Recent cyberattacks against U.S. water and wastewater systems delivered an important reminder: disrupting operational technology (OT) does not always require sophisticated malware or a previously unknown vulnerability. In the July 2026 activity, internet-facing programmable logic controllers (PLCs), weak or reused credentials, undocumented remote access pathways, and recurring third-party configurations created opportunities for attackers to interfere with physical operations.

SpiderLabs’technical review of the July attacks examines the affected technologies, observed activity, and broader threat landscape. The next question is practical: what can small utilities realistically do about it?