Foreign hackers breached the computer systems of two small Colorado water utilities last month, changing pumping cycles, disabling alarms and altering equipment settings before operators regained control, state officials disclosed on September 19, 2026.
What Happened
According to Colorado officials, the intrusions did not compromise drinking water quality or treatment processes, and the affected utilities’ operators were able to identify and reverse the unauthorized changes. Governor Jared Polis’s office described the incidents as “brief” and said the associated risks were “quickly addressed by the providers themselves.” The identities of the specific utilities have not been publicly disclosed.
Officials have not attributed the intrusions to a specific threat actor, though the state noted that previous, similarly styled attacks on US water infrastructure this year have been linked to actors with suspected ties to Iran and China.
Part of a Wider Pattern
The Colorado incidents add to a year in which more than 100 drinking water and wastewater systems across at least a dozen US states — including Minnesota, Michigan, Georgia, South Dakota and New Jersey — have reported cyberattacks targeting internet-exposed programmable logic controllers (PLCs). In late July, hackers broke into the operational technology behind more than 30 municipal water systems in Minnesota, changing passwords and IP addresses on exposed PLCs and locking operators out of their own equipment.
The pattern echoes an earlier wave documented in coordinated attacks that disabled a UK power plant and hit US water utilities, and follows a related warning about active reconnaissance against internet-exposed Siemens S7 PLCs flagged by CISA, the NSA and the FBI.
Federal Response
The US Environmental Protection Agency (EPA) said it is investigating the Colorado breaches and working with the affected utilities to identify vulnerabilities and strengthen defenses. The agency has previously reported identifying more than 900 vulnerabilities across over 650 water systems nationwide in 2026, and says it has helped remediate roughly 700 of those weaknesses across more than 500 utilities.
Why It Matters
Water and wastewater utilities are frequently smaller, resource-constrained operators with internet-exposed industrial control systems and limited dedicated cybersecurity staff, making them attractive, comparatively low-effort targets for state-linked and opportunistic threat actors alike. Security researchers and federal advisories have repeatedly urged utilities to take PLCs off the public internet, enforce multifactor authentication for remote access, and monitor for unauthorized changes to ladder logic and equipment configurations.

Leave a Reply