Key Takeaways

  • Foreign actors altered operational controls at two privately owned Colorado water utilities, but operators quickly regained control.
  • Officials reported no effect on drinking water quality, treatment processes, or public safety.
  • The incidents expose broader weaknesses around internet-connected industrial equipment and remote access across small U.S. utilities.

Foreign actors recently gained access to technology controlling physical infrastructure at two small Colorado water utilities, changing equipment settings, disabling alarms and remote access, and altering pumping cycles.

Operators quickly recovered control of both systems. State officials said the intrusions did not affect drinking water quality or treatment processes, and no public safety impact was reported. The two privately owned utilities each serve fewer than 200 people, placing the total affected population at roughly 400 residents.

Reporting by ABC News said Colorado has not publicly identified the attackers or determined whether the two incidents are connected to attacks elsewhere in the United States. The state is aware of continuing activity by an Iranian-backed group targeting drinking water and wastewater operations, but officials have not attributed the Colorado breaches to that group.

Similar techniques or targets do not establish that the same threat actor is responsible, particularly when exposed industrial equipment can be accessed by multiple groups. Premature attribution can distract from the immediate issue: outsiders reached systems capable of changing real-world physical operations.

The attacks went beyond viewing administrative records or stealing credentials. Manipulating pumps, alarms, and equipment settings crosses from conventional information technology compromise into operational technology, or OT. These environments use programmable logic controllers, supervisory control systems, sensors, and communications equipment to manage physical processes.

A utility does not need to serve a major city to become an attractive target. Smaller operators often operate with limited security budgets, aging equipment, thin staffing, and outside contractors who require remote access. Cellular modems may offer a convenient way to monitor distant pumps and treatment assets, but direct exposure creates a short path from the public internet to operational controls.

The Cybersecurity and Infrastructure Security Agency reported that more than 100 U.S. drinking water and wastewater systems across 12 states have been targeted by cyberattacks this year. The activity commonly involved programmable logic controllers connected directly to cellular modems.

That scale changes the threat calculation. An exposed controller at a utility serving fewer than 200 people may look insignificant in isolation. Across thousands of decentralized operators, however, the same configuration becomes a repeatable attack surface when threat actors automate discovery and test common credentials or known device weaknesses across the entire sector.

An IOActive assessment of CISA's revised water-sector figures notes that the exposure is broader than initially reported. The concern is not limited to sophisticated intrusions; attackers can reach operational devices because basic network separation, access controls, and monitoring are frequently absent.

For utility executives and technology suppliers, the practical response starts with asset visibility. Operators can inventory programmable logic controllers and other internet-facing hardware, remove direct exposure where feasible, place OT behind segmented networks, and route remote connections through controlled access points with multifactor authentication. Logging remote sessions and maintaining tested manual operating procedures also reduces recovery time.

Equipment from Rockwell Automation, Siemens, and Schneider Electric is widely present in industrial environments and frequently appears in water-sector security discussions. An Analysis Atlas review highlights the central role of major automation vendors in the wider OT and industrial-control security market. However, that does not indicate that products from any particular vendor were involved in the Colorado breaches.

Although the Colorado incidents ended without reported harm, they demonstrate that attackers can successfully manipulate physical operations rather than simply entering a business network. For water providers, state agencies, integrators, and equipment vendors, securing programmable logic controllers and segmenting network access are immediate requirements to prevent physical infrastructure manipulation.