Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Colorado’s Water Utilities Fall Victim to Sophisticated Cyberattacks

A pair of private water utilities in Colorado recently found themselves under attack from sophisticated hackers targeting their operational technology (OT) systems. The attackers, described as “foreign actors” by a spokesperson for Governor Jared Polis, attempted to disrupt the utilities’ industrial control systems (ICS). While the disruptions were brief and did not affect water services or public safety, the incident serves as a stark reminder of the growing threat of cyberattacks on critical infrastructure.

The affected utilities serve fewer than 200 people each, but the potential consequences of such attacks are far-reaching. The hackers manipulated equipment settings, disabled remote access and alarms, and altered pumping cycles – all designed to cause chaos and disrupt operations. Fortunately, the disruptions were short-lived, and the utilities were able to quickly recover.

The Colorado governor’s office has not named the targeted utilities or confirmed who is behind the attack, but they have acknowledged that the incident may be linked to a larger campaign targeting the water sector in at least 12 states across the United States. In July, the Cybersecurity and Infrastructure Security Agency (CISA) warned of an Iranian-backed group attempting to access drinking water and wastewater systems.

The water sector has been repeatedly targeted by hackers in recent months, with over 100 internet-exposed water systems compromised in cyberattacks in July alone. CISA has urged the industry to prioritize OT security, highlighting the critical importance of protecting these vulnerable systems from exploitation. Infracritical, an independent security group, has established a central repository aggregating technical indicators and operational data from recent breaches.

The Colorado incident serves as a wake-up call for water utilities and critical infrastructure operators nationwide. As our reliance on interconnected technology grows, so too do the risks associated with cyberattacks. It is imperative that these organizations take proactive steps to strengthen their defenses and protect against increasingly sophisticated threats.

In light of this incident, we urge all water utility operators and critical infrastructure owners to review their OT security posture and take immediate action to mitigate potential vulnerabilities. This includes implementing robust access controls, conducting regular vulnerability assessments, and staying informed about emerging threats in the sector. By prioritizing OT security, we can help prevent devastating disruptions and protect public safety.


Source: SecurityWeek — 2026-09-21