A foreign threat actor briefly breached two private water systems in Colorado. Although the intruders changed equipment settings, officials said the incidents never threatened water treatment or quality.

Hackers Alter Water Utility Equipment

The attacks affected two small Colorado water utilities in August. Together, the private providers serve around 200 people.

According to state officials, the intruders changed equipment settings and altered pumping cycles. They also disabled remote access and alarm systems.

However, both incidents lasted only a short time. The affected providers quickly addressed the risks and then notified state authorities.

Officials said the attackers never placed the water treatment process or water quality in danger.

State Has Not Identified the Attackers

The office of Colorado Governor Jared Polis described the attacker as a foreign threat actor.

However, state officials have not confirmed the group’s identity or country of origin.

The governor’s office noted that Iranian-backed hackers have previously targeted US drinking water and wastewater facilities.

Still, officials have not attributed the Colorado breaches to Iran or any specific hacking group.

Attacks Follow Major Minnesota Campaign

The incidents follow a coordinated campaign against water infrastructure in Minnesota.

In late July, the pro-Iranian hacktivist group CyberAv3ngers targeted more than 30 water and wastewater providers across the state.

Officials described that campaign as one of the largest cyberattacks against Minnesota’s water infrastructure.

Minnesota IT Services worked with state public safety officials, the FBI and other government agencies after the attacks. Their efforts focused on supporting affected communities and improving infrastructure security.

CISA Warns About Exposed Control Systems

In early August, CISA urged critical infrastructure operators to remove exposed industrial control equipment from the internet.

The warning covered programmable logic controllers and other operational technology. Water providers use these systems to manage pumps, valves and treatment processes.

CISA advised operators to route remote access through a virtual private network or secure gateway. Organisations should never expose programmable logic controllers directly to the internet.

Security experts believe some Iran-linked groups search broadly for vulnerable systems instead of selecting specific US facilities in advance.

Therefore, small providers can face attacks even when they serve limited populations.

Colorado Issues New Security Guidance

Colorado officials are monitoring cyberattack trends across the United States.

The state has urged water providers to check their security controls and install available updates. It is also distributing new guidance to government agencies.

The recommendations aim to reduce the risk of attackers accessing utility control systems.

Although the recent breaches caused no known harm, the altered alarms and pumping cycles show the potential danger. The incidents also highlight the need for stronger security across small Colorado water utilities.


0 responses to “Hackers Breach Two Colorado Water Utilities”