Follow-up to the FBI/EPA joint advisory (July 30) confirming attacks on water utilities in at least 12 U.S. states since July 27 – attackers changed IPs and passwords on internet-facing PLCs, cutting off operators and causing pressure loss and flooding risk. This piece’s real finding is that despite years of warnings, a fresh scan still found thousands of these controllers openly exposed, including in towns already hit. Researchers characterize the attack pattern as mass opportunistic scanning rather than a sophisticated targeted campaign – meaning the barrier to being hit is low, not high.
EU context - background reference (not this week, but directly relevant to your sector):
Danish and Swedish authorities confirmed in December 2025 and April 2026, respectively, that pro-Russian groups (Z-PENTEST-ALLIANCE / Sandworm-linked actors) had already carried out similar OT intrusions against a Danish water utility near Køge (burst pipes, temporary water loss) and a Swedish heating plant - part of what ENISA's 2025 Threat Landscape report describes as a systematic pattern of state-aligned actors targeting EU water and energy OT interfaces specifically. I flagged this as background rather than "this week's news" since the attribution announcements are from Dec 2025/Apr 2026, but it directly parallels what's happening in the US right now and may be worth referencing in any internal briefing for Danish public-sector water clients.