Hackers Access OT at Two Small Colorado Water Utilities

Attackers altered equipment settings, disabled remote access and alarms, and changed pumping cycles at two small Colorado water utilities in late August; service and safety were not affected.

Two private Colorado water utilities serving fewer than 200 people each had operational technology and industrial control systems accessed by hackers in late August. Attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. The intrusions were brief and did not interrupt water delivery or endanger public safety.

The governor’s office described the perpetrators as “foreign actors,” declined to name the affected utilities and did not provide technical details about how access was gained. The office said it could not confirm which actors were involved and referenced federal reporting that an Iran-linked group has sought access to drinking water and wastewater systems.

Federal authorities reported a wave of intrusions against the water sector over the summer. The Cybersecurity and Infrastructure Security Agency told officials it was aware of roughly 100 internet-exposed water systems targeted in July and investigators have confirmed incidents at facilities in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin and Alabama.

Independent security researchers are collecting technical indicators and operational data from the recent breaches to help utilities and investigators assess exposure and tactics. State and federal agencies have urged water systems to review and harden OT configurations, remove unnecessary internet exposure, and verify alarm and remote-access protections.

Colorado officials said water quality and delivery were not affected during the late-August incidents and that utility operators regained control of equipment. Public-safety and environmental regulators were notified and are coordinating with federal partners to investigate the access and to ensure systems are secured.

Smaller utilities commonly operate legacy control equipment and often have limited cybersecurity staff. Agencies continue to encourage operators to inventory internet-facing assets, apply network segmentation, and work with federal resources to respond to suspicious activity and restore resilient operations.

Articles by this author