5 minNews
Foreign Hackers Breach Two Colorado Water Utilities, Alter Pumping Cycles and Disable Alarms
State officials say the intrusions did not affect drinking water quality, but the incidents add Colorado to a widening series of cyberattacks on U.S. water infrastructure that has touched more than 100 systems across 12 states this year.
Foreign actors breached the computer systems of two small Colorado water utilities last month, altering pumping cycles, disabling alarms and changing equipment settings before operators regained control, state officials said Thursday. The intrusions did not affect drinking water quality or treatment processes, according to Gov. Jared Polis' office, but they add Colorado to a widening series of cyberattacks on U.S. water and wastewater infrastructure.
The two systems provide drinking water to roughly 400 people. Colorado officials have not identified the actors behind the intrusions or said whether they are connected to the broader activity reported elsewhere in the country. The hackers altered equipment settings, disabled remote access and alarms, and changed pumping cycles, according to the governor's office.
«These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state,» Polis spokeswoman Eric Maruyama said in a statement.
The incidents demonstrate how hackers can reach beyond traditional computer networks and gain access to operational technology used to control physical equipment at water plants, including pumps, valves and other machinery. Many utilities rely on internet-connected industrial control systems to remotely monitor and operate pumps, valves, water pressure and other equipment, a practice that federal officials have warned creates vulnerabilities.
Federal authorities warned in July that malicious cyber actors were targeting internet-connected operational technology at water and wastewater utilities. At the time, the FBI and the Environmental Protection Agency said utilities in at least seven states had reported incidents, some of which degraded water operations. The agencies said attackers had remotely accessed internet-facing programmable logic controllers, or PLCs, and tampered with device configurations, in some cases causing utilities to lose monitoring or control capabilities. Reported operational effects included loss of water pressure and flooding.
High-profile cyberattacks have targeted more than 100 drinking water and wastewater systems across 12 states this year, according to the EPA, expanding the footprint of a threat that federal authorities warned this summer was disrupting water operations across the country.
The Colorado breaches follow a series of attacks on water systems across the country this summer, including cyber activity affecting more than 30 community water systems in Minnesota. Federal investigators have examined whether Iranian actors or hackers affiliated with Iran were responsible for the Minnesota attacks, though officials had not publicly attributed the activity at the time. President Donald Trump disputed suggestions that Iran was behind the Minnesota attacks, saying during a Cabinet meeting, «They blame it on Iran. I don't think so.» He instead blamed Minnesota officials.
The recent incidents have renewed attention to longstanding cybersecurity vulnerabilities within America's water infrastructure, particularly among small and rural utilities that can have limited cybersecurity staff and resources. Federal officials have urged operators to remove programmable logic controllers from direct exposure to the internet and strengthen authentication and access controls.
The EPA, which serves as the federal government's sector risk management agency for water and wastewater systems, said it is working with utilities, states and federal partners to identify vulnerabilities and strengthen cybersecurity. Since fiscal year 2025, the agency has identified more than 900 vulnerabilities in over 650 water systems and helped eliminate about 700 at more than 500 utilities. The EPA has also conducted more than 710 cybersecurity risk assessments and provided direct technical assistance to approximately 15,900 utilities.
The FBI declined to comment when reached.
