Hackers breached five Polish water treatment plants in 2025 by exploiting default passwords and internet-exposed industrial control systems. Poland's ABW attributed the attacks to hacktivist groups acting as fronts for Russian intelligence, including APT28, APT29, and Sandworm. The breaches were not sophisticated — attackers simply logged in with unchanged factory credentials and manipulated pump and filter settings. Poland has responded with a record €1 billion cybersecurity budget for 2026, including €80 million for water infrastructure. The US faces the same problem at scale: the EPA found 70% of water utilities violate basic cybersecurity standards, Volt Typhoon has pre-positioned in US water systems, and Congress let critical information-sharing authorities lapse. The core issue in both countries is that small municipal water operators lack the budget, expertise, and regulatory pressure to implement even basic security hygiene.