Breaking
Cyber CrimeDeveloping Story

Colorado Water Utilities Hit in OT Attacks

Two small Colorado water providers were targeted in August, but disruptions were brief and service stayed on.

··2 hours ago·5 min read
Control room with monitors and chairs
Photo by Igor Saikin on Unsplash

Two privately run water utilities in Colorado were the target of cyberattacks in late August, in an apparent attempt to disrupt their operational technology (OT) systems. The incidents represent a rare confirmed case of attackers reaching into industrial control systems at very small providers — each serving fewer than 200 people — even as federal agencies continue to track a broader campaign against water infrastructure nationwide.

Reporting on the Colorado incidents comes from The Denver Post, which first described the attacks. Because technical details remain scarce and the state has not named the utilities or an attacker, the picture of what happened is still partial. The governor's office has described those responsible only as "foreign actors."

What the attackers touched

A spokesperson for Colorado Governor Jared Polis told The Denver Post that the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. Those actions point to hands-on interaction with control systems rather than a mere scan or login attempt.

The disruptions were brief and did not affect water services or public safety, according to the same account. That detail matters: despite the intrusion into control logic, the utilities kept delivering water and no harm to the public was reported.

Few technical details are available about how the attackers gained access. The source material does not specify the initial access vector, the tooling used, or how long the intruders remained in the systems before the disruptions were noticed.

The foreign actor question

The Colorado governor's office has not named the affected utilities or said who is behind the attack, describing the attacker only as "foreign actors." The state also has not confirmed whether the Colorado incidents are connected to a separate, larger campaign against water systems elsewhere in the country.

"We cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems, as per the Cybersecurity and Infrastructure Security Agency."

— A spokesperson for Colorado Governor Jared Polis

That statement leaves the attribution question open. While it references Iran-linked activity against water systems, it does not assert that the Colorado utilities were targeted as part of that specific campaign.

A wider wave in July

The Colorado attacks landed amid heightened attention on water-sector security following a wave of intrusions in July. Federal authorities have not released a complete list of affected utilities, but confirmed targets span facilities in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama.

CISA urged the water sector to secure OT in light of these attacks. The agency said it is aware of 100 internet-exposed water systems targeted in cyberattacks in July.

Independent security group Infracritical has established a central repository aggregating technical indicators and operational data from the recent water sector breaches. That kind of shared repository is often how smaller utilities — which may lack dedicated security staff — get visibility into indicators they would not otherwise see.

Small systems, limited defenses

The Colorado utilities each serve fewer than 200 people. At that scale, providers typically run lean operations and may not have the staff or budget for dedicated cybersecurity monitoring.

The attacks described by the governor's office included disabling remote access and alarms and altering pumping cycles. Those are changes to configured behavior inside control systems, not simply attempts to reach a web interface. Few technical details are available about how the intruders achieved that access, and the source does not confirm whether credentials, exposed interfaces, or another method were involved.

The affected utilities have not been publicly identified. Their small size means the incident is unlikely to draw the same attention as an attack on a large municipal system, even though the operational changes described were significant enough to be characterized as an apparent attempt to cause disruption.

Federal response and warnings

CISA's warning to the water sector followed the July attacks and focused on OT security. The agency has said it is aware of 100 internet-exposed water systems targeted in cyberattacks in July.

Federal authorities have not released a complete list of affected utilities from that wave. The confirmed targets that have been made public span facilities in Minnesota, Michigan, Georgia, South Dakota, New Jersey, Wisconsin, and Alabama.

Infracritical's repository is one of the efforts to consolidate technical indicators and operational data from those breaches, giving defenders a shared reference point as they assess their own exposure.

What remains unknown

The Colorado governor's office has not named the affected utilities or said who is behind the attack. It has described the attacker only as "foreign actors" and has not confirmed a link to the Iran-linked campaign referenced in the spokesperson's statement.

Few technical details are available about the Colorado incidents themselves — no confirmation of how access was obtained, no indication of how long the attackers were present, and no public technical bulletin detailing the specific changes made to equipment settings or pumping cycles.

It also has not been confirmed that the Colorado utilities were targeted as part of the campaign that hit the water sector in at least a dozen states across the United States in July. That leaves the relationship between the Colorado incidents and the broader wave an open question.

Why this matters

For water providers, the Colorado case is a reminder that OT systems at even the smallest utilities can be the target of hands-on manipulation. The attackers in this instance changed equipment settings and pumping cycles — actions that, if sustained or repeated, could complicate operations for providers with limited staff to detect and reverse them. The fact that service stayed on and public safety was unaffected in this case does not tell operators much about how a longer or more aggressive intrusion would play out.

The broader July wave, which CISA said involved 100 internet-exposed water systems, suggests the sector's exposure is not limited to large municipal utilities. Smaller providers often share vendors, integrators, and remote-access tools with many similar systems, which could mean the same techniques reach a wide set of targets.

For readers who depend on small water providers — and for the operators themselves — the practical takeaway from the available reporting is narrow but worth noting: control-system changes can be made quietly, alarms can be disabled, and remote access can be cut. Detecting those changes requires visibility into OT that many small utilities do not currently have. CISA's guidance to the sector after the July attacks, and Infracritical's effort to aggregate indicators, are both aimed at closing that gap, though neither can substitute for monitoring that is actually in place.

What remains unconfirmed — attribution, the specific access method, and any link between Colorado and the wider campaign — is likely to stay that way until federal authorities or the state release more. Until then, the Colorado incidents stand as a small but concrete data point in a sector that has spent months under active targeting.

#water utilities#ot security#ics#cisa#colorado

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories