Hackers Breach Two Colorado Water Utilities, Raising Safety Concerns

Additional Coverage:

Last month, two water utilities in Colorado fell victim to cyberattacks by foreign hackers who infiltrated their computer systems, altering pumping schedules, disabling alarms, and modifying equipment settings before operators restored control, state officials revealed Thursday.

Despite these breaches, Colorado Governor Jared Polis’s office assured the public that drinking water quality and treatment processes remained unaffected. Nevertheless, these incidents place Colorado among a growing number of U.S. water and wastewater systems targeted by cyber intrusions.

According to the Environmental Protection Agency (EPA), over 100 water and wastewater systems across 12 states have faced similar attacks this year, highlighting an expanding threat to critical water infrastructure nationwide. Federal agencies had previously warned about these disruptions during the summer, noting the increasing sophistication of such cyber threats.

Colorado authorities have yet to disclose the identities of the attackers or whether the two breaches are linked to the wider series of incidents reported elsewhere. “These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state,” said Eric Maruyama, a spokesperson for Governor Polis.

The hackers reportedly manipulated equipment settings, disabled remote access and alarms, and changed pumping cycles. This underscores how cybercriminals are now targeting operational technology-not just traditional IT networks-gaining control over physical equipment such as pumps and valves at water treatment facilities.

The affected utilities serve roughly 400 residents, emphasizing how even small systems remain vulnerable.

Federal authorities had cautioned in July that malicious actors were increasingly targeting internet-connected operational technology, like programmable logic controllers (PLCs), at water and wastewater facilities. These intrusions have, in some cases, disrupted water operations by causing loss of water pressure or flooding.

Colorado’s incidents follow a wave of similar attacks this summer, including breaches affecting more than 30 community water systems in Minnesota. While investigations have considered whether Iranian-linked hackers were responsible for some of these attacks, official attribution remains unconfirmed. Former President Donald Trump publicly disputed claims that Iran was behind the Minnesota incidents, instead placing blame on local officials.

These recent cyberattacks have renewed focus on the persistent cybersecurity vulnerabilities within the nation’s water infrastructure, especially among small and rural utilities that often lack sufficient cybersecurity resources.

Many water systems rely on internet-connected industrial control systems to monitor and operate key equipment remotely. Federal experts have urged utilities to disconnect programmable logic controllers from direct internet exposure and to enhance authentication and access controls.

The EPA, as the federal sector risk management agency for water and wastewater systems, is actively collaborating with utilities, state agencies, and federal partners to identify vulnerabilities and bolster defenses. Since fiscal year 2025, the agency has identified over 900 cybersecurity weaknesses in more than 650 water systems, helping to mitigate approximately 700 of these across 500 utilities.

Additionally, the EPA has conducted over 710 cybersecurity risk assessments and provided technical assistance to nearly 16,000 utilities nationwide.

The FBI declined to comment on the recent Colorado attacks when contacted by Fox News Digital.


Read More About This Story:

TRENDING NOW

LATEST LOCAL NEWS