North Star Labs
Threat tracker · Water & wastewater

US water & wastewater cyberattacks.

Where each incident crossed the network — and what network-layer detection can see that point solutions miss.

Water and wastewater systems were built to keep running, not to be watched. The programmable controllers and SCADA networks that run treatment and distribution were designed for availability, not for the network visibility security teams now need. When an attacker reaches a control system, the intrusion travels across the network first — from an IT foothold, across the boundary, into the OT segment.

North Star Labs shows operators that travel: movement across the network layers that connect the business network to the control network, so the crossing is visible before it reaches the process. This tracker collects our technical position pieces on US water and wastewater incidents — what happened, where the network exposure is, and what network-layer detection can and cannot do about it.

Recent incidents

What changes about detection

Most water-sector tools watch the controller or the endpoint. They miss the transit. North Star Labs watches the network in between — the sessions, the east-west movement, the connections that mean someone is already inside and traveling toward the process. The result is a high-fidelity input to the stacks you already run, not another console to staff.

See the detection on your own telemetry

Talk to North Star Labs about a retrospective test on water or wastewater network traffic, or a capability briefing on network-layer detection across the IT/OT boundary.

Talk to North Star Labs

© 2026 North Star Labs LLC. All rights reserved.

Alexandria, VirginiaPittsburgh, PennsylvaniaSAM LHY2TGVEF8E5CAGE 9SV87

NORTH STAR LABS® is a registered trademark of North Star Labs LLC, USPTO Reg. No. 8157679.