Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

OT sabotage in Poland: what privileged access teams missed


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: CERT Polska’s analysis of the December 2025 Poland sabotage case shows attackers lived inside a CHP plant for months before triggering destructive wiper malware, using reused VPN credentials and weak remote access controls to reach operational systems, per Wallix. The case shows that OT resilience depends on privileged access visibility, approval, and containment, not just perimeter defense.

NHIMG editorial — based on content published by Wallix: The most dangerous part of the attack happened months before anyone noticed

By the numbers:

Questions worth separating out

Q: What breaks when privileged OT access is reused across multiple sites?

A: Reuse turns one compromised credential into a multi-site entry path and makes lateral movement far easier.

Q: Why do OT environments need different privileged access controls than enterprise IT?

A: OT environments often contain long-lived assets, separate identity stores, and narrow change windows that make standard IT access models too disruptive.

Q: How can organisations tell whether OT access controls are actually working?

A: Look for evidence that access is issued only on demand, expires automatically, and can be tied to a named user, task, and session record.

Practitioner guidance

  • Inventory every privileged OT remote path Map all VPN, vendor, and administrator routes into OT, then identify where credentials are reused across sites or shared between teams.
  • Require explicit session approval before OT access opens Make each privileged external session contingent on OT team approval and log the approval, duration, and operator identity in a tamper-resistant record.
  • Break cross-site credential reuse immediately Move from reusable remote admin credentials to centrally governed vaulting and per-site access scopes.

What's in the full article

Wallix's full article covers the operational detail this post intentionally leaves for the source:

  • The CERT Polska technical sequence behind the intrusion and destructive phase
  • The specific OT asset types affected, including RTU controllers, protection relays, and HMI computers
  • The NIS2 accountability and resilience context that frames access governance for essential entities
  • The control comparison between endpoint protection, remote access governance, and incident containment

👉 Read Wallix's analysis of the Poland OT sabotage case and privileged access failure →

OT sabotage in Poland: what privileged access teams missed?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

OT privilege architecture fails when remote access is treated as connectivity rather than identity. The Poland case shows that the attack surface was not the wiper alone, but the remote access design that allowed reuse across sites and left months of activity under-governed. Once privileged access becomes portable and persistent, the attacker no longer needs to break into every site separately. The practitioner conclusion is that OT remote access must be governed as a privileged identity problem, not an IT convenience layer.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when third-party access to OT systems is over-permissioned?

A: Accountability sits with the organisation that owns the industrial environment and the access lifecycle, even when a vendor performs the work. Access reviews, offboarding, and policy enforcement must be documented and owned internally, because the operational consequences of over-permissioned access remain inside the plant.

👉 Read our full editorial: Poland’s OT sabotage case shows why privileged access fails



   
ReplyQuote
Share: