who’s to blame?.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

CISA Issues Urgent Warning as Iranian-Linked Actors Target Industrial PLCs in Water Sector

Federal Agencies Issue Urgent Alert on AI-Assisted PLC Exploitation Targeting U.S. Critical Infrastructure

