By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished September 26, 2025

TL;DR: Russian cyberattacks against Polish critical infrastructure are described by Anomali as part of a longer pattern spanning power grids, energy, transport, and destructive malware such as NotPetya, with implications that extend beyond Poland to any operator facing state-linked pressure. The central lesson is that resilience, segmentation, and identity hardening matter more than assuming attacks will stay contained or purely espionage-focused.


At a glance

What this is: Anomali says Russia-linked cyber activity against Poland’s critical infrastructure reflects a coordinated, long-running pressure campaign targeting essential services and operational resilience.

Why it matters: For IAM, PAM, NHI, and broader security teams, this matters because critical infrastructure disruption often begins with identity abuse, remote access weakness, and weak segmentation before it reaches operational technology.

By the numbers:

👉 Read Anomali's analysis of Poland's critical infrastructure threat pattern


Context

Poland critical infrastructure is now a test case for how state-linked cyber operations can blend espionage, coercion, and disruption. The article argues that the threat is not a one-off campaign but a sustained pattern aimed at power, water, transport, and other essential services, which is why conventional perimeter thinking fails when access paths, remote administration, and supplier trust are already exposed.

For identity and access teams, the governance lesson is direct. Critical infrastructure environments still depend on service accounts, vendor connectivity, remote access, and operational exceptions that can be abused long before operators see an obvious outage. That makes MFA, access review, segmentation, and incident readiness part of national resilience, not just enterprise hygiene.


Key questions

Q: What breaks when vendor access is not tightly controlled in critical infrastructure?

A: The main failure is loss of accountability and excessive blast radius. If vendor sessions are not time-limited and recorded, an incident may be impossible to reconstruct, and a compromised account can reach more systems than intended. That turns routine maintenance access into a resilience and recovery problem.

Q: Why do service accounts increase risk in cloud and legacy environments?

A: Service accounts increase risk because they often carry broad privileges, are embedded in applications, and are hard to rotate without breaking dependencies. In cloud environments that spread across teams and accounts, and in legacy systems that resist automation, these identities can persist with more access than they should. That makes them a common path for unauthorized persistence and lateral movement.

Q: How do organisations know if branch segmentation is actually working?

A: Branch segmentation is working only if teams can prove that devices can communicate solely with the systems they need and nothing else. Good evidence includes tested allowed paths, blocked paths that fail as intended, and repeatable segmentation validation after changes. If the control is only visible in diagrams, it is not yet operating as a security boundary.

Q: Who is accountable when a supplier pathway leads to critical infrastructure exposure?

A: Accountability sits with the operator, not just the supplier, because the operator owns the trust model, access approvals, and monitoring expectations. Frameworks such as the NIST Cybersecurity Framework place governance and risk ownership on the organisation that depends on the service. Suppliers matter, but delegated access still needs explicit lifecycle control and review.


Technical breakdown

Why state-linked attackers target critical infrastructure access paths

Critical infrastructure attacks usually begin with access, not disruption. Attackers exploit remote access, supplier trust, or exposed operational systems to gain a foothold inside environments that bridge corporate IT and operational technology. Once inside, they can map systems, identify privileged accounts, and choose whether to collect intelligence or prepare for sabotage. In these environments, the most important weakness is often not malware itself but the gap between business identity controls and OT operational constraints.

Practical implication: tighten remote access, supplier authentication, and privileged account oversight before focusing on downstream detection.

How service accounts and shared credentials widen the blast radius

Service accounts and other non-human identities often sit outside normal user governance. They are hard to inventory, rarely reviewed with the same discipline as human accounts, and frequently carry excessive privileges to keep operations running. In critical infrastructure, that creates a large blast radius: if an attacker steals one credential or session token, they can move from a single interface to systems that control physical processes. Identity sprawl becomes an operational risk, not just an IAM issue.

Practical implication: treat non-human identities as production access assets and enforce review, rotation, and least privilege.

Why OT resilience depends on identity-aware segmentation

Segmentation in critical infrastructure is only effective when identity and network controls work together. Attackers who obtain valid credentials can often bypass simple perimeter assumptions, so controls must verify both device trust and account legitimacy before access is granted. This is why strong MFA, conditional access, and separation between administrative, engineering, and vendor pathways matter. The goal is not perfect prevention but limiting how far a compromise can travel before operators contain it.

Practical implication: align segmentation with identity assurance so a single credential does not translate into broad OT reach.


Threat narrative

Attacker objective: The objective is to weaken national resilience by gaining durable access to critical systems and preserving options for intelligence collection or disruption.

  1. Entry occurs through compromise of remote access, supplier paths, or exposed systems that bridge IT and operational technology.
  2. Escalation follows as attackers identify privileged credentials, service accounts, and trusted administration routes that let them expand access.
  3. Impact is achieved through intelligence collection, disruption of essential services, or preparation for destructive malware and coordinated pressure campaigns.

NHI Mgmt Group analysis

Critical infrastructure compromise is an identity problem before it becomes an availability problem. State-linked campaigns still depend on remote access, trusted vendors, and privileged accounts to move from perimeter contact into operational environments. That means the first failure is usually governance of who and what is allowed to authenticate, not the final payload. Practitioners should treat access pathways as part of resilience engineering, not just security administration.

Standing privilege in operational environments creates the wrong assumptions for national resilience. The article’s attack pattern reflects a familiar governance gap: once access exists, it tends to persist long enough to be reused, expanded, or handed off across teams. That assumption breaks down when adversaries are patient and coordinated. The practical conclusion is that critical sectors need tighter lifecycle control over both human and non-human access.

Identity-aware segmentation is the control that separates nuisance intrusion from operational crisis. Firewalls and network zones matter, but they do not compensate for broad trust in authenticated users or service accounts. A compromised credential should not be enough to reach engineering consoles, supplier portals, or OT management planes. This is where NIST Cybersecurity Framework outcomes and zero trust principles align with infrastructure protection. Practitioners should design for containment after credential compromise, not before it.

Critical infrastructure defenders need to assume mixed motivation from state-linked actors. The same intrusion can support espionage today and disruption later, which makes narrow detection logic insufficient. Security programmes should be built to absorb long dwell time, inter-team coordination, and the reuse of legitimate access. For identity teams, the takeaway is to govern trust boundaries with the same seriousness as physical safety boundaries.

Horizontal access expansion is the real failure mode hidden inside infrastructure attacks. Standing credential exposure window is the most useful concept here: once a privileged account or remote session is exposed, the defender often has little time to limit its usefulness. That changes the operational meaning of access reviews, MFA, and vendor governance. Practitioners should measure how quickly access can be revoked, not just whether it exists on paper.

What this signals

Critical infrastructure teams should expect adversaries to keep using legitimate access paths because those paths survive scrutiny longer than malware signatures do. That means access governance, supplier offboarding, and service account rotation need to be treated as resilience controls, not just identity hygiene. The operational question is no longer whether a credential exists, but how quickly it can be rendered useless after compromise.

Access-path resilience: the useful programme metric is how much damage a valid account can do before containment begins. That moves attention from perimeter alerts to identity lifecycle speed, privileged path reduction, and supplier trust limits. For programmes that already use the NIST Cybersecurity Framework 2.0, this is where govern and protect outcomes converge in practice.


For practitioners

  • Harden remote access into critical networks Require strong MFA for all administrative and vendor pathways, and separate business access from operational access so one compromise does not cross both zones.
  • Inventory and review service accounts monthly Track every service account, API key, and shared credential that can reach OT-adjacent systems, then rotate or remove anything without a current owner.
  • Reduce blast radius with identity-based segmentation Limit engineering, supplier, and emergency-access accounts to the smallest set of systems required, and verify that conditional access is enforced before OT administration begins.
  • Test incident response against coercion scenarios Run exercises that assume intelligence collection, not immediate encryption, because state-linked attackers may stay quiet until they can influence essential services.

Key takeaways

  • Poland’s critical infrastructure exposure shows that state-linked cyber operations are designed to exploit trust, access, and operational dependence before they cause visible disruption.
  • Identity weaknesses such as shared credentials, weak supplier governance, and broad privileged access increase the blast radius of any foothold in critical environments.
  • Operators should measure resilience by how fast access can be revoked and contained, not just by whether threats are detected after entry.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Identity-based access control is central to limiting intrusion into critical infrastructure.
NIST SP 800-53 Rev 5AC-6Least privilege directly addresses the broad access paths exploited in infrastructure attacks.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral Movement; TA0040 , ImpactThe article’s attack pattern spans access, movement, and disruptive impact.
NIST Zero Trust (SP 800-207)Zero trust principles help constrain authenticated access across mixed IT and OT environments.
CIS Controls v8CIS-6 , Access Control ManagementAccess control management is the practical control family most exposed in the article.

Map privileged and supplier access to PR.AC-4 and verify boundary enforcement before OT connectivity.


Key terms

  • Critical infrastructure: Systems and services whose failure would seriously affect public safety, economic stability, or national security. In cyber terms, these environments combine IT, operational technology, and supplier access, so identity failures can become physical disruption rather than simple data loss.
  • Operational Technology: Operational Technology is the hardware and software that monitors or controls physical processes such as manufacturing lines, utilities, and transportation systems. Unlike standard IT, OT prioritises uptime and safety, so identity controls must be precise enough to reduce risk without interrupting essential operations.
  • Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
  • Identity-centric segmentation: Identity-centric segmentation is the practice of limiting access by identity, device, and authorised resource rather than by network location alone. It is especially relevant to defence environments because it reduces lateral movement and produces a clearer audit trail for compliance review.

What's in the full article

Anomali's full article covers the operational detail this post intentionally leaves for the source:

  • Source-linked breakdown of the 2015, 2016, 2017, and 2022-present attack patterns against Poland and neighbouring states
  • Practical recommendations for MFA, service account governance, vulnerability assessment, and incident response planning
  • Operational guidance for protecting ICS, SCADA, and other critical infrastructure systems from state-linked intrusion
  • Source citations and references that map the historical pattern to named incidents and public threat reporting

👉 Anomali's full post covers the attack history, defender recommendations, and cited source material.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and identity lifecycle control. It helps security and identity teams translate access governance into operational resilience across complex programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org