In late July, water and wastewater utilities in the United States reported coordinated cyberattacks targeting internet-connected programmable logic controllers (PLCs). Although the incidents occurred in the US, water-sector cybersecurity experts across Europe closely monitored the attacks because similar technologies are widely used worldwide.
The attackers reportedly gained access to exposed operational technology devices and modified configuration settings, passwords, and network information. These changes reduced visibility and disrupted normal monitoring and control functions at some facilities.
The incident highlighted one of the most persistent risks facing water utilities: operational technology systems connected directly to the internet. Security authorities warned that exposed industrial devices remain attractive targets for threat actors seeking to disrupt critical services.
The event serves as a valuable lesson for European water operators. Strengthening network segmentation, restricting remote access, and implementing stronger authentication mechanisms are increasingly viewed as essential measures for protecting critical infrastructure.