Hackers Manipulated Control Systems at Two Colorado Water Utilities
Foreign threat actors breached two small, privately owned Colorado water utilities in late August and manipulated equipment used to control drinking-water systems, according to information the governor’s office provided to Axios.
Each utility serves fewer than 200 people. Colorado officials said the problems were resolved, technical assistance was offered and other water providers were alerted. The state has not identified the attackers, and the FBI declined to comment on the Colorado incidents.
Small utilities face a national OT campaign
The breaches fit a broader pattern of attacks against operational technology in the U.S. water sector. In a July 30 alert, the Cybersecurity and Infrastructure Security Agency warned that attackers were targeting internet-exposed programmable logic controllers, changing passwords and IP addresses to lock operators out or disrupt monitoring.
An FBI public-service announcement later said water and wastewater organizations in at least seven states had reported incidents since July 27, with some activity degrading operations. Federal guidance urges utilities to remove PLCs from direct internet exposure, require multifactor authentication for remote access and maintain the ability to operate safely in manual mode.
The Colorado cases show why a system’s size is not a reliable measure of cyber risk. Small utilities often run the same kinds of industrial controllers as larger operators but have fewer security staff, older equipment and limited maintenance windows. John Strand, Owner, Black Hills Information Security:
“This isn’t something critical infrastructure operators can fix overnight. Many of the security programs these organizations need take months, sometimes years, to properly implement. We were caught flat-footed. We need to start taking action now, because building that defensive capability is going to take time.”
For defenders, the priority is to inventory remote-access paths, segment business networks from control environments and alert on changes to PLC passwords, addresses and logic. Tested backups and manual operating procedures are equally important because a brief loss of visibility can quickly become a public-safety problem.


