Water utilities don't get to choose whether they're a target. Qilin chose for them.

On July 17, 2026, Acosol — the public water utility serving Spain's western Costa del Sol — confirmed a ransomware attack by the Qilin group. This is not a hypothetical about critical infrastructure risk. It is this week's incident report.

WHAT ACTUALLY HAPPENED

Qilin breached Acosol's systems, disrupting the availability of internal information and potentially exposing customer records — contact details, national ID numbers, contract data, and possibly payment information. Acosol activated its incident response protocols and is now warning subscribers directly to watch for suspicious calls, emails, and messages referencing their account, since threat actors routinely weaponize breach details for follow-on fraud.

This is not an isolated hit. Qilin has claimed roughly 700 victims through 2025 alone, surging after the RansomHub shutdown absorbed displaced affiliates and their tooling. Water utilities, school districts, and local courts sit alongside enterprise targets on its victim list — organizations chosen for weak defenses and thin security budgets, not deep pockets. Public-sector infrastructure has become the path of least resistance, not an afterthought.

WHY CRITICAL INFRASTRUCTURE CHANGES THE MATH

A ransomware hit on a retailer costs money. A ransomware hit on a water utility threatens the ability to bill, monitor, and in worst cases operate safely — while customers become a second attack surface through the phishing wave that follows every breach notification.

Utilities were built for reliability, not resilience against modern intrusion. Qilin is betting that gap stays open, and so far the bet keeps paying off. Every under-resourced public utility, water district, or municipal service is now a viable target, not a marginal one — attractive precisely because it can least afford a dedicated security team.

WHAT TO DO NOW

SEGMENT OT FROM IT AGGRESSIVELY — billing systems, customer databases, and operational controls should never share a flat network.

ASSUME CUSTOMER DATA IS PHISHING FUEL — the breach notification itself becomes a lure; brief customers before attackers do.

TEST YOUR INCIDENT RESPONSE PLAN NOW — Acosol's fast public warning limited damage; a plan tested only during the incident usually fails.

AUDIT THIRD-PARTY AND LEGACY ACCESS — public utilities carry old vendor connections that rarely get revisited until it's too late.

Critical infrastructure security isn't a compliance checkbox. It's the thing standing between a ransomware note and a community without reliable water service.

Would your utility's incident response survive first contact with Qilin?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.