Foreign hackers briefly seized control of operational technology systems at two small, privately owned Colorado water utilities in late August, manipulating equipment used to manage drinking water infrastructure but leaving service and water quality unaffected, according to state officials[1][4][5][6].
The incidents affected two utilities that each serve fewer than 200 people and rely on network-connected control systems to operate pumps and other devices[1][4][5][12]. State spokespersons said the intruders changed equipment settings, disabled remote access and alarms, and altered pumping cycles before operators regained control and notified Colorado authorities[1][3][4][5][6][11][13].
Governor Jared Polis’ office described the perpetrators only as foreign actors and said investigators have not yet determined who is behind the compromises or how they initially gained access to the systems[4][5][11][12]. Officials added that treatment processes and water quality were not impacted at either provider, and there was no known risk to public safety[4][5][6][8][11].
Colorado’s announcement comes amid broader concerns that hostile groups are increasingly probing small U.S. water and wastewater utilities that often lack dedicated cybersecurity staff and robust defenses for aging industrial control equipment[4][5][9][12]. State officials said they are aware of ongoing efforts by Iranian-backed actors to access drinking water and wastewater systems elsewhere in the country, but they have not linked the Colorado attacks to any specific group[4][9][11][12].
After the breaches, state health and environmental agencies offered technical assistance to the affected utilities and issued alerts to other water providers across Colorado, urging them to review access controls, monitoring, and incident response procedures for their OT environments[9][11][12]. Denver Water, which serves roughly 1.5 million people in the metro area, said it evaluated the situation and determined its systems were not affected by the incidents[12].
Security experts say the ability to remotely change pump schedules, silence alarms, or disable remote access highlights how compromises of OT networks can quickly translate into physical risks, even when attackers cause only brief disruptions[1][5][9][14]. Small utilities are being urged to limit remote connectivity to industrial equipment, enforce strong authentication and unique passwords for control system accounts, maintain offline backups and recovery plans, and ensure staff know how to safely shift to manual operations if their digital controls are tampered with.
References
- Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
- Foreign hackers breach two more US water utilities …
- ‘Foreign actors’ briefly hacked two small Colorado water utilities last month, state says
- Foreign hackers targeted Colorado water systems in August …
- ‘Foreign actors’ targeted small, private water providers in Colorado
- Foreign Hackers Targeted Colorado Water Systems in …
- Foreign Hackers Breach Colorado Water Utilities, Prompt Statewide Alert | KOA 850 AM & 94.1 FM
- Cybersecurity breach affected two small Colorado water …
- Foreign actors breach Colorado water systems
- Foreign Hackers Breach Two Colorado Water Utilities – IJR
- Hackers Gain Control of Water System Devices in Colorado
