News Date: 2026-09-21
Two private water utilities in Colorado experienced cyberattacks against operational technology systems in late August, with intruders reportedly changing equipment settings, disabling remote access and alarms, and modifying pumping cycles. Officials said the disruptions were brief and did not interrupt water service or endanger the public.
Small Systems, Serious Consequences
The affected utilities each serve fewer than 200 people. Their limited size is significant because smaller operators often have fewer cybersecurity specialists, older industrial equipment and greater dependence on outside contractors. Attackers do not need to compromise a major metropolitan facility to create operational disruption or public concern.
Colorado officials described the intruders only as foreign actors. They referenced broader activity involving an Iran-backed group targeting US drinking-water and wastewater systems, but there has been no confirmed attribution connecting that campaign to the Colorado incidents.
The attacks reportedly involved industrial control systems rather than conventional office networks. Manipulating pumping schedules or suppressing alarms can have physical consequences if operators do not notice the changes quickly. Even unsuccessful attacks may reveal network layouts, equipment models and response procedures that can support future operations.
CISA has previously warned the water sector about exposed operational systems, and the agency was aware of roughly 100 internet-accessible water systems targeted during attacks in July. In my view, this illustrates a recurring infrastructure problem: remote connectivity is often added for convenience without equivalent investment in authentication, segmentation and monitoring.
Practical Protection for Water Operators
- Remove programmable controllers and management interfaces from direct internet exposure.
- Require multifactor authentication for remote maintenance and vendor access.
- Separate business networks from operational technology using tightly controlled gateways.
- Document normal equipment settings and alert on unauthorized configuration changes.
- Maintain offline recovery information and tested manual operating procedures.
- Review contractor accounts regularly and disable access immediately when work ends.
- Preserve logs and report suspected intrusions to federal and state authorities.
I believe smaller utilities need shared monitoring, regional incident-response support and affordable secure-access services rather than compliance instructions alone. These organizations provide essential services but may lack the staff required to operate a mature security program independently. The Colorado incidents ended without a public-safety impact, yet they should be treated as a warning that operational resilience depends on visibility, manual safeguards and rapid human intervention.
