IndustrialCyber

Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access


Foreign hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings, according to a spokesperson for Colorado Gov. Jared Polis. The utilities serve fewer than 200 people, and the governor’s office said the incidents did not affect public safety, water services, treatment processes or water quality. The providers addressed the risks and later alerted state officials, Reuters reported.

The Colorado incidents came amid a broader wave of cyberattacks targeting water systems across the U.S., with more than 100 drinking water and wastewater systems across 12 states targeted this year, according to the Environmental Protection Agency, Fox News reported. 

So far, Colorado officials have not identified the actors behind the intrusions or confirmed whether they were connected to the broader activity, while the governor’s office said it was aware of ongoing efforts by an Iranian-backed group to access drinking water and wastewater systems. 

Attackers are believed to have changed equipment settings, disabled remote access and alarms, and altered pumping cycles at the facilities. Officials said the incidents were brief and quickly addressed. Treatment processes, water quality and public safety were not affected.

Back in July, CISA said more than 100 internet-exposed water systems were targeted, with activity focused on OT including programmable logic controllers. Cyberattacks on municipal water systems across at least seven states in July 2026 have intensified scrutiny of water infrastructure security and exposed gaps in existing protection approaches. The EPA has been designated as the sector risk management agency responsible for addressing water sector cybersecurity as part of broader critical infrastructure protection efforts.

Commenting on the Colorado attacks, Joe Saunders, CEO at RunSafe Security, wrote in an emailed statement that “The recent attacks on U.S. water systems by nation-state actors underscore that critical infrastructure cybersecurity is national security. Bad actors are testing for weaknesses and prepositioning in critical software to cause disruption at the time and place of their choosing.” 

He added, “We must act now to not only patch and securely boot code we ship, but most importantly we must prevent exploitation at runtime since nation-states are targeting fielded systems in the field.” 

“I think everything happening with AI is absolutely important, and people should be paying attention to it. But I truly feel like the AI news cycle has completely overwhelmed the targeting of critical infrastructure in the United States,” according to John Strand, owner at Black Hills Information Security. “For a long time, it seemed like many nation-states were avoiding direct attacks against critical infrastructure, at least at the rate we’re seeing now. It increasingly feels like the gloves are off. We’ve seen municipalities disrupted by cyberattacks, and we’re seeing water and other critical infrastructure targeted and compromised.”

He noted that “This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”

“Direct manipulation of operational technology in critical infrastructure threatens physical reliability, regulatory compliance, and public trust long before water quality is compromised,” Damon Small, board of directors at Xcape, wrote in an emailed statement. “Cyberattacks against Colorado water utilities highlight a distinct shift in state-sponsored tactics, moving past initial proof of concept access to actively probing operators’ response capabilities. Despite many critical changes having been made to remote access, alerting, and pump cycles, the human operators detected the anomalies and responded quickly, mitigating the incident.”

Small added that “Broad access to Internet-exposed programmable logic controllers is now an established reality, making the central threat no longer whether adversaries can gain unauthorized entry, but how rapidly the victim organization contains the breach once inside. Security leaders must move past basic perimeter defense by removing control interfaces from the public Internet, enforcing multi-factor authentication across all remote access gateways, and isolating industrial control networks behind strict firewalls.”

Some of the critical takeaways Small noted include that adversaries have escalated from opportunistic probing to evaluating operational incident response capabilities in real time. Despite attackers altering critical configurations, rapid human detection prevented physical impact, highlighting the necessity of agile response, and executives must enforce strict network segmentation, eliminate direct remote management, and isolate industrial control panels behind multi-factor gateways. 

He added, “Proving adversaries can break in is old news; the real test is whether your team can kick them out before the pumps change cycles.”

“A utility serving fewer than 200 people cannot fund a security engineer,” Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, wrote in an emailed statement. “Foreign actors hit two private Colorado water plants that size in late August, changed pump cycles, disabled alarms, and cut remote access the on-call operator relied on to check the plant. Governor Jared Polis’ office says treatment and water quality held after the providers drove out and reset the controllers.”

Krell added that “Federal funding should cover those salaries first, then stack the private-sector offers on top. The pacing from Minnesota to Colorado says defenders should plan for the next wave now.”



Source link