Foreign hackers breached operational systems at two small water utilities in Colorado and manipulated equipment used to manage their infrastructure. State officials say the incidents were contained without affecting drinking water quality, water treatment, or public safety.

 

 

The attacks occurred in late August and involved two privately owned water providers, each serving fewer than 200 people. Colorado authorities have not identified the utilities or disclosed their locations, but confirmed that unauthorized actors gained access to systems involved in their operations.

According to the office of Colorado Governor Jared Polis, the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. Despite those actions, officials said customers experienced no interruption to water services and the affected providers were able to resolve the problems quickly.

How the attackers initially entered the systems remains unknown publicly. Authorities have not identified the affected equipment or software, and no specific vulnerability has been linked to the intrusions.

Colorado officials have described those responsible as foreign actors but have not attributed the incidents to a particular country or hacking group. The governor’s office noted that authorities are aware of Iranian-backed hackers targeting drinking water and wastewater infrastructure elsewhere in the United States, but it has not confirmed any connection between those campaigns and the Colorado attacks.

The breaches highlight the risks surrounding operational technology, which is used to control physical equipment rather than simply store information. At water facilities, these systems can manage pumps, valves, pressure, and other processes necessary for delivering water.

Internet-accessible industrial equipment has increasingly attracted attention from attackers because improperly secured remote connections can provide a route into operational environments. Federal cybersecurity authorities have repeatedly advised water providers to identify controllers exposed directly to the internet and restrict unnecessary remote access.

Smaller utilities can face additional difficulties because they often operate with limited cybersecurity staff and budgets while relying on connected industrial equipment. Even a facility serving a small number of customers may therefore present an attractive target when its operational systems are reachable remotely.

Colorado authorities are communicating with other water providers following the incidents and encouraging operators to review their defenses, apply available security updates and reduce unnecessary internet exposure.

Investigators have not publicly identified the hackers, their country of origin, or the technique used to gain initial access. For now, officials say the two intrusions were detected and addressed before the attackers could disrupt water delivery, alter treatment processes, or create a known threat to drinking water safety.

Leave a Reply