Foreign Hackers Hit Two Small Colorado Water Utilities
Foreign hackers altered OT settings at two small Colorado water utilities in late August 2026 without disrupting service; Iranian links remain unconfirmed.
In late August 2026, attackers described as foreign hackers accessed operational technology at two small private Colorado water utilities serving fewer than 200 people. They changed equipment settings, disabled remote access and alarms, and altered pumping cycles; Governor Jared Polis's office said the brief intrusions did not affect drinking water quality, treatment, service, or public safety, and neither utility was named. Officials attributed the activity only to foreign actors while citing Iranian-backed efforts that CISA is tracking against U.S. drinking-water and wastewater systems, though both reports say attribution is unconfirmed. The incidents are discussed alongside a broader campaign against internet-exposed systems: CISA was aware of 100 targeted systems in July across at least a dozen states, while one report says officials could not confirm a link to those cases, in which attackers changed PLC addresses and passwords and sometimes disabled shutdown processes. CISA also warned that some cellular-connected PLCs were exposed without firewalls. The sources agree on the Colorado impacts and differ mainly in how firmly they connect the incidents to the suspected Iranian-linked July activity.
- Two unnamed private Colorado water utilities, serving fewer than 200 people, were targeted via OT/ICS in late August 2026.
- Attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles.
- Governor Jared Polis's office said the brief intrusions did not affect drinking water quality, treatment, service, or public safety.
- Officials described the actors only as foreign and cited Iranian-backed activity that CISA is tracking, but attribution remains unconfirmed.
- CISA was aware of 100 internet-exposed water systems targeted in July across at least a dozen states.
- Officials did not confirm a link to those July cases, in which attackers changed PLC addresses and passwords and sometimes disabled shutdown processes.
- CISA warned that cellular-connected PLCs were exposed without firewalls.
Coverage timelineoldest first · each row is one article
- · 5d agoColorado Water Utilities Hit by Cyberattacks Targeting OT Systems
SecurityWeek· 70
Hackers described as foreign actors targeted OT/ICS at two small Colorado water utilities in late August, altering settings and alarms without disrupting service.
- · 5d agoForeign Hackers Target Two Colorado Water Utilities
Security Affairs· 74
Foreign hackers briefly altered OT settings at two small Colorado water utilities without disrupting service.