Two private water utilities in Colorado were targeted by hackers in late August, with the attackers attempting to disrupt operations by manipulating equipment settings and disabling alarms. The incident highlights the growing threat of cyberattacks on operational technology (OT) systems, which are critical infrastructure components used to control and monitor industrial processes.
The affected utilities serve fewer than 200 people, but the potential consequences of such attacks could be far-reaching. If left unchecked, hackers could cause disruptions to water services, posing a significant risk to public health and safety. Fortunately, in this case, the disruptions were brief and did not affect water supply or pose any immediate threats to the community.
The attackers targeted industrial control systems (ICS), which are used to monitor and control equipment such as pumps, valves, and sensors. By manipulating these settings, hackers can cause equipment to malfunction, disrupting operations and potentially causing physical damage. The fact that the attackers also disabled remote access and alarms suggests a deliberate attempt to evade detection and create chaos.
While federal authorities have not named the utilities or confirmed who is behind the attack, they suspect “foreign actors” may be involved. The mention of an Iranian-backed group raises concerns about state-sponsored cyberattacks targeting critical infrastructure. In July, at least a dozen water facilities across the United States were targeted in a series of attacks attributed to this group.
The Cybersecurity and Infrastructure Security Agency (CISA) has been warning about the risks of OT system vulnerabilities for some time. In light of these attacks, CISA urged the water sector to secure their OT systems, highlighting the importance of robust cybersecurity measures to protect critical infrastructure. The agency also revealed that it is aware of 100 internet-exposed water systems targeted in cyberattacks in July.
The Colorado incident is just one example of a growing trend of OT system breaches. Independent security group Infracritical has established a central repository aggregating technical indicators and operational data from recent water sector breaches, providing valuable insights into the tactics used by attackers. This information can help utilities and authorities better prepare for and respond to future attacks.
In practical terms, this incident serves as a stark reminder of the need for robust cybersecurity measures in OT systems. Utilities must prioritize security and implement measures such as regular software updates, network segmentation, and employee training to prevent similar incidents from occurring in the future. By doing so, they can mitigate the risk of disruptions and protect public health and safety.
Source: SecurityWeek — 2026-09-21